# Vercy AI instruction - YAML 1.2 (JSON-compatible) { "vercy": "1.0-draft", "publication": { "status": "published", "adjudicationStatus": "reviewable-draft", "publishableCanonical": false, "generatedAt": "2026-09-05T20:55:05Z", "synthesisSha256": "48e5e12105839e258a16165e1bfd4aab652916961a604d3e048402695c35c373", "providerMode": "single-provider-waiver", "providers": [ "Claude" ], "waivedProviders": [ "Grok" ] }, "metaModel": { "id": "WM-XCT-037", "registryId": "vr.wm-xct-037", "name": "Dependency / Impact", "version": "0.3.0-research.1", "previousVersions": [], "entryKind": "relationship", "family": "World Models", "category": "Cross-cutting context", "industry": [ "Cross-industry" ], "domain": [ "XCT.DEP" ], "tags": [ "dependency", "impact", "xct.dep" ], "status": "published" }, "canonicalUrl": "https://ver.cy/models/wm-xct-037-dependency-impact/", "sourceUrl": "https://github.com/ver-cy/world-models/tree/feat/mega-model-registry/research/runs/wm-xct-037", "model": { "registry_id": "vr.wm-xct-037", "model_id": "WM-XCT-037", "name": "Dependency / Impact", "entry_kind": "relationship", "purpose": "Provide a reusable, format-neutral mixin for recording identified, versioned assertions that one externally owned endpoint depends on one or more other externally owned endpoints, together with the conditions, evidence qualifiers, assertion lifecycle, graph-participation declarations and downstream-impact parameters that make such assertions operable by other models.", "scope_statement": "WM-XCT-037 models the dependency assertion itself: an identified, versioned, attributed statement that a dependent/consumer endpoint requires a prerequisite/provider endpoint under a typed relation, within a declared scope and effective interval. The canonical direction is dependent -> prerequisite (the dependent is the party that would be affected if the prerequisite were absent, changed or withdrawn); any source vocabulary's own direction term is preserved verbatim alongside the normalized binding. The mixin carries: assertion identity and issuance attribution; applicability scope (adopting Dimension, tenant, jurisdiction, purpose, applicable endpoint types); role-bound endpoint references with scheme-qualified locators, version pins, immutable snapshot digests and compatibility declarations; explicit epistemic and completeness states that separate asserted-present, asserted-absent, unknown, not-assessed and unresolved; arity, ordering, composite-prerequisite grouping and degenerate-shape handling; guarding conditions and evidence qualifiers attached to an assertion; assertion lifecycle including revision, supersession, retraction and expiry; declared graph-participation parameters and declared impact-propagation parameters (traversal direction, propagation scope, criticality binding) that a consuming graph or impact service may act on; and the governance and operating conventions for the assertion corpus. The assertion has weak, host-dependent identity: unless a master system of record already assigns it an identifier, it exists only inside a host record, document or graph and is reconstructed from a deterministic correlation key. The mixin never allocates, owns, copies, renames, merges, configures, deploys, invokes or monitors either endpoint, and never authors the dependency-type vocabulary, computes graph closure or impact, discovers or matches endpoints, executes change, decides authorization, or maintains an audit trail.", "in_scope": [ "Assertion identity, identifier scheme, host scoping and deterministic correlation keys for weakly identified assertions", "Issuance attribution: issuing agent, authority basis, declared-at, observed-at, recorded-at and effective interval", "Applicability scope: adopting Dimension, tenant, jurisdiction, declared purpose, applicable endpoint types and scope qualifiers", "Role binding of dependent/consumer and prerequisite/provider endpoints with canonical direction and preserved source-vocabulary direction", "Scheme-qualified endpoint locators, sub-endpoint anchors, namespace binding and locator-equivalence declarations", "Version pins, immutable snapshot digests, live-reference mode and declared revision-compatibility ranges", "Epistemic and completeness states separating asserted-present, asserted-absent, unknown, not-assessed and unresolved, plus staleness horizons", "Arity patterns (one-to-one, one-to-many, many-to-one, many-to-many), ordered prerequisites, composite prerequisite groups and degenerate shapes", "Guarding conditions and evidence qualifiers attached to an assertion, and the confidence and basis fields that grade it", "Assertion lifecycle: revision, supersession, retraction, expiry, parallel assertions and recorded disagreement without adjudication", "Declared graph-participation and impact-propagation parameters carried on the assertion for consumption by external graph and impact services", "Governance and operating conventions for the assertion corpus: stewardship, canonicalization, patching, access scoping and retention shape" ], "out_of_scope": [ "Creation, allocation, ownership, naming, merging, configuration, deployment, invocation or monitoring of either endpoint", "Authorship, versioning or governance of dependency-type vocabularies and relation-term semantics", "Computation of transitive closure, reachability, cycles or topological order over the assertion set", "Execution of impact analysis, blast-radius calculation, simulation, scoring or prioritization", "Discovery, scanning, matching or inference that determines which endpoint satisfies a requirement", "Endpoint operational state, health, availability and telemetry", "Change execution, release orchestration, remediation and rollback", "Authorization decisions, policy evaluation and enforcement over this model's records or the endpoints", "Audit-trail capture, event-log storage and tamper-evidence services", "Resolution or dereferencing of endpoint locators and verification of retrieved content", "Records-retention scheduling, legal hold and erasure execution" ], "boundary_notes": [ { "neighbor": "Endpoint / resource model of the adopting Dimension (the dependent and prerequisite subjects)", "distinction": "Endpoints are externally owned. This model carries only role-bound references, pins and reported resolution states; it never allocates, renames, merges, configures, deploys, invokes or monitors an endpoint, and deleting an assertion has no effect on either endpoint. RFC 3986 s1.2.2 is explicit that a URI identifies without implying access, which is exactly the separation used here.", "source_refs": [ "SRC-005", "SRC-011" ] }, { "neighbor": "Dependency relation-type vocabulary or classifier registry", "distinction": "The assertion binds one typed relation term but does not author, extend, version or republish the vocabulary. RFC 8288 requires relation types to be registered or expressed as URIs defined elsewhere; SPDX relationshipType and CSAF relationship categories are likewise governed by their own bodies. Term meaning and native direction stay with the issuing registry.", "source_refs": [ "SRC-006", "SRC-012", "SRC-013" ] }, { "neighbor": "Graph, closure and impact-computation services", "distinction": "This model contributes edge assertions and declares whether a prerequisite set is complete, incomplete or unqualified; it never computes closure, depth, cycles, blast radius or scores. SPDX places completeness on the individual relationship, not on a derived graph, and CycloneDX leaves graph assembly to the consumer.", "source_refs": [ "SRC-013", "SRC-014", "SRC-016" ] }, { "neighbor": "Provenance model (W3C PROV)", "distinction": "Alignment only. PROV supplies the qualified-influence pattern (an identified, attributable reification of a binary relation) and bundles for provenance-of-provenance, but does not define dependent or prerequisite roles, pins or applicability scope. This model does not re-implement PROV activity, agent or plan lifecycles.", "source_refs": [ "SRC-001", "SRC-002" ] }, { "neighbor": "Identifier, namespace and scheme authorities", "distinction": "Scheme registration, namespace assignment, persistence guarantees and resolution services remain with their registries. RFC 8141 separates assigning a name from resolving it; this model records the scheme, namespace and locator and states which comparison level was applied, nothing more.", "source_refs": [ "SRC-005", "SRC-009" ] }, { "neighbor": "Change, release and version model of the endpoint owner", "distinction": "Creation and withdrawal of endpoint versions, revisions and snapshots are owned upstream. This model records a pin (live, version, digest or snapshot) and a declared compatibility range, and flags the reference as withdrawn when told so; it does not create, promote or withdraw versions.", "source_refs": [ "SRC-010", "SRC-016" ] }, { "neighbor": "Policy, authorization and audit systems", "distinction": "This model declares access scopes and the minimum facts an audit record should capture about its own records, but never evaluates policy, enforces a decision, or stores an audit trail. Referencing an evaluator or an audit record confers no ownership of evaluation, enforcement or audit-trail semantics.", "source_refs": [ "SRC-002", "SRC-005" ] }, { "neighbor": "Discovery and requirement-matching services", "distinction": "TOSCA shows requirement satisfaction as an orchestration-time matching concern, with node filters selecting a target that provides a capability. This model records only the resulting bound reference and, where relevant, that the binding was abstract at assertion time; it owns no matching algorithm.", "source_refs": [ "SRC-011" ] } ] }, "sources": [ { "id": "SRC-001", "title": "PROV-O: The PROV Ontology", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/prov-o/", "version_or_date": "W3C Recommendation, 30 April 2013", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:05:00Z", "relevance": "Supplies the qualified-influence pattern that reifies a binary relation into an identified instance carrying extra attributes, plus directed relations (wasDerivedFrom, used, wasGeneratedBy) and specializationOf, alternateOf and wasRevisionOf, used as the alignment basis for assertion reification and pinned-endpoint identity." }, { "id": "SRC-002", "title": "PROV-DM: The PROV Data Model", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/prov-dm/", "version_or_date": "W3C Recommendation, 30 April 2013", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:07:00Z", "relevance": "Defines bundles as named sets of provenance descriptions that are themselves entities (provenance of provenance), attribution to an agent, optional identifiers on qualified relations, and the coexistence of multiple accounts of the same subject without built-in conflict resolution - the basis for parallel assertions and weak assertion identity." }, { "id": "SRC-003", "title": "RDF 1.1 Concepts and Abstract Syntax", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/rdf11-concepts/", "version_or_date": "W3C Recommendation, 25 February 2014", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:09:00Z", "relevance": "Establishes IRIs as globally scoped identifiers and blank node identifiers as locally scoped and explicitly not persistent or portable, and notes that a graph name is not required to denote the graph - direct support for host-dependent assertion identity and for distinguishing assertion identity from endpoint identity." }, { "id": "SRC-004", "title": "RDF Schema 1.1", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/rdf-schema/", "version_or_date": "W3C Recommendation, 25 February 2014", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:11:00Z", "relevance": "Defines rdf:Seq (numerical ordering significant), rdf:Bag, rdf:Alt and rdf:List with first, rest and nil, plus the rdf:Statement reification vocabulary - the alignment basis, by analogy, for ordered prerequisites, composite prerequisite grouping and statement-level metadata." }, { "id": "SRC-005", "title": "RFC 3986: Uniform Resource Identifier (URI): Generic Syntax (STD 66)", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/rfc/rfc3986", "version_or_date": "Internet Standard, January 2005", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:13:00Z", "relevance": "Normative basis for endpoint locators: scheme-based federated naming (s3.1), fragment semantics governed by media type (s3.5), identification without implied access (s1.2.2), base-relative resolution (s5) and the four-rung equivalence ladder (s6.2) used for locator comparison rules." }, { "id": "SRC-006", "title": "RFC 8288: Web Linking", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/rfc/rfc8288", "version_or_date": "Proposed Standard, October 2017", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:15:00Z", "relevance": "Defines a link as link context plus relation type plus link target plus target attributes, requires relation types to be registered or expressed as URIs, deprecates the reversed rev parameter in favour of separate relation types, and defines the anchor parameter that overrides the default context - the model for role binding, direction and sub-endpoint anchoring." }, { "id": "SRC-007", "title": "RFC 3339: Date and Time on the Internet: Timestamps", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/rfc/rfc3339", "version_or_date": "Proposed Standard, July 2002 (updated by RFC 9557)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:17:00Z", "relevance": "Mandates seconds and a time-offset (Z or numeric) in Internet timestamps (s5.6) and reserves -00:00 for a known UTC instant with unknown local offset (s4.3); the RFC does not itself distinguish occurrence from recording time, so that separation is stated as a local rule in this model." }, { "id": "SRC-008", "title": "RFC 9562: Universally Unique IDentifiers (UUIDs)", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/rfc/rfc9562", "version_or_date": "Proposed Standard, May 2024 (obsoletes RFC 4122)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:19:00Z", "relevance": "Supports the third identity tier: 128-bit identifiers requiring no central registration, UUIDv7 for time-ordered locality, UUIDv5 for deterministic namespace-based names, and the instruction to treat UUIDs as opaquely as possible rather than parsing embedded meaning." }, { "id": "SRC-009", "title": "RFC 8141: Uniform Resource Names (URNs)", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/rfc/rfc8141", "version_or_date": "Proposed Standard, April 2017", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:21:00Z", "relevance": "Defines persistent, location-independent names with IANA-registered Namespace Identifiers, separates assignment from resolution, requires namespaces to publish their own uniqueness and persistence rules, and excludes r-, q- and f-components from URN-equivalence - the basis for namespace binding and locator equivalence." }, { "id": "SRC-010", "title": "RFC 6920: Naming Things with Hashes", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/rfc/rfc6920", "version_or_date": "Proposed Standard, April 2013", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:23:00Z", "relevance": "Defines the ni content-addressed naming scheme: a self-verifying immutable binding between name and content, comparison on digest algorithm and value alone, an IANA hash-algorithm registry, and the explicit statement that such names identify but do not locate - the basis for immutable snapshot pins." }, { "id": "SRC-011", "title": "TOSCA Simple Profile in YAML Version 1.3", "organization": "OASIS", "url": "https://docs.oasis-open.org/tosca/TOSCA-Simple-Profile-YAML/v1.3/os/TOSCA-Simple-Profile-YAML-v1.3-os.html", "version_or_date": "OASIS Standard, 26 February 2020", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:26:00Z", "relevance": "Primary relationship model with explicit source and target direction: tosca.relationships.DependsOn states that one node depends on another so the prerequisite is processed first; requirements declare node, capability, relationship, occurrences (cardinality) and node filters, separating matching and orchestration from the recorded relationship." }, { "id": "SRC-012", "title": "Common Security Advisory Framework Version 2.0", "organization": "OASIS", "url": "https://docs.oasis-open.org/csaf/csaf/v2.0/os/csaf-v2.0-os.html", "version_or_date": "OASIS Standard, 18 November 2022", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:28:00Z", "relevance": "Product-tree relationships bind product_reference to relates_to_product_reference under an enumerated category (default_component_of, external_component_of, installed_on, installed_with, optional_component_of) and mint a new product ID for the combination - a counterexample showing direction is category-dependent and that composite endpoints may require their own identity." }, { "id": "SRC-013", "title": "SPDX 3.0.1 Specification - Core/Classes/Relationship", "organization": "SPDX Project, The Linux Foundation", "url": "https://spdx.github.io/spdx-spec/v3.0.1/model/Core/Classes/Relationship/", "version_or_date": "SPDX Specification v3.0.1", "source_type": "schema", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T09:31:00Z", "relevance": "Normative relationship envelope: one from Element to one or more to Elements with relationshipType, startTime and endTime; NoneElement asserts explicitly that no such relationship exists and must not be combined with other elements; NoAssertionElement signals that no assertion is being made - direct support for direction, arity and the negation versus unknown separation." }, { "id": "SRC-014", "title": "SPDX 3.0.1 Specification - Core/Vocabularies/RelationshipCompleteness", "organization": "SPDX Project, The Linux Foundation", "url": "https://spdx.github.io/spdx-spec/v3.0.1/model/Core/Vocabularies/RelationshipCompleteness/", "version_or_date": "SPDX Specification v3.0.1", "source_type": "classifier", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T09:33:00Z", "relevance": "Defines complete (known to be exhaustive), incomplete (known not to be exhaustive) and noAssertion (no assertion can be made about completeness) - the normative three-state completeness qualifier adopted for prerequisite sets." }, { "id": "SRC-015", "title": "ECMA-424: CycloneDX Bill of Materials Specification", "organization": "Ecma International", "url": "https://ecma-international.org/publications-and-standards/standards/ecma-424/", "version_or_date": "2nd edition, December 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:35:00Z", "relevance": "Formal standardization of CycloneDX covering syntax and semantics for describing components, services and dependencies and for expressing metadata and lifecycle context; establishes the dependency graph representation used here as an interoperability alignment target." }, { "id": "SRC-016", "title": "CycloneDX BOM XML Schema, version 1.6 (bom-1.6.xsd)", "organization": "OWASP Foundation / Ecma TC54", "url": "https://cyclonedx.org/schema/bom-1.6.xsd", "version_or_date": "CycloneDX schema v1.6", "source_type": "schema", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T09:37:00Z", "relevance": "Defines dependency by ref (a bom-ref whose uniqueness is enforced only within the root bom element) to the components and services that are dependencies of the item described, and states that components without their own dependencies should be declared as empty elements while components with unknown dependencies should not be represented - an inverted encoding of absence versus unknown." }, { "id": "SRC-017", "title": "2025 Minimum Elements for a Software Bill of Materials (SBOM)", "organization": "Cybersecurity and Infrastructure Security Agency (CISA)", "url": "https://www.cisa.gov/resources-tools/resources/2025-minimum-elements-software-bill-materials-sbom", "version_or_date": "Published 22 August 2025 (public comment period 22 August - 3 October 2025)", "source_type": "public-authority", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T09:40:00Z", "relevance": "Confirms that a public authority treats component and dependency relationship data and the explicit declaration of unknowns as required transparency elements and prioritizes machine-processable formats. Used only as corroboration for the existence and framing of these requirements; the detailed field wording was not retrievable in machine-readable form and is recorded as an evidence gap." }, { "id": "SRC-018", "title": "SPDX Specification 3.0.1 - Core Model, RelationshipType vocabulary", "organization": "The Linux Foundation / SPDX Project", "url": "https://spdx.github.io/spdx-spec/v3.0.1/model/Core/Vocabularies/RelationshipType/", "version_or_date": "3.0.1 (published December 2024)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T08:40:00Z", "relevance": "Normative relationship terms used as the anchor for typed dependency kinds: dependsOn, hasPrerequisite, hasRequirement, hasProvidedDependency, hasOptionalDependency, hasDependencyManifest, configures, hasInput, hasOutput, each defined as holding 'during a LifecycleScopeType period'." }, { "id": "SRC-019", "title": "SPDX Specification 3.0.1 - Core Model, LifecycleScopeType vocabulary", "organization": "The Linux Foundation / SPDX Project", "url": "https://spdx.github.io/spdx-spec/v3.0.1/model/Core/Vocabularies/LifecycleScopeType/", "version_or_date": "3.0.1 (published December 2024)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T08:42:00Z", "relevance": "Normative phase vocabulary (build, design, development, runtime, test, other) used to scope edges by lifecycle phase; the absence of a deploy value is the evidence for the recorded phase-alignment gap." }, { "id": "SRC-020", "title": "SPDX Specification 2.3 - Relationships between SPDX elements", "organization": "The Linux Foundation / SPDX Project", "url": "https://spdx.github.io/spdx-spec/v2.3/relationships-between-SPDX-elements/", "version_or_date": "2.3 (published August 2022)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T08:35:00Z", "relevance": "Prior-generation scoped relationship types (DEPENDS_ON, DEPENDENCY_OF, BUILD_DEPENDENCY_OF, DEV_DEPENDENCY_OF, TEST_DEPENDENCY_OF, RUNTIME_DEPENDENCY_OF, OPTIONAL_DEPENDENCY_OF, PROVIDED_DEPENDENCY_OF, DEPENDENCY_MANIFEST_OF, STATIC_LINK, DYNAMIC_LINK, CONTAINS, PREREQUISITE_FOR) and their inverse-direction pairs; source of the direction-normalisation and mapping-residue rules." }, { "id": "SRC-021", "title": "CycloneDX Bill of Materials JSON Schema, version 1.6", "organization": "OWASP Foundation / CycloneDX", "url": "https://raw.githubusercontent.com/CycloneDX/specification/master/schema/bom-1.6.schema.json", "version_or_date": "1.6 schema (bom-1.6.schema.json, retrieved 2026-09-04)", "source_type": "schema", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T08:50:00Z", "relevance": "Defines the dependency object (ref, dependsOn, provides) as 'the direct dependencies of a component, service, or the components provided/implemented by a given component', and states that objects absent from the dependency graph 'may have unknown dependencies' and must be treated as opaque rather than dependency-free; also the compositions completeness concept and externalReference type enumeration." }, { "id": "SRC-022", "title": "TOSCA Version 2.0", "organization": "OASIS Open", "url": "https://docs.oasis-open.org/tosca/TOSCA/v2.0/TOSCA-v2.0.html", "version_or_date": "OASIS Standard, 22 July 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T08:45:00Z", "relevance": "Requirement and capability model: 'Requirements express that a component depends on a feature provided by another component, or that the component has certain requirements against the hosting environment'; capabilities are 'features exposed by components that can be targeted by requirements'. Supplies source/target directionality, occurrences as cardinality, node filters, and the fact that v2.0 removed bundled Simple Profile relationship types." }, { "id": "SRC-023", "title": "Debian Policy Manual - Chapter 7: Declaring relationships between packages", "organization": "The Debian Project", "url": "https://www.debian.org/doc/debian-policy/ch-relationships.html", "version_or_date": "Current published revision (retrieved 2026-09-04)", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T08:55:00Z", "relevance": "Ecosystem-specific but rigorously defined relation grammar: Depends, Pre-Depends (ordering), Recommends, Suggests, Enhances (inverse of Suggests), Breaks, Conflicts (negative), Provides (virtual package / capability), Replaces, and Build-Depends / Build-Depends-Indep / Build-Conflicts; plus version relation operators (<<, <=, =, >=, >>) and alternatives. Primary evidence that negative, ordering and capability relations are first-class and are not expressible as dependsOn." }, { "id": "SRC-024", "title": "package.json - npm CLI configuration reference", "organization": "npm, Inc. (GitHub)", "url": "https://docs.npmjs.com/cli/v10/configuring-npm/package-json", "version_or_date": "npm CLI v10 documentation (retrieved 2026-09-04)", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 3, "accessed_at": "2026-09-04T09:00:00Z", "relevance": "Ecosystem-specific qualifier semantics: peerDependencies express 'the compatibility of your package with a host tool or library, while not necessarily doing a require of this host'; optionalDependencies allow the consumer to 'proceed if it cannot be found or fails to install'; bundleDependencies are included in the published tarball; plus devDependencies, overrides, engines, os and cpu platform constraints." }, { "id": "SRC-025", "title": "Semantic Versioning 2.0.0", "organization": "Semantic Versioning project", "url": "https://semver.org/spec/v2.0.0.html", "version_or_date": "2.0.0", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T09:02:00Z", "relevance": "Normative MAJOR.MINOR.PATCH meaning, the requirement that software using it MUST declare a public API, pre-release and build-metadata syntax, and precedence rules (build metadata ignored, pre-release lower precedence). Used for the register's own compatibility rules and, only where an ecosystem declares SemVer, for version-constraint interpretation." }, { "id": "SRC-026", "title": "SLSA Provenance (predicate specification)", "organization": "Open Source Security Foundation (OpenSSF) / SLSA", "url": "https://slsa.dev/spec/v1.0/provenance", "version_or_date": "v1.0 predicate (v1.2 is the current approved release)", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T08:58:00Z", "relevance": "buildDefinition.resolvedDependencies is defined as the 'unordered collection of artifacts needed at build time' with the explicit caveat that 'completeness is best effort'; ResourceDescriptor (uri, digest, name, downloadLocation, mediaType, annotations) is the shape used for evidence references bound to build-time edges." }, { "id": "SRC-027", "title": "OpenAPI Specification v3.1.0", "organization": "OpenAPI Initiative (The Linux Foundation)", "url": "https://spec.openapis.org/oas/v3.1.0.html", "version_or_date": "3.1.0, 15 February 2021", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T08:47:00Z", "relevance": "Reference Object ($ref) resolution against a base URI, operationId as a unique operation identifier and operationRef as a location reference, the Link Object as a design-time link between a response and an operation, and the statement that a document may be divided into multiple connected parts. Grounds interface-contract endpoints and the compatibility edge to a named operation." }, { "id": "SRC-028", "title": "AsyncAPI Specification 3.0.0", "organization": "AsyncAPI Initiative (The Linux Foundation)", "url": "https://www.asyncapi.com/docs/reference/specification/v3.0.0", "version_or_date": "3.0.0", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T08:52:00Z", "relevance": "Servers as brokers, channels with addresses, operations declaring send or receive against a channel $ref, and protocol bindings. Grounds the separation of produce-side and consume-side stream edges and the distinction between a channel contract endpoint and a broker/server endpoint." }, { "id": "SRC-029", "title": "ECMA-427 - Package-URL (PURL) Specification", "organization": "Ecma International (TC54)", "url": "https://ecma-international.org/publications-and-standards/standards/ecma-427/", "version_or_date": "1st edition, December 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:04:00Z", "relevance": "Standardised seven-component package identifier used across software supply chains and SBOMs, where the type component determines ecosystem-specific meaning of the remaining components. Basis for the governed global identifier tier for package-class endpoints, and for the warning that type semantics are defined outside the standard itself." }, { "id": "SRC-030", "title": "Framing Software Component Transparency: Establishing a Common Software Bill of Materials (SBOM), Third Edition", "organization": "Cybersecurity and Infrastructure Security Agency (CISA), United States", "url": "https://www.cisa.gov/resources-tools/resources/framing-software-component-transparency-2024", "version_or_date": "Third edition, dated 3 September 2024, published 15 October 2024", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:08:00Z", "relevance": "Public-authority guidance that an SBOM unable to convey the full transitive set must explicitly acknowledge 'known unknowns' so a consumer can distinguish a component with no further dependencies from one with unknown or partial dependencies, and that completeness does not propagate uniformly down the dependency hierarchy. Basis for the mandatory completeness assertion and the prohibition on reading absence as independence." }, { "id": "SRC-031", "title": "Business Process Model and Notation (BPMN), Version 2.0.2", "organization": "Object Management Group (OMG)", "url": "https://www.omg.org/spec/BPMN/2.0.2/", "version_or_date": "Version 2.0.2, formal specification, January 2014", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T08:12:00Z", "relevance": "Normative distinction between Sequence Flow (ordering of flow elements inside one process) and Message Flow (exchange across participant/pool boundaries), plus associations and data associations. Grounds the process-reliance kind and the sequence-is-not-causation rule." }, { "id": "SRC-032", "title": "The Organization Ontology", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/vocab-org/", "version_or_date": "W3C Recommendation, 16 January 2014", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T08:12:00Z", "relevance": "Organization, FormalOrganization, OrganizationalUnit, Post, Role, Membership with memberDuring, subOrganizationOf, hasUnit, reportsTo, headOf, hasSite. The Recommendation explicitly removed the claim that the org:reportsTo graph is acyclic, which forces per-kind cycle rules here." }, { "id": "SRC-033", "title": "Time Ontology in OWL", "organization": "World Wide Web Consortium (W3C) and Open Geospatial Consortium (OGC)", "url": "https://www.w3.org/TR/owl-time/", "version_or_date": "W3C Candidate Recommendation Draft, 15 November 2022 (last Recommendation-stage version 19 October 2017)", "source_type": "ontology", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T08:13:00Z", "relevance": "Allen interval relations (before, after, meets, overlaps, during, starts, finishes, equals and inverses) for temporal reliance. Cited as alignment only: the ontology asserts temporal topology and makes no causal claim, and its current /TR/ version is not at Recommendation stage." }, { "id": "SRC-034", "title": "ODRL Information Model 2.2", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/odrl-model/", "version_or_date": "W3C Recommendation, 15 February 2018", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T08:13:00Z", "relevance": "Duty, Permission, Prohibition, Constraint, Party, assigner/assignee and the separation of a normative rule from its fulfilment. Grounds the obligation-versus-reliance distinction and the deontic class code." }, { "id": "SRC-035", "title": "Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA)", "organization": "European Parliament and Council of the European Union", "url": "https://eur-lex.europa.eu/eli/reg/2022/2554/oj", "version_or_date": "Adopted 14 December 2022, OJ L 333, 27 December 2022", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T08:20:00Z", "relevance": "Article 3(22) 'critical or important function' as a materiality test on functions rather than assets; register of information covering arrangements including subcontracting (Article 28); preliminary assessment of concentration and of further subcontracting, including third-country subcontractors (Article 29). Worked example of function-scoped and jurisdiction-sensitive dependency typing." }, { "id": "SRC-036", "title": "Directive (EU) 2024/1760 on corporate sustainability due diligence (CSDDD)", "organization": "European Parliament and Council of the European Union", "url": "https://eur-lex.europa.eu/eli/dir/2024/1760/oj", "version_or_date": "Adopted 13 June 2024, OJ 5 July 2024", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T08:21:00Z", "relevance": "'Chain of activities' with explicit upstream and limited downstream reach, direct and indirect business partners, and carve-outs (product disposal; downstream excluded for regulated financial undertakings). Demonstrates that chain scope is instrument-specific and must be declared per assertion." }, { "id": "SRC-037", "title": "European Legislation Identifier (ELI) register", "organization": "Publications Office of the European Union / EUR-Lex", "url": "https://eur-lex.europa.eu/eli-register/about.html", "version_or_date": "ELI register, consulted 2026-09-04", "source_type": "registry", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T08:22:00Z", "relevance": "URI-based identification of legal acts, FRBR-based metadata including jurisdiction and adoption date, and an ontology for exchanging legislation metadata. Supplies a jurisdiction-neutral citation mechanism for legal and jurisdictional reliance." }, { "id": "SRC-038", "title": "NIST SP 800-161 Rev. 1, Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://csrc.nist.gov/pubs/sp/800/161/r1/upd1/final", "version_or_date": "Revision 1, May 2022, update 1 dated 1 November 2024", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T08:23:00Z", "relevance": "Practice evidence for sub-tier supplier visibility, criticality analysis and dependency mapping across supply chain levels; also marks the boundary where technical supply chain dependency is handled by the adjacent split." }, { "id": "SRC-039", "title": "NIST SP 800-34 Rev. 1, Contingency Planning Guide for Federal Information Systems", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://csrc.nist.gov/pubs/sp/800/34/r1/upd1/final", "version_or_date": "Revision 1, May 2010, updated 11 November 2010", "source_type": "public-authority", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T08:24:00Z", "relevance": "Business impact analysis practice: identify resource requirements and interdependencies, then set recovery objectives. Used to fix the boundary that this model declares reliance while the BIA sets impact and recovery targets. Cited as dated practice guidance, not as a current requirement." }, { "id": "SRC-040", "title": "Enhancing Third-Party Risk Management and Oversight - A Toolkit for Financial Institutions and Financial Authorities", "organization": "Financial Stability Board (FSB)", "url": "https://www.fsb.org/2023/12/final-report-on-enhancing-third-party-risk-management-and-oversight-a-toolkit-for-financial-institutions-and-financial-authorities/", "version_or_date": "Final report, 4 December 2023", "source_type": "public-authority", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T08:25:00Z", "relevance": "Cross-jurisdictional common terminology for critical third-party services, identification of systemic third-party dependencies and concentration, explicitly aiming at comparable and interoperable approaches across jurisdictions." }, { "id": "SRC-041", "title": "Level 2 Data: Who Owns Whom", "organization": "Global Legal Entity Identifier Foundation (GLEIF)", "url": "https://www.gleif.org/en/lei-data/access-and-use-lei-data/level-2-data-who-owns-whom", "version_or_date": "Relationship Record CDF format 2.1; Level 2 collection began May 2017; consulted 2026-09-04", "source_type": "registry", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T08:26:00Z", "relevance": "Direct and ultimate accounting consolidating parent relationships plus reporting-exception formats. The canonical counterexample proving that ownership and consolidation are not dependency, and that absence of a parent record is not absence of reliance." }, { "id": "SRC-042", "title": "Guidelines on outsourcing arrangements (EBA/GL/2019/02)", "organization": "European Banking Authority (EBA)", "url": "https://www.eba.europa.eu/activities/single-rulebook/regulatory-activities/internal-governance/guidelines-outsourcing-arrangements", "version_or_date": "EBA/GL/2019/02, published 4 March 2019, applicable from 30 September 2019", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T08:27:00Z", "relevance": "A definition of outsourcing that separates outsourced functions from other third-party arrangements such as purchase of goods, and criteria for critical or important functions plus register expectations. Grounds the arrangement-type code." }, { "id": "SRC-043", "title": "UN/CEFACT Web Vocabularies", "organization": "United Nations Economic Commission for Europe (UNECE) / UN/CEFACT", "url": "https://vocabulary.uncefact.org/", "version_or_date": "Buy-Ship-Pay Reference Data Model vocabulary, version D23B; consulted 2026-09-04", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T08:29:00Z", "relevance": "Linked-data representation of the Buy-Ship-Pay Reference Data Model and UN/LOCODE. Separating the buy, ship and pay strands is the basis for distinguishing a payment/settlement reliance from a delivery reliance from a contractual reliance on the same counterparty." }, { "id": "SRC-044", "title": "ESCO - European Skills, Competences, Qualifications and Occupations classification", "organization": "European Commission, Directorate-General for Employment, Social Affairs and Inclusion", "url": "https://esco.ec.europa.eu/en/classification", "version_or_date": "ESCO v1.2.1, last updated 10 December 2025", "source_type": "classifier", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T08:30:00Z", "relevance": "Governed occupation, skill/competence and knowledge concepts with mappings to the International Standard Classification of Occupations, giving stable endpoint identifiers for capability and competence reliance instead of free-text role names." }, { "id": "SRC-045", "title": "ISO 17442: The LEI Code Structure", "organization": "Global Legal Entity Identifier Foundation (GLEIF)", "url": "https://www.gleif.org/en/about-lei/iso-17442-the-lei-code-structure", "version_or_date": "ISO 17442 Part 1 published 2012, Part 2 published 2019; page consulted 2026-09-04", "source_type": "registry", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T08:31:00Z", "relevance": "A 20-character globally governed legal entity identifier where each code represents exactly one entity. Supplies the second tier of identity priority for party endpoints when no master-system identifier governs the counterparty." }, { "id": "SRC-046", "title": "Inventory Management Use Case: Software Dependencies", "organization": "OWASP CycloneDX", "url": "https://cyclonedx.org/use-cases/software-dependencies/", "version_or_date": "CycloneDX v1.6 documentation, accessed 2026-09-04", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T09:20:00Z", "relevance": "Defines ref and dependsOn against bom-ref identifiers and states the critical epistemic rule that components with no dependencies must be declared as empty elements, while components absent from the graph may have unknown dependencies and must be treated as opaque rather than dependency-free." }, { "id": "SRC-047", "title": "RPM Reference Manual - Boolean Dependencies", "organization": "RPM Software Management (rpm.org)", "url": "https://rpm-software-management.github.io/rpm/manual/boolean_dependencies.html", "version_or_date": "Documentation for operators introduced in RPM 4.13 and 4.14, accessed 2026-09-04", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T09:20:00Z", "relevance": "Defines and, or, if, if-else, unless, unless-else, with and without, giving normative grammar for alternatives, guarded (conditional) dependencies, negative guards and same-target binding, plus the restriction that if cannot be combined with or and unless cannot be combined with and, and that Provides cannot carry boolean expressions." }, { "id": "SRC-048", "title": "systemd.unit(5) manual page", "organization": "systemd project (manual page mirrored by man7.org)", "url": "https://man7.org/linux/man-pages/man5/systemd.unit.5.html", "version_or_date": "systemd 261", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T09:20:00Z", "relevance": "Distinguishes requirement strength (Requires, Requisite, Wants, BindsTo, PartOf, Upholds), negative requirement (Conflicts) and ordering (Before, After), and states that ordering dependencies are independent of and orthogonal to requirement dependencies. Condition directives cause a silent skip when unmet whereas Assert directives cause failure, which is the canonical inapplicable-versus-failed distinction." }, { "id": "SRC-049", "title": "Shapes Constraint Language (SHACL)", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/shacl/", "version_or_date": "W3C Recommendation, 20 July 2017", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:20:00Z", "relevance": "Separates a declarative shapes graph from a validation report produced by an external processor, defines conformance as absence of results and no reported failure, provides the severity scale (Violation, Warning, Info) and provides sh:deactivated as a declared, reversible suspension of a constraint." }, { "id": "SRC-050", "title": "OWL 2 Web Ontology Language Primer (Second Edition)", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/owl2-primer/", "version_or_date": "W3C Recommendation, 11 December 2012", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:20:00Z", "relevance": "States the open-world assumption explicitly: a fact absent from a database is usually considered false under the closed-world assumption, whereas in an OWL 2 document it may simply be missing but possibly true. Grounds the model's default treatment of undeclared conditions as unknown rather than absent." }, { "id": "SRC-051", "title": "Assigning Pods to Nodes", "organization": "Kubernetes (Cloud Native Computing Foundation)", "url": "https://kubernetes.io/docs/concepts/scheduling-eviction/assign-pod-node/", "version_or_date": "Kubernetes documentation, accessed 2026-09-04", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T09:20:00Z", "relevance": "Contrasts requiredDuringSchedulingIgnoredDuringExecution (hard: cannot proceed unless the rule is met) with preferredDuringSchedulingIgnoredDuringExecution (soft: still proceeds), carrying a weight between 1 and 100 that is summed during scoring, and provides matching operators In, NotIn, Exists, DoesNotExist, Gt and Lt, where NotIn and DoesNotExist express negative conditions." }, { "id": "SRC-052", "title": "RFC 2119 / BCP 14 - Key words for use in RFCs to Indicate Requirement Levels", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/rfc/rfc2119.txt", "version_or_date": "March 1997", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:20:00Z", "relevance": "Normative obligation levels: MUST as an absolute requirement, MUST NOT as an absolute prohibition, SHOULD where valid reasons may exist in particular circumstances to ignore an item but the full implications must be understood and carefully weighed, and MAY as truly optional. Provides a domain-neutral strength scale and the normative basis for a justified, recorded deviation." }, { "id": "SRC-053", "title": "Open Source Vulnerability (OSV) Schema", "organization": "Open Source Security Foundation (OpenSSF)", "url": "https://ossf.github.io/osv-schema/", "version_or_date": "Version 1.9.0, 6 August 2026", "source_type": "schema", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T09:20:00Z", "relevance": "Range model with SEMVER, ECOSYSTEM and GIT types, an events array (introduced, fixed, last_affected, limit), half-open interval interpretation, and the requirement for an explicit enumerated versions list where the ecosystem ordering is uninterpreted. Grounds range endpoints, inclusivity and the dependence of ranges on a declared ordering scheme." }, { "id": "SRC-054", "title": "Semantic Sensor Network Ontology (SOSA/SSN)", "organization": "World Wide Web Consortium (W3C) and Open Geospatial Consortium", "url": "https://www.w3.org/TR/vocab-ssn/", "version_or_date": "W3C Recommendation, 19 October 2017 (link corrections 8 December 2017)", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:00:00Z", "relevance": "Defines Observation, FeatureOfInterest, madeBySensor, usedProcedure, Sampling, and the normative distinction between phenomenonTime (when the result applies to the feature) and resultTime (when the observation completed) - the basis for separating relation time from observation time." }, { "id": "SRC-055", "title": "Data on the Web Best Practices: Data Quality Vocabulary (DQV)", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/vocab-dqv/", "version_or_date": "W3C Working Group Note, 15 December 2016", "source_type": "ontology", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T09:00:00Z", "relevance": "Supplies QualityMeasurement, Metric, Dimension, QualityAnnotation and QualityCertificate, including value-plus-unit measurement structure and the precision dimension - used for referencing external quality assertions rather than computing them here." }, { "id": "SRC-056", "title": "RFC 9334: Remote ATtestation procedureS (RATS) Architecture", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/rfc/rfc9334.html", "version_or_date": "RFC 9334, Informational, January 2023", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:00:00Z", "relevance": "Separates Attester, Endorser, Reference Value Provider, Verifier and Relying Party, and defines Evidence, Endorsements, Reference Values, Attestation Results and Appraisal Policies plus nonce-, epoch-ID- and timestamp-based freshness - the normative basis for the authority roles, freshness mechanisms and the appraisal boundary." }, { "id": "SRC-057", "title": "in-toto Attestation Framework - Statement layer, v1", "organization": "in-toto project (Open Source Security Foundation)", "url": "https://github.com/in-toto/attestation/blob/main/spec/v1/statement.md", "version_or_date": "Statement v1 (https://in-toto.io/Statement/v1)", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T09:00:00Z", "relevance": "Envelope/statement/predicate layering, subject as ResourceDescriptor matched purely by digest, and predicateType typing - the model for binding a claim to an immutable subject by content digest and for keeping signed envelopes external." }, { "id": "SRC-058", "title": "OpenVEX Specification", "organization": "OpenVEX project (OpenSSF)", "url": "https://github.com/openvex/spec/blob/main/OPENVEX-SPEC.md", "version_or_date": "v0.2.0, 18 July 2023", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-04T09:00:00Z", "relevance": "Document @id IRI, author, role, timestamp, version and last_updated; statements as a sequence in which later statements override and enrich earlier ones; mandatory justification or impact_statement for a not_affected status - the working precedent for supersession, required reasons and preserved prior assertions." }, { "id": "SRC-059", "title": "International vocabulary of metrology - Basic and general concepts and associated terms (VIM), entry 2.26 measurement uncertainty", "organization": "Joint Committee for Guides in Metrology (JCGM) / BIPM", "url": "https://jcgm.bipm.org/vim/en/2.26.html", "version_or_date": "VIM 3rd edition (JCGM 200:2012), online edition", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:00:00Z", "relevance": "Defines measurement uncertainty as a non-negative parameter characterizing the dispersion of values attributed to a measurand based on the information used, and links to repeatability condition (2.20), reproducibility condition (2.24) and metrological traceability (2.41) - the standard for stating strength and reproducibility limits rather than bare scores." }, { "id": "SRC-060", "title": "Framing Software Component Transparency: Establishing a Common Software Bill of Materials (SBOM), third edition", "organization": "Cybersecurity and Infrastructure Security Agency (CISA)", "url": "https://www.cisa.gov/sites/default/files/2024-10/SBOM%20Framing%20Software%20Component%20Transparency%202024.pdf", "version_or_date": "Third edition, October 2024", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-04T09:00:00Z", "relevance": "Public-authority framing of SBOM attributes including author, timestamp and dependency relationship, the requirement to identify known unknowns explicitly where the full dependency graph is not enumerated, and depth maturity levels (minimum expected direct dependencies, recommended further levels, aspirational full transitive closure)." }, { "id": "SRC-061", "title": "RFC 7089 - HTTP Framework for Time-Based Access to Resource States (Memento)", "organization": "Internet Engineering Task Force (IETF)", "url": "https://datatracker.ietf.org/doc/html/rfc7089", "version_or_date": "RFC 7089, December 2013, Informational", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-05T09:11:00Z", "relevance": "Normative pattern for as-of reconstruction: datetime negotiation via Accept-Datetime, a Memento-Datetime response header that is 'a promise that the resource state reflected in the response will no longer change', plus TimeGate and TimeMap. Grounds the requirement that a cited prior record version must be immutable and that corrections mint new versions." }, { "id": "SRC-062", "title": "RFC 4268 - Entity State MIB", "organization": "Internet Engineering Task Force (IETF)", "url": "https://datatracker.ietf.org/doc/html/rfc4268", "version_or_date": "RFC 4268, November 2005, Proposed Standard", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:12:00Z", "relevance": "Defines EntityAdminState (unknown, locked, shuttingDown, unlocked), EntityOperState (unknown, disabled, enabled, testing), EntityUsageState, EntityAlarmStatus severity bits (critical, major, minor, warning, indeterminate, underRepair) and EntityStandbyStatus, and states that these are a subset of the ISO/OSI states also defined in ITU-T X.731. Establishes that administrative state and operational state are separate axes owned by the managed entity, not by an assertion about it." }, { "id": "SRC-063", "title": "ITU-T Recommendation X.731 - Information technology - Open Systems Interconnection - Systems management: State management function", "organization": "International Telecommunication Union, Telecommunication Standardization Sector (ITU-T)", "url": "https://www.itu.int/rec/T-REC-X.731/en", "version_or_date": "X.731 (01/92), with corrigenda and amendments to 2001", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:12:00Z", "relevance": "Origin standard for the state-management model that separates administrative permission to use a resource from its operational capability and usage. Cited as the upstream authority for the endpoint-state boundary; the accessible catalogue entry confirms title and edition only, so detailed enumerations are corroborated through SRC-005." }, { "id": "SRC-064", "title": "OGC Abstract Specification Topic 20: Observations, Measurements and Samples (OMS)", "organization": "Open Geospatial Consortium / ISO TC 211", "url": "https://www.ogc.org/standard/om/", "version_or_date": "OGC 20-082r4, version 3.0; published jointly as ISO 19156:2023", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:13:00Z", "relevance": "Normative separation of phenomenonTime (the time to which the result applies) from resultTime (the time the result became available, typically when the procedure completed), plus optional validTime for the period a result is intended to be used. This is the primary basis for late-observation handling and for refusing to conflate event time with ingestion time." }, { "id": "SRC-065", "title": "Resource Observation - HL7 FHIR Release 5", "organization": "Health Level Seven International (HL7)", "url": "https://hl7.org/fhir/R5/observation.html", "version_or_date": "FHIR R5 (v5.0.0)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:13:00Z", "relevance": "Independent corroboration of two-time modelling - effective[x] is 'the time or time-period the observed value is asserted as being true' while issued records when the version was made available after review - and of a status element that is a modifier element carrying registered, preliminary, final, amended and entered-in-error, giving a precedent for annulment distinct from ordinary supersession." }, { "id": "SRC-066", "title": "ISO/IEC 11179-6:2023 Information technology - Metadata registries (MDR) - Part 6: Registration", "organization": "International Organization for Standardization / International Electrotechnical Commission", "url": "https://www.iso.org/standard/78916.html", "version_or_date": "ISO/IEC 11179-6:2023", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:14:00Z", "relevance": "Defines registration status categories governed by a registration authority, with lifecycle categories that progress toward preferred use and then to Superseded (a successor is now preferred) and Retired (no longer recommended for use). Basis for the proposal/review/activation/deprecation/supersession/retirement ladder and for naming a registration authority per transition." }, { "id": "SRC-067", "title": "DCMI Metadata Terms", "organization": "Dublin Core Metadata Initiative (DCMI)", "url": "https://www.dublincore.org/specifications/dublin-core/dcmi-terms/", "version_or_date": "Issued 2020-01-20", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-05T09:14:00Z", "relevance": "Supplies stable supersession semantics - replaces ('supplanted, displaced, or superseded by the described resource') and isReplacedBy - plus valid ('date, often a range, of validity of a resource'), issued and modified, distinguishing a validity range from record dates." }, { "id": "SRC-068", "title": "RFC 8126 / BCP 26 - Guidelines for Writing an IANA Considerations Section in RFCs", "organization": "Internet Engineering Task Force (IETF)", "url": "https://datatracker.ietf.org/doc/html/rfc8126", "version_or_date": "RFC 8126, BCP 26, June 2017, Best Current Practice", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:15:00Z", "relevance": "Registry governance practice: graduated registration policies from First Come First Served through Expert Review and Specification Required, entry states including Reserved and Unassigned, a mandatory change-control policy and named change controller, and the warning that reclaiming previously assigned values 'can lead to interoperability problems'. Grounds review gating and the prohibition on silently reusing retired keys." }, { "id": "SRC-069", "title": "RFC 3339 - Date and Time on the Internet: Timestamps", "organization": "Internet Engineering Task Force (IETF)", "url": "https://datatracker.ietf.org/doc/html/rfc3339", "version_or_date": "RFC 3339, July 2002, Proposed Standard", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:15:00Z", "relevance": "Normative timestamp syntax requiring seconds and a stated numeric offset from UTC or the Z suffix, with -00:00 reserved for a known UTC instant whose local offset is unknown, and permitting second value 60 for leap seconds. Governs every time value in this model." }, { "id": "SRC-070", "title": "ISO/IEC 9075-2:2023 Information technology - Database languages SQL - Part 2: Foundation (SQL/Foundation)", "organization": "International Organization for Standardization / International Electrotechnical Commission", "url": "https://www.iso.org/standard/76584.html", "version_or_date": "ISO/IEC 9075-2:2023, sixth edition, June 2023 (temporal features introduced in SQL:2011)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:16:00Z", "relevance": "Normative basis for bitemporal records: application-time period tables carry the period during which a fact holds in the world, system-versioned tables carry the period during which the row was recorded, and system-versioned application-time period tables combine both. Grounds the two-dimensional as-of reconstruction and the append-only correction rule." }, { "id": "SRC-071", "title": "Constraints of the PROV Data Model (PROV-CONSTRAINTS)", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/prov-constraints/", "version_or_date": "W3C Recommendation, 30 April 2013", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:13:00Z", "relevance": "States that there is no inference making wasDerivedFrom transitive and gives a timing counterexample showing wasInformedBy is not transitive; defines ordering constraints (generation before usage, start before end) and impossibility constraints. Authority for treating transitivity as a declared, not assumed, property." }, { "id": "SRC-072", "title": "OWL 2 Web Ontology Language Structural Specification and Functional-Style Syntax (Second Edition)", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/owl2-syntax/", "version_or_date": "W3C Recommendation, 11 December 2012", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:14:00Z", "relevance": "Defines TransitiveObjectProperty and SubObjectPropertyOf with object property chains, plus the Section 11 global restrictions limiting where composite and transitive properties may be used in OWL 2 DL. Grounds the declared derivation basis for inferred and transitive edges and the need to bound closure." }, { "id": "SRC-073", "title": "RDF 1.1 Semantics", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/rdf11-mt/", "version_or_date": "W3C Recommendation, 25 February 2014", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:15:00Z", "relevance": "Defines entailment ('a graph G simply entails a graph E when every interpretation which satisfies G also satisfies E') and states that a valid inference does not oblige any application to make it, and that RDF is a purely assertional language. Basis for separating asserted facts from optionally materialised derived statements and for refusing absence semantics." }, { "id": "SRC-074", "title": "ISO/IEC 39075:2024 Information technology - Database languages - GQL", "organization": "ISO/IEC JTC 1/SC 32", "url": "https://www.iso.org/standard/76120.html", "version_or_date": "First edition, published April 2024", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:16:00Z", "relevance": "International standard for property-graph querying that normatively defines graph pattern matching, path patterns, match modes and path restrictors (walk, trail, acyclic, simple). Used here only as the alignment vocabulary for declaring which path semantics a recorded result assumed. Full normative text is paywalled; catalogue entry verified." }, { "id": "SRC-075", "title": "CycloneDX Bill of Materials Specification, Protocol Buffers schema bom-1.6.proto (Dependency message)", "organization": "OWASP Foundation / CycloneDX", "url": "https://raw.githubusercontent.com/CycloneDX/specification/master/schema/bom-1.6.proto", "version_or_date": "CycloneDX specification v1.6", "source_type": "schema", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-05T09:17:00Z", "relevance": "Defines ref, dependsOn and provides, and states that 'Components or services that are not represented in the dependency graph may have unknown dependencies. It is recommended that implementations assume this to be opaque and not an indicator of an object being dependency-free.' Direct authority for the opaque-absence rule." }, { "id": "SRC-076", "title": "OpenVEX Specification", "organization": "OpenVEX project (Chainguard and contributors)", "url": "https://raw.githubusercontent.com/openvex/spec/main/OPENVEX-SPEC.md", "version_or_date": "v0.2.0, revised 2023-07-18", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-05T09:18:00Z", "relevance": "Machine-readable justification labels (component_not_present, vulnerable_code_not_present, vulnerable_code_not_in_execute_path, vulnerable_code_cannot_be_controlled_by_adversary, inline_mitigations_already_exist) and the product/subcomponent structure. Model for typed edge-level propagation exclusion distinct from edge absence." }, { "id": "SRC-077", "title": "IEC 61025:2006 Fault tree analysis (FTA)", "organization": "International Electrotechnical Commission (IEC), TC 56 Dependability", "url": "https://webstore.iec.ch/en/publication/4311", "version_or_date": "Edition 2.0, published 2006-12-13", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:19:00Z", "relevance": "International standard for deductive top-down impact analysis; defines top event, intermediate and basic events, cut sets and minimal cut sets, and identification rules and symbols. Authority for cut-set results and for the requirement that assumptions and event boundaries be identified explicitly." }, { "id": "SRC-078", "title": "IEC 61078:2016 Reliability block diagrams", "organization": "International Electrotechnical Commission (IEC), TC 56 Dependability", "url": "https://webstore.iec.ch/en/publication/25647", "version_or_date": "Edition 3.0, published 2016-08-12", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:20:00Z", "relevance": "Standard for modelling dependability with success-path structures, covering qualitative and quantitative analysis, non-coherent and dynamic diagrams, Boolean algebra methods, and the stated relationship with fault tree analysis (IEC 61025) and Markov techniques. Authority for alternative-path and redundancy semantics as the dual of cut sets." }, { "id": "SRC-079", "title": "Strongly Connected Components - Neo4j Graph Data Science documentation", "organization": "Neo4j, Inc.", "url": "https://neo4j.com/docs/graph-data-science/current/algorithms/strongly-connected-components/", "version_or_date": "Graph Data Science, current documentation (versions 2.5 through 2026.07)", "source_type": "first-party-doc", "primary_source": false, "authority_tier": 3, "accessed_at": "2026-09-05T09:21:00Z", "relevance": "Working definition of strongly connected components ('a set is considered a strongly connected component if there is a directed path between each pair of nodes within the set') and the operational pattern of computing over a named in-memory graph projection with stream, stats, mutate and write modes, where results reflect the projected graph at execution time. Used as implementation evidence for snapshot-bound projections, not as normative authority." }, { "id": "SRC-080", "title": "Directive 2011/92/EU on the assessment of the effects of certain public and private projects on the environment (consolidated text, as amended by Directive 2014/52/EU)", "organization": "European Union (EUR-Lex)", "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:02011L0092-20140515", "version_or_date": "Consolidated text, consolidation date 15 May 2014", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T12:00:00Z", "relevance": "Annex IV point 3 requires a baseline scenario and the likely evolution without implementation; point 2 requires reasonable alternatives; point 5 requires direct effects and any indirect, secondary, cumulative, transboundary, short-, medium- and long-term, permanent and temporary, positive and negative effects; point 6 requires the forecasting methods used plus details of difficulties encountered and the main uncertainties. This is the strongest primary anchor for baseline, effect typing, horizon and completeness disclosure." }, { "id": "SRC-081", "title": "NIST Special Publication 800-30 Revision 1: Guide for Conducting Risk Assessments", "organization": "National Institute of Standards and Technology (NIST), U.S. Department of Commerce", "url": "https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf", "version_or_date": "Revision 1, September 2012", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T12:00:00Z", "relevance": "Defines a generic risk model separating threat source, threat event, vulnerability, predisposing condition, likelihood of occurrence and level of impact, and requires assessments to document scope, assumptions, constraints and the confidence and uncertainty in results. Grounds the separation of trigger from effect, the impact-oriented analysis approach, and mandatory assumption and uncertainty disclosure." }, { "id": "SRC-082", "title": "Minimum Requirements for Vulnerability Exploitability eXchange (VEX)", "organization": "Cybersecurity and Infrastructure Security Agency (CISA), U.S. Department of Homeland Security", "url": "https://www.cisa.gov/sites/default/files/2023-04/minimum-requirements-for-vex-508c.pdf", "version_or_date": "Version 1.0.0, April 2023", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T12:00:00Z", "relevance": "Establishes that a negative determination is a first-class published statement: the four statuses (not affected, affected, fixed, under investigation), the requirement that a not_affected status carry a justification such as vulnerable_code_not_in_execute_path or otherwise an impact_statement, and minimum metadata for author and role, timestamp, version and product identification including subcomponents and dependencies. Grounds explicit negative, unknown and non-propagating results." }, { "id": "SRC-083", "title": "Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA)", "organization": "European Union (EUR-Lex)", "url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:32022R2554", "version_or_date": "Regulation (EU) 2022/2554 of 14 December 2022", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T12:00:00Z", "relevance": "Requires business impact analysis of exposures to severe business disruptions using quantitative and qualitative criteria and scenario analysis, testing against severe but plausible scenarios, a register of information on ICT third-party contractual arrangements, and assessment of concentration risk. Grounds scenario-based impact analysis over a maintained dependency register, and the separation of that register from the analysis performed on it." }, { "id": "SRC-084", "title": "IFRS S2 Climate-related Disclosures", "organization": "International Sustainability Standards Board, IFRS Foundation", "url": "https://www.ifrs.org/issued-standards/ifrs-sustainability-standards-navigator/ifrs-s2-climate-related-disclosures/", "version_or_date": "Issued June 2023; effective for annual reporting periods beginning on or after 1 January 2024", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-05T12:00:00Z", "relevance": "Requires disclosure of effects over the short, medium and long term and the use of scenario analysis to assess resilience, with the inputs, assumptions and method of that analysis disclosed. Used analogically to ground horizon banding as a Dimension-declared parameter and scenario assumptions as disclosable inputs, not as a sector obligation." }, { "id": "SRC-085", "title": "Better Regulation Guidelines and Toolbox", "organization": "European Commission", "url": "https://commission.europa.eu/law/law-making-process/planning-and-proposing-law/better-regulation/better-regulation-guidelines-and-toolbox_en", "version_or_date": "Better Regulation Guidelines of 3 November 2021; Better Regulation Toolbox version of 1 December 2025", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T12:00:00Z", "relevance": "Sets out the European Commission impact assessment method in which options are compared against a defined baseline scenario, direct and indirect impacts are identified, analysis is proportionate to significance, and assumptions and uncertainty are made explicit. Corroborates the baseline and completeness requirements independently of the environmental impact assessment regime." }, { "id": "SRC-086", "title": "Guidelines for Human Exposure Assessment", "organization": "United States Environmental Protection Agency (EPA)", "url": "https://www.epa.gov/risk/guidelines-human-exposure-assessment", "version_or_date": "2019", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T12:00:00Z", "relevance": "Establishes exposure as contact or connection, formally distinct from dose and from adverse effect, organises assessment around explicit exposure scenarios, and requires variability and uncertainty to be characterised and confidence communicated. Grounds the separation of dependency-based exposure from assessed effect and from attributed cause." }, { "id": "SRC-087", "title": "NIST IR 8179, Criticality Analysis Process Model: Prioritizing Systems and Components", "organization": "National Institute of Standards and Technology (U.S. Department of Commerce)", "url": "https://csrc.nist.gov/pubs/ir/8179/final", "version_or_date": "April 2018 (final)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:12:00Z", "relevance": "Establishes criticality analysis as a structured method of prioritizing programs, systems and components by their importance to organizational goals and the impact of their failure; anchors criticality as a purpose-relative judgement rather than an intrinsic property." }, { "id": "SRC-088", "title": "NIST SP 800-30 Rev. 1, Guide for Conducting Risk Assessments", "organization": "National Institute of Standards and Technology (U.S. Department of Commerce)", "url": "https://csrc.nist.gov/pubs/sp/800/30/r1/final", "version_or_date": "September 2012 (final)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:12:00Z", "relevance": "Normative separation of likelihood of occurrence, level of impact and resulting risk across a three-tier hierarchy; source of the dependency-based definition of criticality and of qualitative/semi-quantitative assessment scales. Marks risk determination as host-owned." }, { "id": "SRC-089", "title": "NIST SP 800-160 Vol. 2 Rev. 1, Developing Cyber-Resilient Systems: A Systems Security Engineering Approach", "organization": "National Institute of Standards and Technology (U.S. Department of Commerce)", "url": "https://csrc.nist.gov/pubs/sp/800/160/v2/r1/final", "version_or_date": "December 2021 (final; supersedes Vol. 2, 2019)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:18:00Z", "relevance": "Cyber resiliency constructs (goals, objectives, techniques, approaches, design principles) and the capability to anticipate, withstand, recover from and adapt; supplies the definition of criticality as an attribute reflecting relative importance to stated goals, and grounds redundancy and mitigation referencing." }, { "id": "SRC-090", "title": "NIST Computer Security Resource Center Glossary - entries for 'criticality' and 'impact'", "organization": "National Institute of Standards and Technology (U.S. Department of Commerce)", "url": "https://csrc.nist.gov/glossary/term/criticality", "version_or_date": "Entries as published and accessed 5 September 2026, citing CNSSI 4009-2022, NIST SP 800-30 Rev. 1, NIST SP 800-60 Vol. 1/2 Rev. 1, NIST SP 800-160 Vol. 2 Rev. 1 and NIST SP 800-160v1r1", "source_type": "registry", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:26:00Z", "relevance": "Documents four coexisting and non-identical definitions of criticality (consequence of incorrect behaviour, degree of mission dependence, relative importance to stated goals, degree of impact on development or operation), which is direct evidence that criticality values must be scheme-qualified." }, { "id": "SRC-091", "title": "Common Vulnerability Scoring System v4.0 Specification Document", "organization": "Forum of Incident Response and Security Teams (FIRST)", "url": "https://www.first.org/cvss/v4.0/specification-document", "version_or_date": "Document version 1.2, 1 November 2023 (updated 18 June 2024)", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-05T09:16:00Z", "relevance": "A published severity scheme with Base/Threat/Environmental/Supplemental metric groups, an explicit vector-string notation, a None-Critical rating band and Environmental metrics that let a consumer modify severity for asset importance; also states that factors outside CVSS belong to broader risk processes." }, { "id": "SRC-092", "title": "Stakeholder-Specific Vulnerability Categorization (SSVC)", "organization": "Cybersecurity and Infrastructure Security Agency (CISA, U.S. Department of Homeland Security)", "url": "https://www.cisa.gov/stakeholder-specific-vulnerability-categorization-ssvc", "version_or_date": "CISA decision tree customization published 2020; page accessed 5 September 2026", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:34:00Z", "relevance": "A competing, non-numeric prioritisation scheme using decision points (exploitation, technical impact, automatable, mission prevalence, public well-being) and outcomes Track / Track* / Attend / Act - evidence that severity outputs are scheme-shaped and not interconvertible with numeric scores." }, { "id": "SRC-093", "title": "National Critical Functions", "organization": "Cybersecurity and Infrastructure Security Agency (CISA, U.S. Department of Homeland Security)", "url": "https://www.cisa.gov/national-critical-functions", "version_or_date": "NCF set of 55 functions in four categories; page content updated through September 2020, accessed 5 September 2026", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:14:00Z", "relevance": "Defines functions whose disruption would have a debilitating effect and frames holistic analysis of risks and associated dependencies with cascading impacts within and across sectors - primary support for propagation, cross-boundary affected sets and functional rather than entity-level criticality." }, { "id": "SRC-094", "title": "Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA)", "organization": "European Parliament and Council of the European Union", "url": "https://eur-lex.europa.eu/eli/reg/2022/2554/oj/eng", "version_or_date": "Adopted 14 December 2022", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:30:00Z", "relevance": "Binding treatment of critical or important functions, ICT concentration risk, criticality designation criteria for third-party providers and mandatory exit strategies and transition periods - primary support for concentration exposure and substitutability being first-class, and for their designation being externally owned." }, { "id": "SRC-095", "title": "IEC 60812:2018, Failure modes and effects analysis (FMEA and FMECA)", "organization": "International Electrotechnical Commission", "url": "https://webstore.iec.ch/en/publication/26359", "version_or_date": "Edition 3.0, published 10 August 2018", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:14:00Z", "relevance": "Applies to hardware, software, processes including human action and their interfaces; states that where ranking of criticality involves at least the severity of consequences the analysis becomes FMECA, and offers alternative means of calculating risk priority numbers - evidence that severity ranking methods are plural and must be named." }, { "id": "SRC-096", "title": "Principles for operational resilience", "organization": "Basel Committee on Banking Supervision, Bank for International Settlements", "url": "https://www.bis.org/bcbs/publ/d509.htm", "version_or_date": "Consultative document, 6 August 2020 (final principles issued 31 March 2021)", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:30:00Z", "relevance": "Principles-based supervisory framing of the ability to withstand operational risk-related events, drawing on outsourcing guidance - used to place tolerance for disruption, critical operations and third-party reliance in a host discipline outside this model." }, { "id": "SRC-097", "title": "CycloneDX Specification Overview (standardised as ECMA-424)", "organization": "OWASP Foundation and Ecma International (TC54)", "url": "https://cyclonedx.org/specification/overview/", "version_or_date": "CycloneDX v1.7 released 21 October 2025; ECMA-424 published 10 December 2025", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-05T09:36:00Z", "relevance": "An interoperable representation of components, services, dependencies and relationships in which known vulnerabilities and their exploitability are communicated - the exemplar for keeping dependency facts separate from attached severity assertions and for exchanging both under a versioned specification." }, { "id": "SRC-098", "title": "CreationInfo - SPDX Specification 3.0.1 (Core Model)", "organization": "SPDX Project / The Linux Foundation", "url": "https://spdx.github.io/spdx-spec/v3.0.1/model/Core/Classes/CreationInfo/", "version_or_date": "SPDX 3.0.1, December 2024", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:13:00Z", "relevance": "Requires every Element to carry created (DateTime), createdBy (Agent: Person, Organization or SoftwareAgent) and specVersion, and distinguishes the modelled creation time from the time the data was generated. Grounds the issuer archetype and the event-time versus ingestion-time separation." }, { "id": "SRC-099", "title": "Annotation - SPDX Specification 3.0.1 (Core Model)", "organization": "SPDX Project / The Linux Foundation", "url": "https://spdx.github.io/spdx-spec/v3.0.1/model/Core/Classes/Annotation/", "version_or_date": "SPDX 3.0.1, December 2024", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:13:00Z", "relevance": "Models a typed, separately-attributed assertion about an existing Element with its own creationInfo and subject. Grounds reviewer and analyst commentary as first-class, independently attributed records rather than mutations of the underlying dependency assertion." }, { "id": "SRC-100", "title": "Verifiable Credentials Data Model v2.0", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/vc-data-model-2.0/", "version_or_date": "W3C Recommendation, 15 May 2025", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:14:00Z", "relevance": "Separates issuer, holder, subject and verifier roles, adds validFrom/validUntil validity periods and credentialStatus, and distinguishes verification (authorship) from validation (fit for a verifier's purpose). Grounds the issuer archetype, time-bounded role bindings and the reviewer/approver split." }, { "id": "SRC-101", "title": "ODRL Vocabulary & Expression 2.2", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/odrl-vocab/", "version_or_date": "W3C Recommendation, 15 February 2018", "source_type": "ontology", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:14:00Z", "relevance": "Defines Party functions (assigner, assignee, and odrl:function roles such as informedParty, trackingParty, dataController) and constraint left operands including odrl:purpose, odrl:spatial, odrl:recipient and odrl:industry. Grounds purpose and jurisdiction qualifiers and the observer archetype without embedding polity doctrine." }, { "id": "SRC-102", "title": "RFC 8126 / BCP 26 - Guidelines for Writing an IANA Considerations Section in RFCs", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/rfc/rfc8126.html", "version_or_date": "RFC 8126, BCP 26, June 2017", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:15:00Z", "relevance": "Establishes registration-governance archetypes: Designated Expert (reviewer) who must coordinate review, respond in bounded time, defend decisions and recuse on conflict of interest; Change Controller as the party authorized to approve future modification; graduated approval policies; entry states (reserved, deprecated, obsolete); and an appeals path for contested expert decisions." }, { "id": "SRC-103", "title": "eXtensible Access Control Markup Language (XACML) Version 3.0 Plus Errata 01, Core Specification", "organization": "OASIS", "url": "https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html", "version_or_date": "OASIS Standard, 22 January 2013", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:16:00Z", "relevance": "Separates policy administration (PAP), decision (PDP), enforcement (PEP) and attribute supply (PIP), with obligations and advice discharged by the enforcement point. Provides the normative basis for keeping authorization decisions and enforcement outside this model while it supplies declarative role and duty attributes." }, { "id": "SRC-104", "title": "NIST SP 800-53 Rev. 5 - Security and Privacy Controls for Information Systems and Organizations", "organization": "National Institute of Standards and Technology (NIST), U.S. Department of Commerce", "url": "https://csrc.nist.gov/pubs/sp/800/53/r5/upd1/final", "version_or_date": "Rev. 5, September 2020, updates through 10 December 2020; DOI 10.6028/NIST.SP.800-53r5", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:16:00Z", "relevance": "Control catalogue organised into families including Access Control (AC), Audit and Accountability (AU), Risk Assessment (RA), Program Management (PM) and Supply Chain Risk Management (SR). Establishes that access control, audit and accountability, and supply-chain governance are distinct control families with distinct owners, supporting the separation of this model from access and audit models." }, { "id": "SRC-105", "title": "NIST SP 800-37 Rev. 2 - Risk Management Framework for Information Systems and Organizations", "organization": "National Institute of Standards and Technology (NIST), U.S. Department of Commerce", "url": "https://csrc.nist.gov/pubs/sp/800/37/r2/final", "version_or_date": "Rev. 2, December 2018; DOI 10.6028/NIST.SP.800-37r2", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:17:00Z", "relevance": "Defines an explicit role set - authorizing official, system owner, common control provider, information owner/steward, risk executive function, security and privacy officers - and an authorization decision that constitutes accepted risk, tracked with a plan of action and milestones. Grounds the approver, endpoint steward and exception-authority archetypes." }, { "id": "SRC-106", "title": "NIST Computer Security Resource Center Glossary - separation of duty", "organization": "National Institute of Standards and Technology (NIST), U.S. Department of Commerce", "url": "https://csrc.nist.gov/glossary/term/separation_of_duty", "version_or_date": "Glossary entry sourced from NIST SP 800-192, NISTIR 8403 and NIST IR 8539; accessed 5 September 2026", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:18:00Z", "relevance": "Defines separation of duty as preventing any single user holding privileges sufficient for unilateral misuse, and distinguishes static separation (conflicting roles never assigned to the same user), dynamic separation (enforced at access time, e.g. two-person rules) and history-based variants. Grounds the incompatible-duty declarations." }, { "id": "SRC-107", "title": "Regulation (EU) 2016/679 (General Data Protection Regulation)", "organization": "European Parliament and Council of the European Union", "url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng", "version_or_date": "Regulation of 27 April 2016, consolidated text on EUR-Lex", "source_type": "legislation", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:18:00Z", "relevance": "Article 4(7)/(8) controller and processor; Article 5(1)(b) purpose limitation; Article 5(1)(e) storage limitation; Article 5(2) accountability; Article 6 lawful basis; Article 30 records of processing activities. Grounds mandatory purpose qualifiers, retention referral and the requirement that personal data in role bindings be minimised and justified." }, { "id": "SRC-108", "title": "Unauthorized Dispositions of Federal Records", "organization": "U.S. National Archives and Records Administration (NARA)", "url": "https://www.archives.gov/records-mgmt/resources/unauthorized-dispositions", "version_or_date": "Current guidance page, accessed 5 September 2026; cites 44 U.S.C. 3106 and 36 CFR Part 1230", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:19:00Z", "relevance": "Establishes that unlawful removal, deletion, alteration or destruction of records must be reported to the Archivist under 44 U.S.C. 3106 and 36 CFR Part 1230, and that a records-management oversight function - not the originating system - owns adjudication. Grounds the legal-hold marker and the outward referral of disposition execution." }, { "id": "SRC-109", "title": "RFC 8785: JSON Canonicalization Scheme (JCS)", "organization": "RFC Editor / IETF Independent Submission", "url": "https://www.rfc-editor.org/info/rfc8785", "version_or_date": "June 2020, Informational", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-05T09:10:00Z", "relevance": "Defines deterministic JSON serialization (lexicographic property sorting, whitespace removal, ECMAScript number serialization, UTF-8 output) and its I-JSON limits, including no duplicate keys, IEEE 754 double number range and no Unicode normalization." }, { "id": "SRC-110", "title": "RDF Dataset Canonicalization: A Standard RDF Dataset Canonicalization Algorithm (RDFC-1.0)", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/rdf-canon/", "version_or_date": "W3C Recommendation, 21 May 2024", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:11:00Z", "relevance": "Defines deterministic blank-node labelling and canonical form for RDF datasets, enabling comparison, hashing and signing of graph-shaped dependency projections independent of serialization order." }, { "id": "SRC-111", "title": "RFC 6902: JavaScript Object Notation (JSON) Patch", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/info/rfc6902", "version_or_date": "April 2013, Proposed Standard", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:12:00Z", "relevance": "Defines the add, remove, replace, move, copy and test operations, JSON Pointer targeting, the test operation as a precondition mechanism, and all-or-nothing patch application." }, { "id": "SRC-112", "title": "RFC 7396: JSON Merge Patch", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/info/rfc7396", "version_or_date": "October 2014, Proposed Standard", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:13:00Z", "relevance": "Defines merge-patch semantics where null means removal and arrays are replaced wholesale, and states the format is inappropriate for documents that use explicit null values or need partial array edits." }, { "id": "SRC-113", "title": "RFC 3339: Date and Time on the Internet: Timestamps", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/info/rfc3339", "version_or_date": "July 2002, Proposed Standard", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:14:00Z", "relevance": "Defines the date-time profile of ISO 8601 with mandatory seconds, the Z designator for a zero UTC offset, numeric offsets computed as local time minus UTC, leap-second value 60, and -00:00 as the unknown-local-offset convention." }, { "id": "SRC-114", "title": "RFC 9562: Universally Unique IDentifiers (UUIDs)", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/info/rfc9562", "version_or_date": "May 2024, Proposed Standard", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:15:00Z", "relevance": "Defines UUID versions 1 through 8 and states that implementations SHOULD use UUIDv7, a Unix-epoch time-ordered identifier sortable as opaque bytes, for new time-ordered identifier needs." }, { "id": "SRC-115", "title": "RFC 9535: JSONPath: Query Expressions for JSON", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/info/rfc9535", "version_or_date": "February 2024, Proposed Standard", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:19:00Z", "relevance": "Defines query expressions, nodelist results and normalized paths as a canonical, testable node-location form, and positions JSONPath as a companion to JSON Pointer rather than a replacement." }, { "id": "SRC-116", "title": "RFC 8141: Uniform Resource Names (URNs)", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/info/rfc8141", "version_or_date": "April 2017, Proposed Standard", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:21:00Z", "relevance": "Defines URN syntax, namespace identifiers and namespace-specific strings assigned and managed consistently by a delegated authority committed to persistence and non-reassignment, and separates resolution, service and fragment parameters from the identifier itself." }, { "id": "SRC-117", "title": "SLSA Specification v1.2 - Build Provenance", "organization": "Open Source Security Foundation (OpenSSF) / SLSA project", "url": "https://slsa.dev/spec/v1.2/build-provenance", "version_or_date": "SLSA v1.2, Approved track", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-05T09:22:00Z", "relevance": "Defines verifiable provenance describing where, when and how an artifact was produced, serialized as an in-toto statement with subject digests, a build definition including resolved dependencies, and a builder identity that bounds the trust claim." }, { "id": "SRC-118", "title": "Data Catalog Vocabulary (DCAT) - Version 3", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/vocab-dcat-3/", "version_or_date": "W3C Recommendation, 22 August 2024", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:24:00Z", "relevance": "Provides dcat:previousVersion, dcat:hasCurrentVersion and dcat:version for lifecycle version chains, dcat:DatasetSeries for grouped releases, and dcat:CatalogRecord with dcterms:issued and dcterms:modified separating resource dates from registration dates." }, { "id": "SRC-119", "title": "RFC 9110: HTTP Semantics", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/rfc/rfc9110.html", "version_or_date": "STD 97, June 2022", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T08:41:00Z", "relevance": "Normative definitions of safe and idempotent methods (9.2.1, 9.2.2: repeating a request has the same intended effect as a single one), conditional requests and preconditions (13.1, If-Match with ETag validators against the lost-update problem), and the 409 Conflict / 412 Precondition Failed outcome semantics reused here as interface-neutral command semantics." }, { "id": "SRC-120", "title": "RFC 9457: Problem Details for HTTP APIs", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/rfc/rfc9457.html", "version_or_date": "Standards Track, July 2023 (obsoletes RFC 7807)", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T08:44:00Z", "relevance": "Machine-readable failure representation: type, title, status, detail, instance plus extension members, and the requirement to vet error content so failures do not leak exploitable detail. Anchors the failure half of the command result contract." }, { "id": "SRC-121", "title": "RFC 6902: JavaScript Object Notation (JSON) Patch", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/rfc/rfc6902.html", "version_or_date": "Standards Track, April 2013", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:02:00Z", "relevance": "Atomic partial-update semantics: the whole patch fails if any operation fails, and the test operation expresses a precondition. Anchors patch rules and the all-or-nothing application of a revision." }, { "id": "SRC-122", "title": "RFC 8785: JSON Canonicalization Scheme (JCS)", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/rfc/rfc8785.html", "version_or_date": "Informational, June 2020", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-05T09:03:00Z", "relevance": "Deterministic serialization for hashing and signing (lexicographic UTF-16 property ordering, ECMAScript number serialization). Used for request fingerprints that decide whether a repeated command is a replay, and for artifact integrity hashes." }, { "id": "SRC-123", "title": "CloudEvents Specification, Version 1.0.2", "organization": "Cloud Native Computing Foundation (CNCF) Serverless Working Group", "url": "https://github.com/cloudevents/spec/blob/v1.0.2/cloudevents/spec.md", "version_or_date": "v1.0.2", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-05T08:42:00Z", "relevance": "Event envelope semantics: required id, source, specversion, type; optional subject and time; the rule that producers MUST ensure source+id is unique per distinct event; time MUST follow RFC 3339 and may be occurrence time or a consistent producer algorithm. Anchors emitted-event identity and the caveat about producer-chosen time." }, { "id": "SRC-124", "title": "HL7 FHIR Release 5 - RESTful API (managing resource contention, conditional create, versioning)", "organization": "Health Level Seven International (HL7)", "url": "https://hl7.org/fhir/R5/http.html", "version_or_date": "FHIR R5 (v5.0.0), 26 March 2023", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T08:48:00Z", "relevance": "Weak ETag derived from versionId with If-Match for version-aware update and 412 (or 409) on mismatch; conditional create via If-None-Exist returning 200 on one match instead of duplicating and 412 on multiple matches; version-specific retrieval by (id, versionId); servers may require preconditions. Anchors concurrency, idempotent declare and immutable version identity." }, { "id": "SRC-125", "title": "HL7 FHIR Release 5 - ArtifactAssessment resource", "organization": "Health Level Seven International (HL7)", "url": "https://hl7.org/fhir/R5/artifactassessment.html", "version_or_date": "FHIR R5 (v5.0.0), maturity level 1, Trial Use", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-05T08:52:00Z", "relevance": "A separable assessment about another record, with workflowStatus (submitted, triaged, waiting-for-input, resolved-no-change, resolved-change-required, deferred, duplicate, applied, published, entered-in-error), disposition (unresolved, not-persuasive, persuasive, persuasive-with-modification, not-persuasive-with-modification) and artifactReference/Canonical/Uri. Anchors the review and approval record as a distinct artifact whose attribution differs from the statement." }, { "id": "SRC-126", "title": "HL7 FHIR Release 5 - OperationOutcome resource", "organization": "Health Level Seven International (HL7)", "url": "https://hl7.org/fhir/R5/operationoutcome.html", "version_or_date": "FHIR R5 (v5.0.0), Normative since v4.0.0", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T08:53:00Z", "relevance": "A structured collection of issues with severity (fatal, error, warning, information, success), an issue type code and an expression locating the offending element. Anchors the validation outcome report and the blocking-versus-advisory distinction." }, { "id": "SRC-127", "title": "HL7 FHIR Release 5 - PublicationStatus value set", "organization": "Health Level Seven International (HL7)", "url": "https://hl7.org/fhir/R5/valueset-publication-status.html", "version_or_date": "FHIR R5 (v5.0.0), normative, required binding", "source_type": "classifier", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T08:54:00Z", "relevance": "draft (under development, not ready for normal use), active (ready for normal use), retired (withdrawn or superseded, should no longer be used) and unknown. A standards-backed minimum lifecycle spine that the command state machine specializes without redefining." }, { "id": "SRC-128", "title": "The Idempotency-Key HTTP Header Field (draft-ietf-httpapi-idempotency-key-header-07)", "organization": "Internet Engineering Task Force (IETF) HTTPAPI Working Group", "url": "https://datatracker.ietf.org/doc/html/draft-ietf-httpapi-idempotency-key-header-07", "version_or_date": "Internet-Draft revision 07, 15 October 2025; expired, not published as an RFC", "source_type": "standard", "primary_source": false, "authority_tier": 3, "accessed_at": "2026-09-05T08:50:00Z", "relevance": "Evidence that a client-supplied idempotency key for non-idempotent operations is common practice but has no stable normative status; used only to show the gap, with the binding requirements taken from RFC 9110 idempotency and conditional requests instead." }, { "id": "SRC-129", "title": "SPARQL 1.1 Query Language", "organization": "World Wide Web Consortium (W3C)", "url": "https://www.w3.org/TR/sparql11-query/", "version_or_date": "W3C Recommendation 21 March 2013", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:00:00Z", "relevance": "Normative semantics for dataset scope (FROM / FROM NAMED / GRAPH), property paths including arbitrary-length and inverse paths, the rule that connectivity matching introduces no duplicate paths and that cycles do not yield infinite results, negation scoped to the queried dataset, and the statement that OFFSET and LIMIT are only useful when ordering is made predictable by ORDER BY." }, { "id": "SRC-130", "title": "OGC API - Features - Part 1: Core corrigendum", "organization": "Open Geospatial Consortium (OGC)", "url": "https://docs.ogc.org/is/17-069r4/17-069r4.html", "version_or_date": "Version 1.0.1, published 2022-05-11", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T09:00:00Z", "relevance": "Normative paging pattern: numberMatched and numberReturned, permission to omit numberMatched when the matched count is unknown or difficult to compute, server-imposed maximum limits that must not error, the permission to return fewer items than requested, and the next link relation for continuation." }, { "id": "SRC-131", "title": "RFC 7089: HTTP Framework for Time-Based Access to Resource States -- Memento", "organization": "Internet Engineering Task Force (IETF)", "url": "https://www.rfc-editor.org/rfc/rfc7089.html", "version_or_date": "RFC 7089, December 2013, Informational", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-05T09:00:00Z", "relevance": "Datetime negotiation pattern for as-of reads: a requested datetime is resolved by best match to an available prior state, and the response states the datetime of the state actually returned; also the notion that a returned prior state is frozen. Grounds the requirement to disclose requested instant versus resolved reference point." }, { "id": "SRC-132", "title": "CycloneDX Bill of Materials Standard - JSON Schema 1.6", "organization": "OWASP Foundation / Ecma International (ECMA-424)", "url": "https://cyclonedx.org/schema/bom-1.6.schema.json", "version_or_date": "bom-1.6.schema.json ($id http://cyclonedx.org/schema/bom-1.6.schema.json)", "source_type": "schema", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-05T09:00:00Z", "relevance": "Dependency object (ref, dependsOn, provides) shows typed asymmetric edges; compositions.aggregate enumerates completeness including complete, incomplete, partition-qualified incomplete values (first-party / third-party, proprietary / open source), unknown ('best-effort ... completeness is inconclusive') and not_specified, grounding partition-aware completeness disclosure." }, { "id": "SRC-133", "title": "deps.dev API v3 documentation", "organization": "Google", "url": "https://docs.deps.dev/api/v3/", "version_or_date": "v3 (with v3alpha Query), documentation as accessed 2026-09-05", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 3, "accessed_at": "2026-09-05T09:00:00Z", "relevance": "Working example of dependency query operations: GetRequirements returns declared constraints while GetDependencies returns a resolved graph with SELF/DIRECT/INDIRECT nodes and edges; node-level and graph-level errors are reported without suppressing results; GetProject surfaces externally computed OpenSSF Scorecard health data; Query results are capped. Evidences declared-versus-resolved distinction, partial-result disclosure and health-as-reference." }, { "id": "SRC-134", "title": "AIP-158: Pagination", "organization": "Google (API Improvement Proposals)", "url": "https://google.aip.dev/158", "version_or_date": "Approved; created 2019-02-18", "source_type": "secondary", "primary_source": false, "authority_tier": 3, "accessed_at": "2026-09-05T09:00:00Z", "relevance": "Widely followed design guidance, not a standard: page tokens must be opaque and grant no authorization, servers may return fewer results than requested including zero without being at the end, other request arguments must stay consistent across pages, and tokens may expire. Explicitly offers no cross-page consistency guarantee, which is why this model requires reference-point binding instead." }, { "id": "SRC-135", "title": "ISO/IEC 39075 Database Language GQL (JTC 1 information article)", "organization": "ISO/IEC JTC 1", "url": "https://jtc1info.org/wp-content/uploads/2024/04/2024-Article-39075-Database-Language-GQL.docx.pdf", "version_or_date": "2024 article describing ISO/IEC 39075:2024, published April 2024", "source_type": "public-authority", "primary_source": false, "authority_tier": 2, "accessed_at": "2026-09-05T09:00:00Z", "relevance": "Authority-published description of ISO/IEC 39075:2024 GQL: property-graph data model, graph pattern matching, path patterns and path finding, and its relationship to SQL/PGQ. Used as an alignment pointer for path-mode vocabulary (walk, trail, simple, acyclic); the standard text itself is paywalled, so path-mode detail is treated as an alignment claim rather than verified normative text." }, { "id": "SRC-136", "title": "OWASP CycloneDX Authoritative Guide to SBOM", "organization": "OWASP Foundation / CycloneDX", "url": "https://cyclonedx.org/guides/OWASP_CycloneDX-Authoritative-Guide-to-SBOM-en.pdf", "version_or_date": "Current edition, accessed 2026-09-05", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-05T00:00:00Z", "relevance": "Documents the compositions aggregate values (complete, incomplete, incomplete_first_party_only, incomplete_third_party_only, unknown, not_specified) and the dependencies graph fields ref, dependsOn and provides; grounds scoped coverage disclosure and provided/virtual capabilities." }, { "id": "SRC-137", "title": "Static Analysis Results Interchange Format (SARIF) Version 2.1.0, OASIS Standard", "organization": "OASIS Open", "url": "https://docs.oasis-open.org/sarif/sarif/v2.1.0/os/sarif-v2.1.0-os.html", "version_or_date": "2.1.0, 27 March 2020", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T00:00:00Z", "relevance": "Provides graph, node, edge, graphTraversal and edgeTraversal for replayable paths through a graph, result.baselineState (new, unchanged, updated, absent), result.rank, human-readable message alongside machine-readable properties, and resultProvenance with first/last detection times." }, { "id": "SRC-138", "title": "STIX Version 2.1, OASIS Standard", "organization": "OASIS Open", "url": "https://docs.oasis-open.org/cti/stix/v2.1/os/stix-v2.1-os.html", "version_or_date": "2.1, OASIS Standard", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T00:00:00Z", "relevance": "Defines a confidence property with named scales, the Opinion object (opinion, explanation, authors, object_refs) for retaining divergent assessments, and revoked / valid_from / valid_until / created / modified for staleness and withdrawal." }, { "id": "SRC-139", "title": "Traffic Light Protocol (TLP) Version 2.0 Standard Definitions and Usage Guidance", "organization": "FIRST (Forum of Incident Response and Security Teams)", "url": "https://www.first.org/tlp/", "version_or_date": "TLP 2.0, August 2022", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-05T00:00:00Z", "relevance": "TLP:RED, TLP:AMBER, TLP:AMBER+STRICT, TLP:GREEN and TLP:CLEAR with their sharing rules and document marking requirements; the handling vocabulary carried on report renditions and notification-content drafts." }, { "id": "SRC-140", "title": "NIST Computer Security Resource Center Glossary - security impact analysis", "organization": "National Institute of Standards and Technology (NIST)", "url": "https://csrc.nist.gov/glossary/term/security_impact_analysis", "version_or_date": "Current entry, citing NIST SP 800-128, SP 800-137, SP 800-30 Rev. 1, SP 800-39 and SP 800-53 Rev. 5", "source_type": "public-authority", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T00:00:00Z", "relevance": "Defines impact analysis as the analysis conducted to determine the extent to which a change has affected a system - an analytical act distinct from configuration change control; the authority for separating report generation from approval and implementation." }, { "id": "SRC-141", "title": "SPDX 3.0.1 Specification - Serializations", "organization": "The Linux Foundation / SPDX Project", "url": "https://spdx.github.io/spdx-spec/v3.0.1/serializations/", "version_or_date": "v3.0.1", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T10:00:00Z", "relevance": "A domain standard that defines multiple parallel serializations (JSON-LD, Turtle, N-Triples, RDF/XML) plus a canonical serialization notion, while making no round-trip or loss statement - direct evidence that loss reporting must be added by the adopting model." }, { "id": "SRC-142", "title": "RFC 4180: Common Format and MIME Type for Comma-Separated Values (CSV) Files", "organization": "IETF", "url": "https://www.rfc-editor.org/rfc/rfc4180.html", "version_or_date": "October 2005, Informational", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-05T10:00:00Z", "relevance": "Registers text/csv and documents that CSV has never been formally specified, admitting wide interpretation variance. Grounds the mandatory loss declaration and dialect pinning for tabular projections." }, { "id": "SRC-143", "title": "RDF 1.2 Concepts and Abstract Syntax", "organization": "W3C", "url": "https://www.w3.org/TR/rdf12-concepts/", "version_or_date": "Candidate Recommendation Snapshot, 07 April 2026", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T10:00:00Z", "relevance": "Triple terms, rdf:reifies and reifiers allow statements about statements including non-asserted ones; the spec states that relations involving more than two entities can only be expressed indirectly. Grounds the RDF expressivity entry and the uncertainty/non-assertion mapping." }, { "id": "SRC-144", "title": "Defining N-ary Relations on the Semantic Web (W3C Working Group Note)", "organization": "W3C Semantic Web Best Practices and Deployment Working Group", "url": "https://www.w3.org/TR/swbp-n-aryRelations/", "version_or_date": "12 April 2006, Working Group Note (informative)", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-05T10:00:00Z", "relevance": "Pattern 1 (a class for the relation instance) and Pattern 2 (lists) for relations carrying probability, severity or temporal qualifiers. Grounds the reified-assertion projection pattern used when a target format has only binary edges." }, { "id": "SRC-145", "title": "JSON-LD 1.1: A JSON-based Serialization for Linked Data", "organization": "W3C", "url": "https://www.w3.org/TR/json-ld11/", "version_or_date": "W3C Recommendation, 16 July 2020", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T10:00:00Z", "relevance": "@context term-to-IRI mapping, @id/@type/@graph, and explicitly enumerated features without direct RDF equivalents (@json literals, blank node predicates, @list ordering). Grounds namespace binding and the JSON↔RDF loss boundary." }, { "id": "SRC-146", "title": "Model for Tabular Data and Metadata on the Web", "organization": "W3C", "url": "https://www.w3.org/TR/tabular-data-model/", "version_or_date": "W3C Recommendation, 17 December 2015", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T10:00:00Z", "relevance": "Table group/table/column/row/cell model with core and additional annotations; cells hold atomic or list values only, with no nested structures and no graph linking. Grounds the CSV expressivity ceiling and the sidecar-metadata requirement." }, { "id": "SRC-147", "title": "YAML Ain't Markup Language (YAML) version 1.2.2", "organization": "YAML Language Development Team", "url": "https://yaml.org/spec/1.2.2/", "version_or_date": "Revision 1.2.2, 1 October 2021", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-05T10:00:00Z", "relevance": "YAML 1.2 is a strict superset of JSON; anchor names are a serialization detail discarded after composing; indentation, styles and comments are presentation details that must not convey content. Grounds YAML round-trip limits and comment-loss declarations." }, { "id": "SRC-148", "title": "CommonMark Spec", "organization": "CommonMark", "url": "https://spec.commonmark.org/0.31.2/", "version_or_date": "Version 0.31.2, 28 January 2024", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-05T10:00:00Z", "relevance": "Unambiguous Markdown-to-AST/HTML parsing, seven HTML block types passed through as raw HTML, and no statement about round-tripping back from HTML. Grounds Markdown as a presentation-only, non-authoritative projection requiring an embedded machine block." }, { "id": "SRC-149", "title": "HTML Standard - Microdata", "organization": "WHATWG", "url": "https://html.spec.whatwg.org/multipage/microdata.html", "version_or_date": "Living Standard, 4 September 2026", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T10:00:00Z", "relevance": "itemscope/itemtype/itemid/itemprop/itemref and the microdata-to-JSON algorithm; properties are unordered except among same-named properties. Grounds embedding machine-readable assertion identity and endpoint roles in HTML projections and the ordering caveat." }, { "id": "SRC-150", "title": "OpenAPI Specification v3.1.1", "organization": "OpenAPI Initiative (The Linux Foundation)", "url": "https://spec.openapis.org/oas/v3.1.1.html", "version_or_date": "3.1.1, 24 October 2024", "source_type": "standard", "primary_source": true, "authority_tier": 1, "accessed_at": "2026-09-05T10:00:00Z", "relevance": "Media-type keyed content maps with most-specific-key selection, Schema Object as a superset of JSON Schema 2020-12, and separation of specification version, document version and API version. Grounds API projection description and three-way version distinction." }, { "id": "SRC-151", "title": "Model Context Protocol - Versioning", "organization": "Model Context Protocol project", "url": "https://modelcontextprotocol.io/specification/versioning", "version_or_date": "Current protocol version 2026-07-28", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-05T10:00:00Z", "relevance": "Date-string protocol versions incremented only on backwards-incompatible change, per-request protocolVersion declaration, UnsupportedProtocolVersionError and a documented deprecation window. Grounds compatibility declarations for MCP projections." }, { "id": "SRC-152", "title": "Model Context Protocol - Server Features: Resources", "organization": "Model Context Protocol project", "url": "https://modelcontextprotocol.io/specification/2026-07-28/server/resources", "version_or_date": "Revision 2026-07-28", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-05T10:00:00Z", "relevance": "RFC 3986 resource URIs, resources/list pagination cursors, mimeType, text vs base64 blob contents, subscriptions, and the rule that an empty contents array must not be returned for a non-existent resource. Grounds MCP projection addressing and ambiguity avoidance." }, { "id": "SRC-153", "title": "MongoDB Extended JSON (v2)", "organization": "MongoDB, Inc.", "url": "https://www.mongodb.com/docs/manual/reference/mongodb-extended-json/", "version_or_date": "MongoDB Manual v8.3 (Current)", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 3, "accessed_at": "2026-09-05T10:00:00Z", "relevance": "Canonical mode preserves BSON type information while relaxed mode loses Int32/Int64/Double distinctions and date precision context. Grounds the document-store projection mode requirement and its declared loss." }, { "id": "SRC-154", "title": "gitattributes - Defining attributes per path", "organization": "Git project (git-scm.com)", "url": "https://git-scm.com/docs/gitattributes", "version_or_date": "Git documentation, current", "source_type": "first-party-doc", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-05T10:00:00Z", "relevance": "text/eol normalization, diff and merge drivers, and clean/smudge filters with the explicit idempotence requirement that clean→clean equals clean and smudge→smudge→clean equals clean. Grounds byte-stability and round-trip rules for file/Git projections." }, { "id": "SRC-155", "title": "Pro Git - Git Internals: Git Objects", "organization": "Git community (Chacon & Straub)", "url": "https://git-scm.com/book/en/v2/Git-Internals-Git-Objects", "version_or_date": "Pro Git, 2nd edition (online)", "source_type": "secondary", "primary_source": false, "authority_tier": 3, "accessed_at": "2026-09-05T10:00:00Z", "relevance": "Content-addressable blob/tree/commit objects where the hash is both identity and integrity check, forming an immutable DAG. Used to explain why a Git projection's commit identity is a carrier identifier, not the assertion identifier." }, { "id": "SRC-156", "title": "Semantic Versioning 2.0.0", "organization": "Semantic Versioning (semver.org)", "url": "https://semver.org/", "version_or_date": "2.0.0", "source_type": "standard", "primary_source": true, "authority_tier": 2, "accessed_at": "2026-09-05T10:00:00Z", "relevance": "MAJOR/MINOR/PATCH increment rules, with rule 8 requiring a MAJOR increment for any backward-incompatible public-API change. Grounds the compatibility class assigned to a projection schema change." } ], "structure": { "bundles": [ { "id": "dep-core-assertion-envelope", "name": "Dependency assertion envelope", "description": "The identified, attributed, scoped and versioned statement that carries a dependency claim, treated as a first-class record distinct from the endpoints it relates.", "rationale": "PROV shows that a dependency relation only becomes describable, attributable and disputable once it is reified into an identified instance with its own attributes, and that a named set of such descriptions is itself an entity able to carry its own provenance. SPDX and CSAF likewise make the relationship a class in its own right rather than a property of a component, so envelope identity, issuance and lifecycle must be modelled separately from the endpoints.", "source_refs": [ "SRC-001", "SRC-002", "SRC-012", "SRC-013" ], "layers": [ { "id": "dep-core-identity-and-issuance", "name": "Assertion identity and issuance attribution", "description": "How a dependency assertion is identified in the absence of strong global identity, and who issued it, on what authority, and at which distinct times.", "source_refs": [ "SRC-002", "SRC-003", "SRC-007", "SRC-008" ], "findings": [ { "id": "dep-core-assertion-identity", "name": "Assertion identity distinct from endpoint identity", "description": "A dependency assertion has weak, host-dependent identity. PROV makes the identifier on a qualified influence optional, RDF reification supplies no identity guarantee, and RDF blank node identifiers are explicitly local to a file or store and not persistent or portable; a CycloneDX bom-ref is unique only within the root bom element of one document. The assertion identifier must therefore be minted under a stated identity priority, must never be conflated with either endpoint's identifier, and where no identifier exists the assertion is reconstructed from a deterministic correlation key plus the host record that scopes it.", "source_refs": [ "SRC-001", "SRC-002", "SRC-003", "SRC-008", "SRC-016" ], "questions": [ { "id": "dep-core-q-identity-scheme", "text": "Which identifier scheme mints this assertion identifier, and is it an authoritative master-system identifier, a governed IRI or URN, or a Dimension-assigned UUID?", "kind": "identity", "answer_data": [ "Identifier value and its scheme or namespace", "Identity tier reached in the priority order", "Name of the assigning authority or minting Dimension" ] }, { "id": "dep-core-q-identity-host", "text": "When no global identifier exists, which host record, document or named graph scopes the local assertion identifier?", "kind": "composition", "answer_data": [ "Reference to the host record, document or named graph", "Statement that the local identifier is not portable outside that host", "Deterministic correlation key over issuer, roles, relation type and effective start" ] }, { "id": "dep-core-q-identity-separation", "text": "How is the assertion identifier kept demonstrably distinct from the identifiers of the dependent and prerequisite endpoints?", "kind": "definition", "answer_data": [ "Assertion identifier value", "Dependent and prerequisite endpoint identifier values", "Rule forbidding reuse of an endpoint identifier as an assertion identifier" ] }, { "id": "dep-core-q-identity-equivalence", "text": "Which normalization rules make two syntactically different assertion identifiers equivalent, and which differences must never be collapsed?", "kind": "validation", "answer_data": [ "Comparison level applied (character, syntax-based or scheme-based)", "List of components excluded from equivalence", "Recorded outcome when two records collide on the correlation key but differ on issuer" ] } ], "data_elements": [ { "id": "dep-core-de-assertion-id", "name": "Assertion identifier", "description": "The identifier of this dependency assertion, minted under the model's identity priority order and opaque to consumers.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-008", "SRC-009" ] }, { "id": "dep-core-de-assertion-id-scheme", "name": "Assertion identifier scheme", "description": "The URI scheme, URN namespace identifier or UUID version under which the assertion identifier was minted, and the identity tier it represents.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-008", "SRC-009" ] }, { "id": "dep-core-de-assertion-host-scope", "name": "Host scope reference", "description": "Reference to the record, document or named graph within which a locally scoped assertion identifier is unique; required whenever the identifier is not globally governed.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-003", "SRC-016" ] }, { "id": "dep-core-de-assertion-correlation-key", "name": "Assertion correlation key", "description": "Deterministic natural key derived from issuer, dependent role reference, prerequisite role references, relation-type term and effective start, used to recognise the same claim across hosts; a correlation aid, never a substitute identifier.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-008" ] } ], "artifacts": [ { "id": "dep-core-assertion-record", "name": "Dependency assertion envelope record", "description": "The single identified record that binds assertion identity, issuance attribution, applicability scope, role-bound endpoint references, relation-type term and lifecycle status into one addressable unit, independent of serialization.", "media_or_form": [ "structured record in any hierarchical serialization", "RDF named graph or qualified-influence instance", "tabular row in a relationship register", "signed statement payload" ], "serial": false, "identity_strategy": "Carries dep-core-de-assertion-id as its primary key; where the record originates in a master system of record, that system's assertion key is used verbatim, otherwise a governed IRI or URN, or failing that a Dimension-minted UUID, is assigned. The record is never keyed by an endpoint identifier, an effective date or a revision label.", "source_refs": [ "SRC-002", "SRC-008", "SRC-013" ] } ], "inline_only_rationale": null }, { "id": "dep-core-issuance-attribution", "name": "Issuer, authority basis and the three assertion times", "description": "Every assertion is attributed to an agent that speaks under some authority, and carries times that must not be conflated: declared-at (when the issuer made the claim), observed-at (when the dependency condition was seen to hold at the endpoints) and recorded-at (when the record entered this model). RFC 3339 fixes the representation but not the distinction, and SPDX carries startTime and endTime on the relationship itself, so the effective interval is a property of the claim rather than of either endpoint.", "source_refs": [ "SRC-002", "SRC-007", "SRC-013" ], "questions": [ { "id": "dep-core-q-issuer-agent", "text": "Which agent issued this assertion, and is that agent recorded separately from the agent that supplied the underlying observation?", "kind": "provenance", "answer_data": [ "Issuer agent reference and role", "Observing agent or tool reference where different", "Basis code: declared, observed, derived or imported" ] }, { "id": "dep-core-q-issuer-times", "text": "What are the declared-at, observed-at and recorded-at values for this assertion, and which of them orders competing records?", "kind": "temporal", "answer_data": [ "Three RFC 3339 timestamps with seconds and explicit offset", "Statement of which timestamp is authoritative for ordering", "Effective interval start and optional end" ] }, { "id": "dep-core-q-issuer-authority", "text": "Under what delegated authority may this issuer assert a dependency involving endpoints it does not own?", "kind": "authority", "answer_data": [ "Authority basis reference (mandate, stewardship assignment or contract)", "Whether the issuer owns the dependent, the prerequisite, neither or both", "Scope limits placed on that authority" ] }, { "id": "dep-core-q-issuer-minimum", "text": "Which attribution facts must be present before an assertion may leave draft status?", "kind": "requirement", "answer_data": [ "Mandatory attribution field list", "Rule for handling a missing observed-at value", "Rejection or quarantine outcome recorded when attribution is incomplete" ] } ], "data_elements": [ { "id": "dep-core-de-issuer-ref", "name": "Issuer reference", "description": "Reference to the agent that made the assertion; the agent itself is described by a separate party or agent model and only referenced here.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-002", "SRC-013" ] }, { "id": "dep-core-de-authority-basis", "name": "Authority basis", "description": "Reference to the mandate, stewardship assignment or agreement under which the issuer is entitled to speak about the named endpoints.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002", "SRC-012" ] }, { "id": "dep-core-de-declared-at", "name": "Declared-at time", "description": "RFC 3339 instant at which the issuer made the assertion.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-007" ] }, { "id": "dep-core-de-observed-at", "name": "Observed-at time", "description": "RFC 3339 instant at which the dependency condition was observed to hold at the endpoints; absent for purely declarative assertions.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-007" ] }, { "id": "dep-core-de-recorded-at", "name": "Recorded-at time", "description": "RFC 3339 instant at which the assertion record was ingested into this model; never back-dated to match observed-at.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-007" ] }, { "id": "dep-core-de-effective-interval", "name": "Effective interval", "description": "Start and optional end instants over which the issuer claims the dependency holds, carried on the assertion rather than on either endpoint.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-013" ] } ], "artifacts": [], "inline_only_rationale": "Issuance attribution is a set of scalar reference and timestamp values that qualify the assertion envelope record already declared in this model. Emitting a separate attestation document would either duplicate the envelope or drift from it under revision, and the agent, mandate and observing tool are each owned by referenced party, authority and tooling models, so only their references are held inline." } ] }, { "id": "dep-core-scope-and-lifecycle", "name": "Applicability scope and envelope lifecycle", "description": "The governing context that bounds where an assertion applies, and the states, revisions and supersession relations of the assertion record itself.", "source_refs": [ "SRC-002", "SRC-011", "SRC-012", "SRC-013" ], "findings": [ { "id": "dep-core-applicability-scope", "name": "Governing context and applicable endpoint types", "description": "An assertion is only meaningful inside a declared context: the adopting Dimension and tenant that govern the record, an optional jurisdiction, the purpose for which the claim was made, the endpoint types the claim is declared applicable to, and any qualifier narrowing it to an environment, deployment or lifecycle phase. TOSCA requirements constrain valid target types before any relationship is admitted, and CSAF relationship categories are only interpretable against a product tree; both show that applicability must be stated rather than inferred.", "source_refs": [ "SRC-011", "SRC-012", "SRC-017" ], "questions": [ { "id": "dep-core-q-scope-governance", "text": "Which adopting Dimension, tenant and jurisdiction govern this assertion record?", "kind": "ownership", "answer_data": [ "Adopting Dimension reference", "Tenant or organizational unit reference", "Jurisdiction codes, or an explicit statement that none applies" ] }, { "id": "dep-core-q-scope-types", "text": "Which endpoint types is this assertion declared applicable to, and what is recorded when an endpoint's type falls outside that set?", "kind": "classification", "answer_data": [ "Applicable endpoint type references drawn from an external type registry", "Out-of-scope handling code (reject, quarantine or record as scope violation)", "Reference to the type registry that defines the terms" ] }, { "id": "dep-core-q-scope-purpose", "text": "For which declared purpose was this assertion made, and may a consumer reuse it for a different purpose without re-issuance?", "kind": "decision", "answer_data": [ "Declared purpose codes or text", "Reuse permission flag and any stated limits", "Named purposes for which the assertion is explicitly not valid" ] }, { "id": "dep-core-q-scope-qualifier", "text": "Which environment, deployment or lifecycle-phase qualifiers narrow the applicability of this assertion?", "kind": "constraint", "answer_data": [ "Scope qualifier values and the dimension each constrains", "Statement of whether the qualifier set is exhaustive or illustrative", "Reference to the condition facilities that carry any guard expression" ] } ], "data_elements": [ { "id": "dep-core-de-dimension-ref", "name": "Adopting Dimension reference", "description": "Reference to the Dimension that owns and governs this assertion record and its namespace.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-009" ] }, { "id": "dep-core-de-tenant-ref", "name": "Tenant reference", "description": "Reference to the tenant or organizational unit whose data partition holds the record.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-012" ] }, { "id": "dep-core-de-jurisdiction-code", "name": "Jurisdiction code", "description": "Opaque code for a legal or regulatory jurisdiction under which the assertion is claimed to apply; the code list is owned by an external jurisdiction registry.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-017" ] }, { "id": "dep-core-de-declared-purpose", "name": "Declared purpose", "description": "The purpose for which the assertion was issued, constraining legitimate downstream reuse.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-017" ] }, { "id": "dep-core-de-applicable-endpoint-type", "name": "Applicable endpoint type reference", "description": "Reference to an endpoint type from an external type registry that this assertion is declared to apply to; analogous to a TOSCA requirement's valid target types.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-011" ] }, { "id": "dep-core-de-scope-qualifier", "name": "Scope qualifier", "description": "Environment, deployment or lifecycle-phase qualifier that narrows applicability; guard logic itself is carried by the model's condition facilities and referenced, not duplicated here.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-011", "SRC-012" ] } ], "artifacts": [], "inline_only_rationale": "Applicability scope consists entirely of references into externally governed registries (Dimension, tenant, jurisdiction, endpoint type) plus short qualifier values that must travel with the envelope record to be interpretable at all. Materializing scope as a separate artifact would create a second place where an assertion's validity is stated and would invite the two statements to diverge under revision." }, { "id": "dep-core-revision-supersession", "name": "Envelope lifecycle, revision and supersession", "description": "An assertion record moves through draft, active, superseded, retracted and expired states. PROV separates a revision from a new entity and treats disagreeing accounts as coexisting bundles rather than as an error, so this model records parallel assertions from different issuers side by side and never silently overwrites one with another. Which changes are revisions and which break identity is fixed by canonicalization rule, not decided at write time.", "source_refs": [ "SRC-001", "SRC-002", "SRC-013" ], "questions": [ { "id": "dep-core-q-lifecycle-states", "text": "Which lifecycle states may an assertion envelope occupy, and which transitions between them are permitted?", "kind": "lifecycle", "answer_data": [ "Enumerated status values and the permitted transition set", "Required fields for each transition", "Terminal states from which no further transition is allowed" ] }, { "id": "dep-core-q-lifecycle-identity-break", "text": "Which changes to an assertion require a new assertion identifier rather than a new revision of the existing one?", "kind": "decision", "answer_data": [ "List of identity-breaking fields (roles, relation type, direction, scope)", "List of revision-preserving fields (pins, states, qualifiers)", "Successor identifier recorded on the superseded record" ] }, { "id": "dep-core-q-lifecycle-retraction", "text": "How is a retracted or superseded assertion distinguished from one that simply expired at the end of its effective interval?", "kind": "state", "answer_data": [ "Status value and retraction reason", "Retraction timestamp distinct from effective-interval end", "Statement that expiry asserts nothing about the current dependency" ] }, { "id": "dep-core-q-lifecycle-parallel", "text": "How are competing assertions from different issuers about the same endpoint pair carried without one overwriting another?", "kind": "exception", "answer_data": [ "Set of coexisting assertion identifiers sharing a correlation key", "Per-assertion issuer and declared-at values", "Recorded disagreement marker with no resolution verdict" ] } ], "data_elements": [ { "id": "dep-core-de-envelope-status", "name": "Envelope status", "description": "Lifecycle state of the assertion record: draft, active, superseded, retracted or expired.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-013" ] }, { "id": "dep-core-de-revision-label", "name": "Revision label", "description": "Monotonic ordinal identifying a revision of one assertion identity; carries no date component and is never reused.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-008" ] }, { "id": "dep-core-de-supersedes-ref", "name": "Supersedes reference", "description": "Reference to the assertion identity or revision that this record replaces, mirroring the PROV revision relation.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "dep-core-de-superseded-by-ref", "name": "Superseded-by reference", "description": "Forward pointer to the successor record, so that an already resolved and cached assertion can be followed to its replacement.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "dep-core-de-retraction-reason", "name": "Retraction reason", "description": "Reason text or code recorded when an assertion is withdrawn as mistaken rather than allowed to expire.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-002" ] }, { "id": "dep-core-de-parallel-assertion-ref", "name": "Parallel assertion reference", "description": "Reference to a coexisting assertion by a different issuer over the same correlation key, recorded as disagreement without adjudication.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002" ] } ], "artifacts": [ { "id": "dep-core-revision-entry", "name": "Assertion revision entry", "description": "An ordered entry capturing one revision of a single assertion identity: revision label, change set, status at that revision, issuer, declared-at and content digest. It is the model's own versioning record for its own data, not an audit trail of external activity.", "media_or_form": [ "append-only revision list attached to the envelope record", "version-controlled document revision", "row in a revision register" ], "serial": true, "identity_strategy": "Composite of dep-core-de-assertion-id and dep-core-de-revision-label; the parent assertion identifier is authoritative and the ordinal is allocated per identity, never reused after retraction and never derived from a date.", "source_refs": [ "SRC-001", "SRC-008", "SRC-013" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "dep-core-endpoint-boundary", "name": "Endpoint reference boundary", "description": "How the assertion points at endpoints it does not own: role assignment and canonical direction, locators and namespaces, version pins and snapshots, epistemic state, and the shape of the relation between the two sides.", "rationale": "RFC 3986 separates identification from access and RFC 8141 separates name assignment from resolution, so an assertion can reference an endpoint without any claim over it. RFC 8288 and TOSCA both make the context or source and target or prerequisite roles explicit, and SPDX, CycloneDX and CSAF each encode direction, arity and absence differently - so the reference boundary needs its own explicit rules rather than inheriting one format's conventions.", "source_refs": [ "SRC-005", "SRC-006", "SRC-009", "SRC-011", "SRC-013", "SRC-016" ], "layers": [ { "id": "dep-core-role-direction", "name": "Role assignment, direction and locators", "description": "Which endpoint occupies which role, in which canonical direction, and how each endpoint is pointed at without asserting ownership over it.", "source_refs": [ "SRC-005", "SRC-006", "SRC-011", "SRC-013" ], "findings": [ { "id": "dep-core-direction-and-roles", "name": "Canonical direction and role binding", "description": "The canonical direction is dependent or consumer to prerequisite or provider: the dependent is the party affected if the prerequisite is absent, changed or withdrawn. TOSCA states this explicitly for DependsOn (the prerequisite is processed first), SPDX runs from a single from element to one or more to elements, and CycloneDX dependsOn lists what the described component requires. Direction is nonetheless not universal: CSAF categories such as installed_on invert the intuitive reading, and RFC 8288 deprecated the reversed rev parameter precisely because reversed relations proved error-prone. Imported relations are therefore normalized once into the canonical direction, with the original term and its native direction preserved verbatim.", "source_refs": [ "SRC-006", "SRC-011", "SRC-012", "SRC-013", "SRC-016" ], "questions": [ { "id": "dep-core-q-direction-roles", "text": "Which endpoint holds the dependent role and which holds the prerequisite role under the canonical direction?", "kind": "relationship", "answer_data": [ "Dependent role binding with its endpoint reference", "Prerequisite role bindings with their endpoint references", "Restatement of the canonical direction that the binding satisfies" ] }, { "id": "dep-core-q-direction-preserve", "text": "When the source vocabulary states the relation in the opposite direction, how are the original term and its native direction preserved?", "kind": "interoperability", "answer_data": [ "Source relation term recorded verbatim with its defining vocabulary", "Native direction of that term as published", "Reversal flag showing the binding was inverted on import" ] }, { "id": "dep-core-q-direction-type", "text": "Which typed relation term does this assertion carry, and which governed vocabulary defines its meaning?", "kind": "classification", "answer_data": [ "Relation-type term reference", "Vocabulary or registry identifier and version", "Statement that term semantics are owned by that registry, not by this model" ] }, { "id": "dep-core-q-direction-evidence", "text": "What must be established before an imported relation is recorded as direction-reversed rather than rejected?", "kind": "validation", "answer_data": [ "Published direction statement from the source vocabulary", "Reviewer or rule that authorised the reversal", "Rejection outcome recorded when native direction is undocumented or ambiguous" ] } ], "data_elements": [ { "id": "dep-core-de-dependent-ref", "name": "Dependent role binding", "description": "Reference to the endpoint that occupies the dependent or consumer role; exactly one per assertion, matching the SPDX single-from shape.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-011", "SRC-013" ] }, { "id": "dep-core-de-prerequisite-ref", "name": "Prerequisite role binding", "description": "Reference to an endpoint occupying the prerequisite or provider role; one or more per assertion.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-013", "SRC-016" ] }, { "id": "dep-core-de-relation-type-ref", "name": "Relation-type term reference", "description": "Reference to the typed relation term from a governed vocabulary; the term is bound, never authored or redefined here.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-006", "SRC-012", "SRC-013" ] }, { "id": "dep-core-de-source-direction-term", "name": "Source direction term", "description": "The relation term exactly as stated by the source vocabulary, together with that vocabulary's published direction, retained even after normalization.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006", "SRC-012" ] }, { "id": "dep-core-de-direction-normalization", "name": "Direction normalization flag", "description": "Whether the canonical binding was taken as asserted or inverted on import.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-006", "SRC-013" ] } ], "artifacts": [], "inline_only_rationale": "Role binding and direction are the semantic core of the envelope record and cannot be split from it without making the record ambiguous: a detached direction artifact could be read out of context and inverted. The relation term itself is an artifact of an external vocabulary registry that this model only references, so nothing artifact-like remains to declare locally." }, { "id": "dep-core-endpoint-locators", "name": "Endpoint locators, namespaces and comparison", "description": "Each role binding carries a scheme-qualified locator. RFC 3986 makes schemes a federated naming system and states that the presence of a URI implies neither access nor resolution; RFC 8141 requires URN namespaces to publish their own uniqueness and persistence rules and separates assignment from resolution. Sub-endpoints are addressed with an anchor rather than by minting a new endpoint identity, following the RFC 8288 anchor parameter and RFC 3986 fragment semantics. Because a CycloneDX bom-ref is unique only within one document, any imported document-local reference must be rebound to a scheme-qualified locator or explicitly marked host-scoped.", "source_refs": [ "SRC-005", "SRC-006", "SRC-009", "SRC-016" ], "questions": [ { "id": "dep-core-q-locator-form", "text": "What form does each endpoint locator take, and which scheme or namespace authority governs it?", "kind": "identity", "answer_data": [ "Locator value and scheme", "Namespace identifier and its registering authority", "Whether the namespace publishes uniqueness and persistence rules" ] }, { "id": "dep-core-q-locator-anchor", "text": "How is a sub-endpoint such as an interface, partition or component addressed without minting a new endpoint identity?", "kind": "composition", "answer_data": [ "Anchor or fragment value and the base locator it qualifies", "Statement of what interprets the anchor", "Rule preventing the anchored form from being registered as a separate endpoint" ] }, { "id": "dep-core-q-locator-compare", "text": "Which comparison level determines whether two endpoint references denote the same endpoint?", "kind": "validation", "answer_data": [ "Comparison level applied and its justification", "Components excluded from equivalence", "Recorded outcome when two locators are equivalent only under a weaker level" ] }, { "id": "dep-core-q-locator-consume", "text": "What must the reference carry so a consumer can resolve it, given that this model performs no resolution?", "kind": "interoperability", "answer_data": [ "Scheme, namespace and any resolution hint or service reference", "Explicit statement that resolution is the consumer's responsibility", "Handling rule for document-local references imported from an exchange format" ] } ], "data_elements": [ { "id": "dep-core-de-endpoint-locator", "name": "Endpoint locator", "description": "Scheme-qualified identifier of a referenced endpoint; it identifies without implying access or resolvability.", "value_kind": "identifier", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-005", "SRC-009" ] }, { "id": "dep-core-de-locator-scheme", "name": "Locator scheme", "description": "The URI scheme or URN namespace identifier governing the locator, naming the authority responsible for assignment.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-005", "SRC-009" ] }, { "id": "dep-core-de-locator-anchor", "name": "Sub-endpoint anchor", "description": "Anchor or fragment addressing a part of the referenced endpoint; interpreted by the endpoint's own type or media type, not by this model.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-006" ] }, { "id": "dep-core-de-locator-scope-flag", "name": "Locator scope flag", "description": "Whether the locator is globally governed or scoped to a host document, as with an imported document-local reference.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-003", "SRC-016" ] }, { "id": "dep-core-de-locator-comparison-level", "name": "Locator comparison level", "description": "The equivalence rung applied when deciding that two locators denote the same endpoint, recorded so comparisons are reproducible.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-009" ] } ], "artifacts": [], "inline_only_rationale": "A locator is a reference value, not a document. Every artifact in this area belongs to a neighbouring model: the endpoint record itself is owned by the endpoint or resource model, and the scheme or namespace registration is owned by its registering authority. Declaring a local artifact here would assert custody over identifiers this model only cites." } ] }, { "id": "dep-core-reference-resolution", "name": "Version pinning and reference state", "description": "Whether a reference tracks the live endpoint or a fixed revision or digest, and what is known about whether the reference currently resolves.", "source_refs": [ "SRC-005", "SRC-010", "SRC-013", "SRC-014", "SRC-016" ], "findings": [ { "id": "dep-core-version-pinning", "name": "Live references, version pins and immutable snapshots", "description": "A reference is either live (tracking whatever the locator currently denotes) or pinned to a specific version, content digest or snapshot. RFC 6920 gives the content-addressed form: a self-verifying name compared on digest algorithm and value alone, which names content but does not locate it. PROV separates a general entity from its specialization and a revision from its source, which is the alignment for treating a pinned reference as a specialization of the live endpoint. A declared compatibility range states which upstream revisions the issuer claims the assertion still covers; deciding whether a new revision actually satisfies it is the endpoint owner's and the consumer's work, not this model's.", "source_refs": [ "SRC-001", "SRC-010", "SRC-013", "SRC-016" ], "questions": [ { "id": "dep-core-q-pin-mode", "text": "Is this reference live, pinned to a version, pinned to a content digest, or pinned to a snapshot?", "kind": "classification", "answer_data": [ "Pin mode code", "Pinned value where the mode requires one", "Statement of what may change upstream without invalidating the assertion" ] }, { "id": "dep-core-q-pin-digest", "text": "Which digest algorithm and value bind an immutable snapshot to this reference?", "kind": "evidence", "answer_data": [ "Digest algorithm name from a registered algorithm registry", "Digest value", "Statement that verification is performed by the resolving consumer" ] }, { "id": "dep-core-q-pin-range", "text": "Which upstream revisions does the issuer declare compatible with this assertion, and how is that range expressed?", "kind": "constraint", "answer_data": [ "Compatibility range expression and its grammar", "Whether the range is issuer-declared or vendor-published", "Consequence recorded when a revision outside the range is encountered" ] }, { "id": "dep-core-q-pin-withdrawn", "text": "What is recorded when the pinned revision is withdrawn or replaced upstream?", "kind": "exception", "answer_data": [ "Reference state transition triggered by withdrawal", "Retained pin value with a withdrawn marker", "Statement that this model records the fact but performs no remediation" ] } ], "data_elements": [ { "id": "dep-core-de-pin-mode", "name": "Pin mode", "description": "Whether the reference is live, version-pinned, digest-pinned or snapshot-pinned.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-010" ] }, { "id": "dep-core-de-pinned-version", "name": "Pinned version", "description": "The endpoint version or revision label the reference is fixed to, recorded exactly as published by the endpoint owner.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013", "SRC-016" ] }, { "id": "dep-core-de-content-digest", "name": "Content digest", "description": "Digest algorithm and value that immutably bind the reference to specific content; compared on algorithm and value only.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-010" ] }, { "id": "dep-core-de-compatibility-range", "name": "Declared compatibility range", "description": "The issuer's declaration of which upstream revisions the assertion is claimed to cover, with the grammar used to express it.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013", "SRC-016" ] }, { "id": "dep-core-de-snapshot-ref", "name": "Snapshot reference", "description": "Reference to an immutable snapshot of the endpoint held by an external system; a specialization of the live endpoint, not a copy owned here.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-010" ] } ], "artifacts": [ { "id": "dep-core-endpoint-pin-descriptor", "name": "Endpoint pin descriptor", "description": "A descriptor attached to one role binding that fixes what the reference points at: pin mode, pinned version or digest, snapshot reference and declared compatibility range. It is a naming record only; it holds no endpoint content and triggers no fetch or verification.", "media_or_form": [ "structured sub-record of the assertion envelope", "content-addressed name expression", "lockfile-style pin entry" ], "serial": false, "identity_strategy": "Identified by the parent assertion identifier plus the role binding it qualifies; where the pin is digest-based, the digest algorithm and value provide a self-verifying secondary key. Never keyed by the endpoint's own identifier alone, since one endpoint may be pinned differently by many assertions.", "source_refs": [ "SRC-001", "SRC-010", "SRC-016" ] } ], "inline_only_rationale": null }, { "id": "dep-core-assertion-states", "name": "Epistemic, completeness and resolution states", "description": "Silence must never become proof. SPDX separates an explicit NoneElement (no such relationship exists) from a NoAssertionElement (no assertion is being made), and its RelationshipCompleteness vocabulary separates complete, incomplete and noAssertion. CycloneDX encodes the same distinction in the opposite way - an empty dependency element means no dependencies, while an unrepresented component means unknown - so the two encodings are not interchangeable and a normalized epistemic state must be recorded explicitly. Reference resolution adds a further axis: resolved, unresolved or dangling, ambiguous, or withdrawn upstream, each carrying a verification time and a staleness horizon.", "source_refs": [ "SRC-013", "SRC-014", "SRC-016", "SRC-017" ], "questions": [ { "id": "dep-core-q-state-epistemic", "text": "Which epistemic state applies here: dependency asserted present, asserted absent, unknown, not assessed, or unresolved?", "kind": "state", "answer_data": [ "Epistemic state code", "Reason or method that produced the state", "Explicit statement that the absence of a record is not the absent state" ] }, { "id": "dep-core-q-state-completeness", "text": "Is the prerequisite set for this dependent declared exhaustive, known not to be exhaustive, or unqualified?", "kind": "quality", "answer_data": [ "Completeness qualifier value", "Scope over which completeness is claimed", "Issuer that stands behind the completeness claim" ] }, { "id": "dep-core-q-state-staleness", "text": "When was this endpoint reference last verified, and after what interval is that observation treated as stale?", "kind": "measurement", "answer_data": [ "Last-verified RFC 3339 timestamp", "Staleness horizon as a duration", "Derived stale flag and its recomputation rule" ] }, { "id": "dep-core-q-state-independence", "text": "How does the record distinguish an explicitly asserted independence from the mere absence of any assertion?", "kind": "definition", "answer_data": [ "Explicit independence marker and its issuer", "Scope and relation type over which independence is claimed", "Contrast case showing what an absent record means" ] }, { "id": "dep-core-q-state-ambiguous", "text": "Which state is recorded when a prerequisite locator resolves to more than one candidate endpoint?", "kind": "exception", "answer_data": [ "Ambiguous resolution state code", "Candidate locator list as reported by the external resolver", "Statement that disambiguation is not performed by this model" ] } ], "data_elements": [ { "id": "dep-core-de-epistemic-state", "name": "Epistemic state", "description": "Normalized state of the claim: asserted-present, asserted-absent, unknown, not-assessed or unresolved. Absence of a record is never encoded as asserted-absent.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-013", "SRC-016" ] }, { "id": "dep-core-de-completeness", "name": "Prerequisite completeness qualifier", "description": "Whether the prerequisite set is complete, incomplete or unqualified, adopting the SPDX three-state vocabulary.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-014" ] }, { "id": "dep-core-de-resolution-state", "name": "Reference resolution state", "description": "Reported outcome of an external resolver for a role-bound locator: resolved, unresolved or dangling, ambiguous, or withdrawn upstream.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-009" ] }, { "id": "dep-core-de-last-verified-at", "name": "Last-verified time", "description": "RFC 3339 instant at which the reference state was last confirmed by an external resolver.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007" ] }, { "id": "dep-core-de-staleness-horizon", "name": "Staleness horizon", "description": "Duration after which an unrefreshed verification is treated as stale, so that an old confirmation is not read as a current one.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-017" ] } ], "artifacts": [ { "id": "dep-core-non-dependency-statement", "name": "Explicit non-dependency statement", "description": "An identified, attributed statement that a named dependent has no prerequisite of a given relation type within a stated scope - the positive form of absence, distinct from an unrecorded dependency. Follows the SPDX pattern in which an explicit none marker must stand alone and must not be combined with other targets.", "media_or_form": [ "structured negative-assertion record", "explicit none marker in an exchange format", "register entry of declared independence" ], "serial": false, "identity_strategy": "Uses the same identity priority and identifier space as an ordinary assertion envelope, keyed by dep-core-de-assertion-id; the dependent reference, relation type and scope together form the correlation key, and no prerequisite role binding is present.", "source_refs": [ "SRC-013", "SRC-014", "SRC-016" ] } ], "inline_only_rationale": null } ] }, { "id": "dep-core-assertion-shape", "name": "Relation shape and degenerate cases", "description": "Arity, ordering, composite prerequisites and the degenerate shapes that a naive edge model silently mishandles.", "source_refs": [ "SRC-004", "SRC-011", "SRC-012", "SRC-013" ], "findings": [ { "id": "dep-core-shape-and-degeneracy", "name": "Arity, ordering, composite prerequisites and degenerate shapes", "description": "SPDX gives one from element to one or more to elements, so one-to-one and one-to-many are native while many-to-one and many-to-many are expressed as multiple assertions sharing a prerequisite or a correlation key. TOSCA adds occurrence constraints for cardinality bounds. Ordering has no dependency-specific normative source: RDF Schema supplies rdf:Seq, where numerical ordering of membership properties is significant, and rdf:List, where ordering is structural, and these are adopted by analogy. CSAF shows that a composite of two products is given its own minted product identifier, which is why a composite prerequisite group is modelled here as a grouping over references rather than as a new endpoint. Self-dependencies, exact duplicates and reversed direction are recorded as detected shapes, never silently normalized away.", "source_refs": [ "SRC-004", "SRC-011", "SRC-012", "SRC-013" ], "questions": [ { "id": "dep-core-q-shape-arity", "text": "Which arity pattern does this assertion express, and how are many-to-one and many-to-many cases carried?", "kind": "composition", "answer_data": [ "Arity pattern code", "Number of dependent and prerequisite role bindings", "Correlation key or group reference linking assertions that jointly express a wider arity" ] }, { "id": "dep-core-q-shape-order", "text": "When prerequisites are ordered, what carries the ordinal and what does that order actually mean?", "kind": "relationship", "answer_data": [ "Ordinal per prerequisite binding", "Declared meaning of the order (precedence, preference or fallback)", "Statement of whether the order is significant or merely presentational" ] }, { "id": "dep-core-q-shape-composite", "text": "How is a composite prerequisite group expressed without importing condition evaluation into this record?", "kind": "constraint", "answer_data": [ "Group membership references", "Combination operator code such as all-of or any-of", "Reference to the condition facilities that hold any guard expression" ] }, { "id": "dep-core-q-shape-degenerate", "text": "How are self-dependencies and exact-duplicate assertions detected and recorded rather than silently dropped?", "kind": "validation", "answer_data": [ "Self-reference flag where dependent and prerequisite locators are equivalent", "Duplicate marker and the reference to the earlier assertion", "Rule requiring the shape to be recorded, not discarded" ] }, { "id": "dep-core-q-shape-duplicate-key", "text": "Which key decides that two assertion records express the same claim?", "kind": "identity", "answer_data": [ "Correlation key composition", "Comparison level applied to each locator within the key", "Treatment of records that match on key but differ on issuer or effective interval" ] } ], "data_elements": [ { "id": "dep-core-de-arity-pattern", "name": "Arity pattern", "description": "Declared shape of the assertion: one-to-one, one-to-many, many-to-one or many-to-many, where the latter two are carried across linked assertions.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-011", "SRC-013" ] }, { "id": "dep-core-de-prerequisite-ordinal", "name": "Prerequisite ordinal", "description": "Ordinal attached to a prerequisite role binding when order is significant, together with the declared meaning of that order.", "value_kind": "number", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-004" ] }, { "id": "dep-core-de-composite-group", "name": "Composite prerequisite group", "description": "Grouping over prerequisite role bindings with a combination operator; guard logic and its evaluation are referenced from the model's condition facilities, not embedded here.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-004", "SRC-012" ] }, { "id": "dep-core-de-self-reference-flag", "name": "Self-reference flag", "description": "Set when the dependent and a prerequisite locator are equivalent at the recorded comparison level, so the degenerate shape is visible rather than hidden.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-005", "SRC-013" ] }, { "id": "dep-core-de-duplicate-of-ref", "name": "Duplicate-of reference", "description": "Reference to an earlier assertion carrying the same correlation key, recorded when a duplicate is admitted rather than rejected.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-002", "SRC-013" ] } ], "artifacts": [ { "id": "dep-core-composite-prerequisite-group", "name": "Composite prerequisite group record", "description": "A named grouping of two or more prerequisite role bindings treated as one prerequisite for the dependent, carrying membership, optional ordinals and a combination operator. It groups references only; it mints no endpoint and evaluates no condition.", "media_or_form": [ "ordered or unordered collection sub-record within the envelope", "RDF collection or sequence over references", "grouped rows in a prerequisite register" ], "serial": false, "identity_strategy": "Identified by the parent assertion identifier plus a stable group label unique within that assertion; the group never inherits or reuses a member endpoint's identifier, and if the composite ever needs standalone identity it must be minted by the endpoint model, not here.", "source_refs": [ "SRC-004", "SRC-012", "SRC-013" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "dep-tech-taxonomy-bundle", "name": "Typed dependency taxonomy", "description": "Everything needed to decide what an endpoint is, which single dependency kind applies, what the edge actually asserts, in which lifecycle phase it holds, and which qualifiers weaken, condition or negate it.", "rationale": "Every downstream use of a dependency fact - impact tracing, export to an SBOM, orchestration, review - depends first on the edge being typed unambiguously. Primary vocabularies disagree on granularity (SPDX 2.3 enumerates scoped dependency types, SPDX 3.0.1 collapses them into dependsOn plus a lifecycle scope, CycloneDX offers only dependsOn and provides, Debian and TOSCA add negative, ordering and capability relations). A local, partitioned kind register with explicit facets is therefore required before any alignment can be recorded.", "source_refs": [ "SRC-018", "SRC-019", "SRC-020", "SRC-021", "SRC-022", "SRC-023" ], "layers": [ { "id": "dep-tech-kind-layer", "name": "Referent classes and the dependency kind register", "description": "What may sit at each end of an edge, how the kind space is partitioned across referent families, and what each edge actually asserts about the world.", "source_refs": [ "SRC-018", "SRC-020", "SRC-021", "SRC-022", "SRC-001", "SRC-023" ], "findings": [ { "id": "dep-tech-referent-classes", "name": "Endpoint referent classes", "description": "The closed set of classes that may occupy either end of a typed dependency edge, and the rule that picks exactly one class when a candidate could be read as several. Classes span source artifacts and distributable packages or modules; source, build and test toolchain tools; deployed runtime services; interface contracts (API operations, message channels, wire protocols); data sets and data streams; schemas and ontologies; configuration items; secret and trust material referenced opaquely; compute, network and storage resources; named deployment environments; and external managed platforms outside the adopting Dimension's control. Class assignment is what makes the per-kind endpoint-type constraints enforceable, and it is deliberately independent of the storage projection: a class is a semantic role, not a document type.", "source_refs": [ "SRC-020", "SRC-021", "SRC-022", "SRC-027", "SRC-028", "SRC-029" ], "questions": [ { "id": "dep-tech-q-rc-definition", "text": "Which referent classes may occupy an endpoint of a typed dependency edge, and what single discriminating property separates each class from its nearest neighbour?", "kind": "definition", "answer_data": [ "Referent class code and normative definition", "Discriminating property against each adjacent class", "Worked example and counterexample per class" ] }, { "id": "dep-tech-q-rc-identity", "text": "Which identifier scheme is authoritative for each referent class, and in what order are fallbacks used when the master-system identifier is unavailable?", "kind": "identity", "answer_data": [ "Authoritative master system per referent class", "Governed global identifier scheme (purl type, SPDX element IRI, contract URI, orchestrator node identifier)", "Dimension-minted UUID or ULID fallback marker", "Rejected-as-identifier list (version strings, digests, paths, dates)" ] }, { "id": "dep-tech-q-rc-classification", "text": "When a candidate endpoint reads plausibly as a package, a deployed runtime service, an interface contract and a deployment environment at once, which class wins and on what rule?", "kind": "classification", "answer_data": [ "Precedence rule text and its ordering criterion", "Adjudication record with adjudicator identity", "Multi-class candidate exemplars and their resolved class" ] }, { "id": "dep-tech-q-rc-access", "text": "How is an endpoint recorded when it lies outside the adopting Dimension's control, such as an external managed platform, a third-party registry or a public trust anchor?", "kind": "access", "answer_data": [ "Control-boundary flag (internal, external-managed, public)", "Identifier available for an uncontrolled endpoint and its stability guarantee", "Export restriction applied to internal locators" ] } ], "data_elements": [ { "id": "dep-tech-de-referent-class", "name": "Referent class code", "description": "Governed code naming the semantic role of an endpoint (for example source artifact, distributable package, toolchain tool, runtime service, interface contract, data set, data stream, schema or ontology, configuration item, secret reference, trust anchor, compute resource, network resource, storage resource, deployment environment, external platform).", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-020", "SRC-021", "SRC-022" ] }, { "id": "dep-tech-de-endpoint-ref", "name": "Endpoint identifier reference", "description": "Opaque reference to the endpoint in its system of record, or a governed global identifier such as a purl, an SPDX element IRI, a CycloneDX bom-ref within its BOM scope, or an interface document URI plus operation or channel reference.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-021", "SRC-027", "SRC-028", "SRC-029" ] }, { "id": "dep-tech-de-identifier-scheme", "name": "Endpoint identifier scheme and tier", "description": "Which scheme produced the endpoint reference and which identity-priority tier it occupies, so that a consumer can tell a master-system key from a Dimension-scoped surrogate.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-029", "SRC-021" ] }, { "id": "dep-tech-de-control-boundary", "name": "Control boundary flag", "description": "Whether the endpoint is internal to the adopting Dimension, an externally managed platform, or a public shared resource; drives export restriction and the plausibility of any completeness claim about it.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-022", "SRC-030" ] } ], "artifacts": [ { "id": "dep-tech-referent-class-register", "name": "Referent class register", "description": "Governed register of endpoint referent classes, each with a normative definition, its discriminating property against adjacent classes, the authoritative identifier scheme and fallback order, the control-boundary values it may take, and adjudicated multi-class exemplars. Published with a version and an effective interval; consumers pin the version.", "media_or_form": [ "controlled vocabulary register", "machine-readable code list", "narrative definition set with worked exemplars" ], "serial": false, "identity_strategy": "Each entry is keyed by the register namespace IRI governed by the adopting Dimension plus the class code, qualified by monotonic register version (namespace/class-code@version). No date component appears in the key; the effective interval carries temporal meaning.", "source_refs": [ "SRC-021", "SRC-022", "SRC-029" ] } ], "inline_only_rationale": null }, { "id": "dep-tech-kind-register", "name": "Dependency kind register and per-kind facets", "description": "The partitioned register of typed dependency kinds together with the seven facets each kind must declare: canonical direction, permitted referent class at each endpoint, permitted cardinality, lifecycle phase or phases, version or compatibility expression rule, whether the kind licenses impact propagation, and documented false-positive exemplars. Kinds are organised by referent family - packages and modules; source, build and test toolchains; runtime services; interfaces and protocols; data sets and streams; schemas and ontologies; configuration and secret references; compute, network and storage; deployment environments; trust material; external platforms - and are required to be mutually disjoint in semantics. Representative kinds include requires-package, statically-links, dynamically-links, bundles-vendored-copy, provides-capability, built-with-tool, tested-with-tool, builds-from-source, invokes-service, conforms-to-interface, produces-to-stream, consumes-from-stream, reads-data-set, validates-against-schema, configured-by, requires-secret-reference, hosted-on, attaches-to-storage, routes-through-network, deployed-into-environment, trusts-anchor, depends-on-external-platform, conflicts-with, must-precede and co-located-with, the last being an explicit non-dependency record. No single package ecosystem's semantics are adopted globally; ecosystem-specific rules are labelled at the binding, not baked into the kind.", "source_refs": [ "SRC-018", "SRC-020", "SRC-021", "SRC-022", "SRC-023", "SRC-027", "SRC-028" ], "questions": [ { "id": "dep-tech-q-kr-classification", "text": "Which single registered kind code applies to this relation, and which other kinds were considered and excluded, with the reason for each exclusion?", "kind": "classification", "answer_data": [ "Assigned kind code", "Excluded candidate kinds with exclusion reason", "Register version under which the assignment was made" ] }, { "id": "dep-tech-q-kr-relationship", "text": "For this kind, what is the canonical direction, which referent classes are permitted at the source and target ends, and what cardinality is allowed at each end?", "kind": "relationship", "answer_data": [ "Canonical direction statement (source depends on target, or the inverse, expressed once and normalised)", "Permitted source and target referent class lists", "Minimum and maximum occurrences at each end" ] }, { "id": "dep-tech-q-kr-composition", "text": "How is the kind space partitioned across referent families so that no two registered kinds share the same semantics, and what test detects an overlap?", "kind": "composition", "answer_data": [ "Referent family to kind mapping", "Disjointness test procedure and its outcome", "Overlap adjudication record for near-duplicate proposals" ] }, { "id": "dep-tech-q-kr-constraint", "text": "What disqualifying conditions and documented false-positive exemplars prevent this kind from being asserted, even when a tool or manifest appears to support it?", "kind": "constraint", "answer_data": [ "Disqualifying condition list", "False-positive exemplars (shared host read as requirement, transitive lockfile entry read as direct, vendored copy counted twice, virtual capability provider read as the only provider, correlated deployment timing read as ordering)", "Handling rule for a disqualified candidate" ] }, { "id": "dep-tech-q-kr-authority", "text": "Which cited source or explicit Dimension decision authorises this kind, and who is accountable for changes to its facets?", "kind": "authority", "answer_data": [ "Source citation or Dimension-local justification text", "Accountable steward identity", "Register version in which the kind was introduced, changed or deprecated" ] } ], "data_elements": [ { "id": "dep-tech-de-kind-code", "name": "Dependency kind code", "description": "Governed code identifying exactly one typed dependency kind within the register namespace.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-018", "SRC-021", "SRC-023" ] }, { "id": "dep-tech-de-canonical-direction", "name": "Canonical direction", "description": "The one direction in which the kind is stored, so that inverse-form external statements (for example an SPDX 2.3 DEPENDENCY_OF, or a Debian Enhances relative to Suggests) are normalised on intake with the original term retained in the binding record.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-020", "SRC-023" ] }, { "id": "dep-tech-de-endpoint-constraint", "name": "Endpoint class constraint", "description": "Permitted referent classes at the source end and at the target end of the kind, expressed as two class-code sets.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-022", "SRC-021" ] }, { "id": "dep-tech-de-cardinality-rule", "name": "Permitted cardinality", "description": "Occurrence bounds at each end, following the TOSCA occurrences pattern (minimum and maximum instances of the requirement that may exist), including whether many-to-one, one-to-many or many-to-many is admissible for the kind.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-022" ] }, { "id": "dep-tech-de-false-positive-exemplar", "name": "False-positive exemplar", "description": "A recorded case in which the kind looks applicable but is not, with the discriminating fact that rules it out; mandatory for any kind that may be produced by discovery or inference.", "value_kind": "text", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-021", "SRC-030" ] } ], "artifacts": [ { "id": "dep-tech-kind-register-artifact", "name": "Dependency kind register", "description": "The governed, versioned register of dependency kinds. Each entry carries the kind code, referent family, definition, canonical direction, source and target endpoint class constraints, cardinality bounds, permitted lifecycle phases, version or compatibility expression rule, propagation-licence pointer, false-positive exemplars, external alignment pointers and lifecycle status (proposed, active, deprecated with successor). Storage-neutral: it may be projected as a table, a code list, a graph vocabulary or document sections without changing its semantics.", "media_or_form": [ "controlled vocabulary register", "faceted register with one row per kind", "machine-readable code list with facet columns" ], "serial": false, "identity_strategy": "Entries are keyed by the Dimension-governed register namespace IRI plus the kind code, qualified by monotonic register version (namespace/kind-code@version). Facet changes produce a new version rather than an in-place edit; superseded entries stay resolvable with a successor mapping. No date-derived component appears in the key.", "source_refs": [ "SRC-018", "SRC-020", "SRC-021", "SRC-022", "SRC-023" ] } ], "inline_only_rationale": null }, { "id": "dep-tech-relation-nature", "name": "Nature of the asserted relation", "description": "The discriminator that separates five distinct things routinely conflated under the word dependency: a functional requirement (the source cannot correctly build, start or operate without the target), a resource consumption (the source consumes capacity, quota or throughput the target supplies), a compatibility constraint (the source imposes a permissible range or shape on the target without necessarily invoking it, as with a peer relation), an ordering constraint (the target must reach a state before the source may proceed, as with a pre-dependency, without any ongoing requirement), and mere co-location or correlation (shared host, shared owner, shared release train, correlated failure timing) which is explicitly not a dependency. Nature is orthogonal to kind: two edges of the same kind may differ in nature, and nature is the primary determinant of whether an impact traversal is even meaningful.", "source_refs": [ "SRC-022", "SRC-001", "SRC-023", "SRC-024" ], "questions": [ { "id": "dep-tech-q-rn-definition", "text": "Does this edge assert a functional requirement, a resource consumption, a compatibility constraint, an ordering constraint, or mere co-location or correlation?", "kind": "definition", "answer_data": [ "Nature code with definition", "Evidence sentence justifying the chosen nature", "Nature codes explicitly ruled out" ] }, { "id": "dep-tech-q-rn-requirement", "text": "What concretely fails, degrades or becomes unbuildable if the target is absent, incompatible, unavailable or exhausted?", "kind": "requirement", "answer_data": [ "Failure mode description tied to a lifecycle phase", "Degradation versus hard failure distinction", "Whether an alternative target satisfies the same requirement" ] }, { "id": "dep-tech-q-rn-measurement", "text": "Where the edge is a resource consumption, what quantity, unit and observation basis are recorded, and are they a declared reservation or an observed draw?", "kind": "measurement", "answer_data": [ "Quantity value and unit", "Declared reservation versus observed draw flag", "Observation basis, window and source system reference" ] }, { "id": "dep-tech-q-rn-decision", "text": "On what basis is a correlation or co-residency refused promotion to a dependency edge, and who adjudicates that refusal?", "kind": "decision", "answer_data": [ "Refusal rule and the discriminating evidence it demands", "Adjudicator identity and decision event time", "Retained non-dependency observation record with its non-propagating marker" ] } ], "data_elements": [ { "id": "dep-tech-de-nature-code", "name": "Relation nature code", "description": "One of functional-requirement, resource-consumption, compatibility-constraint, ordering-constraint, or co-location-or-correlation; the last never licenses propagation.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-022", "SRC-023", "SRC-024" ] }, { "id": "dep-tech-de-failure-mode", "name": "Failure or degradation statement", "description": "What the source cannot do if the target is absent, incompatible, unavailable or exhausted, scoped to a lifecycle phase; empty is not permitted for a functional-requirement nature.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-023", "SRC-022" ] }, { "id": "dep-tech-de-consumption-quantity", "name": "Consumption quantity", "description": "Quantity and unit of the resource drawn or reserved, present only when the nature is resource-consumption, together with whether the figure is a declared reservation or an observed draw referenced from an observability system.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-022" ] }, { "id": "dep-tech-de-nonpropagating-flag", "name": "Non-propagating observation flag", "description": "Marks a recorded relation as an observation that must never be traversed for impact, regardless of any propagation licence attached to its kind.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-021" ] } ], "artifacts": [], "inline_only_rationale": "Nature is a small set of coded attributes plus a short justification carried on each individual edge assertion; it produces no separate governed object, no independently versioned document and no exchangeable payload. The consumption figures it may reference are measured, retained and served by the adopting Dimension's capacity and observability systems, so materialising them as an artifact here would duplicate a neighbouring model's records and imply an observation capability this model explicitly does not hold." } ] }, { "id": "dep-tech-modality-layer", "name": "Lifecycle phase and requirement qualifiers", "description": "When the edge holds, and the conditions, alternatives, version constraints and negations that change what the edge means for a consumer.", "source_refs": [ "SRC-019", "SRC-020", "SRC-023", "SRC-024", "SRC-025", "SRC-026" ], "findings": [ { "id": "dep-tech-lifecycle-phase", "name": "Lifecycle phase scoping of the edge", "description": "The phase or phases in which a dependency actually holds: design, development, build, test, deploy and runtime. Phase is the axis that SPDX 3.0.1 made explicit by defining relationships as holding 'during a LifecycleScopeType period', replacing the SPDX 2.3 practice of encoding phase into the relationship type itself (BUILD_DEPENDENCY_OF, TEST_DEPENDENCY_OF, RUNTIME_DEPENDENCY_OF). A single pair of endpoints may carry several phase-scoped edges with different qualifiers and different propagation licences: a compiler is a build-phase requirement and absent at runtime; a broker is a runtime requirement and irrelevant at build. Deploy is treated as a locally defined phase because no primary external vocabulary provides a normative value for it, and this is recorded as an open gap rather than presented as aligned.", "source_refs": [ "SRC-018", "SRC-019", "SRC-020", "SRC-026" ], "questions": [ { "id": "dep-tech-q-lp-lifecycle", "text": "In which lifecycle phase or phases does this dependency hold, and is it absent in every other phase?", "kind": "lifecycle", "answer_data": [ "Phase code set (design, development, build, test, deploy, runtime)", "Explicit statement of phases in which the edge does not hold", "Separate edge identifiers where the same endpoints relate differently per phase" ] }, { "id": "dep-tech-q-lp-temporal", "text": "Does the edge hold continuously within its phase or only during a bounded window, and what start and end event times bound it?", "kind": "temporal", "answer_data": [ "Validity interval start and end event times in RFC 3339 with seconds and explicit offset", "Continuous versus windowed indicator", "Whether an end time means expiry, retraction or phase exit" ] }, { "id": "dep-tech-q-lp-state", "text": "How does the subject's own state - not yet built, built, deployed, retired - change which phase-scoped edges a consumer should treat as active?", "kind": "state", "answer_data": [ "Subject state to active-phase mapping", "Rule for edges that survive retirement (for example archived build inputs)", "Reference to the subject model that masters the state value" ] }, { "id": "dep-tech-q-lp-interoperability", "text": "Which external phase vocabulary value does this phase map to, and what residue remains unmapped when no external value exists?", "kind": "interoperability", "answer_data": [ "External phase term, vocabulary identifier and version", "Mapping strength (exact, broader, narrower, no-match)", "Recorded residue note for locally defined phases such as deploy" ] } ], "data_elements": [ { "id": "dep-tech-de-phase-code", "name": "Lifecycle phase code", "description": "Phase in which the edge holds; values align to SPDX LifecycleScopeType (build, design, development, runtime, test, other) with deploy defined locally and flagged as unaligned.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-019", "SRC-020" ] }, { "id": "dep-tech-de-validity-interval", "name": "Edge validity interval", "description": "Start and end event times bounding the period in which the edge is asserted to hold, each an RFC 3339 timestamp with seconds and an explicit offset; an open end means still holding, not unknown.", "value_kind": "timestamp", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-026", "SRC-018" ] }, { "id": "dep-tech-de-phase-alignment-note", "name": "Phase alignment residue", "description": "Record of what is lost when a local phase is projected into an external vocabulary, including the case where the external vocabulary has no corresponding value.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-019", "SRC-020" ] } ], "artifacts": [], "inline_only_rationale": "Phase is a coded attribute set plus a validity interval carried directly on each edge assertion; it has no independent existence, no separate governance object and nothing to exchange on its own. The external phase vocabularies it references are published and versioned by SPDX, so reproducing them as a local artifact would create a stale copy and imply ownership of a vocabulary this model only aligns to. The one durable derived object, the unmapped-phase residue, belongs to the external vocabulary crosswalk rather than here." }, { "id": "dep-tech-requirement-qualifier", "name": "Conditionality, alternatives and version or compatibility constraint", "description": "The qualifiers that change how a consumer must read an edge, and the grammar in which acceptable targets are expressed. Conditionality covers optional (the source proceeds without the target), peer (a compatibility expectation on a host that the source does not itself pull in), development-only, transitive versus direct, bundled or vendored (the target ships inside the source's distributed artifact), platform-provided (the target is assumed present and is not distributed), capability-satisfying (the target supplies a named capability that several providers could supply, as with a virtual package or a TOSCA capability), negative or conflicting (the target must not be present, or not at certain versions), and circular. Constraint expression covers declared ranges on an unresolved requirement versus resolved pins on a specific artifact, alternatives, and platform or engine restrictions. Grammars differ irreconcilably across ecosystems, so each expression is stored with the grammar identifier that governs its interpretation and precedence.", "source_refs": [ "SRC-020", "SRC-023", "SRC-024", "SRC-025", "SRC-026" ], "questions": [ { "id": "dep-tech-q-rq-classification", "text": "Which qualifiers apply to this edge - optional, peer, development-only, transitive, bundled or vendored, platform-provided, capability-satisfying, negative or conflicting, or circular?", "kind": "classification", "answer_data": [ "Qualifier flag set with per-flag justification", "Qualifier combinations that the kind forbids", "Ecosystem term that produced each flag, with its grammar identifier" ] }, { "id": "dep-tech-q-rq-constraint", "text": "How is the acceptable target version or capability range expressed, and which ecosystem grammar and precedence rules govern that expression?", "kind": "constraint", "answer_data": [ "Constraint expression string exactly as declared", "Grammar identifier and version (for example a SemVer range, a Debian version relation, a platform or engine restriction)", "Precedence and pre-release handling rule applicable to that grammar" ] }, { "id": "dep-tech-q-rq-relationship", "text": "Is this a declared range against an unresolved requirement or a resolved pin against a specific artifact, and where is each of the two recorded?", "kind": "relationship", "answer_data": [ "Declared versus resolved indicator", "Manifest reference for the declared range and lockfile or attestation reference for the resolved pin", "Digest or content identifier bound to the resolved target" ] }, { "id": "dep-tech-q-rq-exception", "text": "How are alternatives, negative relations and circular relations recorded so that a consumer cannot read them as ordinary requirements?", "kind": "exception", "answer_data": [ "Alternative-set representation and the rule for selecting among alternatives", "Negative relation encoding with its exclusion range and severity (must not coexist versus must be deconfigured first)", "Cycle marker, participating edge identifiers and the reason the cycle is admissible or must be escalated" ] } ], "data_elements": [ { "id": "dep-tech-de-qualifier-flags", "name": "Qualifier flag set", "description": "Coded flags recording optionality, peer status, development-only scope, transitivity, bundling or vendoring, platform-provided status, capability satisfaction, negation and circularity for the edge.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-020", "SRC-023", "SRC-024" ] }, { "id": "dep-tech-de-constraint-expression", "name": "Version or compatibility constraint expression", "description": "The acceptable-target expression exactly as declared, stored verbatim so that it is never reinterpreted outside its own grammar.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-023", "SRC-024", "SRC-025" ] }, { "id": "dep-tech-de-constraint-grammar", "name": "Constraint grammar identifier", "description": "Identifier and version of the grammar governing the constraint expression and its precedence rules; mandatory whenever a constraint expression is present, because cross-ecosystem comparison of ranges is not defined by any primary source.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-023", "SRC-024", "SRC-025" ] }, { "id": "dep-tech-de-resolution-state", "name": "Declared or resolved indicator", "description": "Whether the edge carries an unresolved declared range or a resolved pin, and, when resolved, the reference and digest of the specific artifact selected.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-026", "SRC-021" ] }, { "id": "dep-tech-de-alternative-set", "name": "Alternative target set", "description": "Ordered or unordered set of targets any one of which satisfies the requirement, with the rule that governs selection; recorded rather than collapsed, because collapsing an alternative set to one target fabricates a requirement.", "value_kind": "collection", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-023" ] } ], "artifacts": [], "inline_only_rationale": "Qualifiers and constraint expressions are per-edge attributes whose authoritative form lives in the source manifest, lockfile or topology declaration owned by the ecosystem or the subject's own repository. Copying those declarations into a governed artifact here would duplicate a system of record this model does not own and would invite silent divergence when the manifest changes. The model therefore carries the verbatim expression, its grammar identifier and the reference back to the declaring document, and nothing more." } ] } ] }, { "id": "dep-tech-assertion-bundle", "name": "Edge assertion, evidence and impact licence", "description": "Everything needed to trust a dependency fact and to know how far it may legitimately be carried: the identity and validity of the assertion, how it was determined and with what evidence and completeness, the declarative licence for downstream traversal, and the bindings to external vocabularies and neighbouring analyses.", "rationale": "A typed edge is worthless to an agent without provenance and a completeness statement: CycloneDX warns that objects absent from the dependency graph must be treated as opaque rather than dependency-free, CISA requires known unknowns to be stated explicitly, and SLSA states that resolved build dependencies are complete only on a best-effort basis. Equally, impact tracing is the most common misuse of dependency data, so the permission to traverse must be declared per kind and separated from the act of traversing, which belongs to a consumer.", "source_refs": [ "SRC-021", "SRC-001", "SRC-026", "SRC-030" ], "layers": [ { "id": "dep-tech-assertion-layer", "name": "Edge identity, determination and evidence", "description": "How an individual dependency assertion is identified, timed, attributed, evidenced and qualified for confidence and completeness.", "source_refs": [ "SRC-021", "SRC-001", "SRC-026", "SRC-029", "SRC-030" ], "findings": [ { "id": "dep-tech-edge-identity", "name": "Edge assertion identity and validity", "description": "The dependency edge assertion is a first-class record with its own identifier, distinct from both endpoints and from any document that happens to carry it. It binds a source endpoint reference, a kind code, a target endpoint reference, a phase set, a qualifier set and the pinned kind-register version, and it carries asserter identity, event time, observation time, a validity interval and an integrity binding to the content it describes. Assertions are append-only: a correction supersedes rather than overwrites, and a withdrawal is a tombstone that preserves the identifier so a consumer can tell 'this edge was withdrawn' from 'this edge never existed'. Endpoint re-identification or re-versioning does not silently mutate an existing assertion; it produces a new one with an explicit predecessor link.", "source_refs": [ "SRC-021", "SRC-026", "SRC-029", "SRC-018" ], "questions": [ { "id": "dep-tech-q-ei-identity", "text": "What identifier does the edge assertion itself carry, and how does that identifier stay stable when either endpoint is re-identified or re-versioned?", "kind": "identity", "answer_data": [ "Edge assertion identifier and its issuing tier (master-system key, governed IRI, or Dimension-minted UUID or ULID)", "Predecessor and successor assertion links", "Rule distinguishing endpoint re-identification from a genuinely new edge" ] }, { "id": "dep-tech-q-ei-provenance", "text": "Who asserted this edge, from which artefact or system, and at what event time and separately recorded observation time?", "kind": "provenance", "answer_data": [ "Asserter identity and role", "Source document, manifest, topology declaration or attestation reference", "Event time and observation or ingestion time, each RFC 3339 with seconds and explicit offset" ] }, { "id": "dep-tech-q-ei-temporal", "text": "Over what validity interval is this edge asserted to hold, and how is a retraction distinguished from an expiry or a phase exit?", "kind": "temporal", "answer_data": [ "Validity interval with start and end event times", "Termination reason code (expiry, retraction, supersession, phase exit)", "Tombstone record retaining identifier, kind, reason, retraction event time and asserter" ] }, { "id": "dep-tech-q-ei-validation", "text": "What integrity binding ties the assertion to the endpoint content it describes, and what must a consumer do when that binding cannot be verified?", "kind": "validation", "answer_data": [ "Content digest over the canonical assertion form plus asserter identity", "Endpoint digest or resource descriptor referenced for the resolved target", "Consumer obligation on verification failure (treat as unverified, do not silently accept)" ] } ], "data_elements": [ { "id": "dep-tech-de-edge-id", "name": "Edge assertion identifier", "description": "Stable identifier for the assertion itself, issued from the highest available identity tier and carrying no date-derived component; distinct from either endpoint identifier.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-029", "SRC-021" ] }, { "id": "dep-tech-de-asserter", "name": "Asserter identity", "description": "The agent, tool or role that recorded the assertion, referenced to the adopting Dimension's identity system rather than restated.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-026" ] }, { "id": "dep-tech-de-event-time", "name": "Event time", "description": "When the relation became true or ceased to be true in the subject system, as an RFC 3339 timestamp with seconds and an explicit offset or Z.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-026", "SRC-001" ] }, { "id": "dep-tech-de-observation-time", "name": "Observation or ingestion time", "description": "When the asserter detected or loaded the fact, recorded separately from event time and mandatory whenever the two differ.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-026", "SRC-001" ] }, { "id": "dep-tech-de-integrity-digest", "name": "Integrity digest", "description": "Content digest over the canonical assertion form together with the asserter identity; binds content and is never used as an identifier.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-026", "SRC-021" ] } ], "artifacts": [ { "id": "dep-tech-edge-assertion-record", "name": "Dependency edge assertion record", "description": "The append-only record of one typed dependency assertion: edge identifier, source endpoint reference and class, kind code, target endpoint reference and class, phase set, nature, qualifier set, constraint expression and grammar, resolution state, pinned kind-register version, asserter, event time, observation time, validity interval, termination reason, predecessor and successor links, integrity digest and evidence references. Format-neutral: the same record may be projected as a graph edge, a document node, a row or a message without altering its meaning.", "media_or_form": [ "structured assertion record", "append-only record series with supersession links", "graph edge projection with qualified attributes" ], "serial": true, "identity_strategy": "Keyed by the authoritative master-system identifier for the edge where one exists, otherwise a governed IRI, otherwise a Dimension-minted UUID or ULID marked as Dimension-scoped. Successive assertions about the same edge are distinguished by a monotonic assertion sequence appended to the edge identifier (edge-id#sequence); the sequence never encodes a date, and temporal meaning is carried by event time, observation time and the validity interval.", "source_refs": [ "SRC-021", "SRC-026", "SRC-029", "SRC-018" ] } ], "inline_only_rationale": null }, { "id": "dep-tech-determination", "name": "Determination method, evidence and completeness", "description": "How the edge came to be known and how much may be concluded from it. Three determination methods are kept strictly distinct: declared (stated in a manifest, topology declaration, interface document or other authored artefact), discovered (derived from an observation such as a lockfile resolution, a build attestation of resolved dependencies, an image inventory or a telemetry record produced elsewhere), and inferred (concluded by heuristic, similarity or model, never directly stated or observed). Each carries an evidence reference back to the producing system, a confidence statement with named limitations, and a falsification condition. Separately, completeness is asserted per subject and per kind and phase scope, because a set of edges says nothing about the edges that are missing: an empty outgoing set must never be published or read as independence, and completeness does not propagate uniformly to transitive targets.", "source_refs": [ "SRC-021", "SRC-001", "SRC-026", "SRC-030" ], "questions": [ { "id": "dep-tech-q-dt-evidence", "text": "Was this edge declared in an authored artefact, discovered from an observation produced elsewhere, or inferred, and which evidence reference supports it?", "kind": "evidence", "answer_data": [ "Determination method code", "Evidence reference with uri, digest, name and media type where available", "Producing system identity and whether this model may cite it without re-deriving it" ] }, { "id": "dep-tech-q-dt-quality", "text": "What confidence and named limitations attach to a discovered or inferred edge, and what observation or statement would falsify it?", "kind": "quality", "answer_data": [ "Confidence statement with the scale it uses and that scale's provenance", "Named limitations of the method", "Explicit falsification condition" ] }, { "id": "dep-tech-q-dt-provenance", "text": "Which tool, method and version produced this determination, and is the result reproducible from the recorded inputs alone?", "kind": "provenance", "answer_data": [ "Tool or method identifier and version", "Recorded inputs and parameters sufficient to reproduce, or a statement that reproduction is not possible", "Reference to the attestation or run record held by the producing system" ] }, { "id": "dep-tech-q-dt-validation", "text": "How is completeness of a subject's outgoing edge set asserted for a given kind and phase scope, and how are known unknowns stated so that absence is not read as independence?", "kind": "validation", "answer_data": [ "Completeness level (complete, partial, unknown) with the kind and phase scope it covers", "Explicit known-unknown statement naming what was not examined and why", "As-of event time and observation time for the completeness claim", "Statement that completeness does not propagate to transitive targets" ] } ], "data_elements": [ { "id": "dep-tech-de-determination-method", "name": "Determination method", "description": "Declared, discovered or inferred; fixes what may legitimately be concluded from the edge and constrains which propagation licences apply.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-026", "SRC-030" ] }, { "id": "dep-tech-de-evidence-ref", "name": "Evidence reference", "description": "Pointer to the supporting artefact held by its producing system, following the resource-descriptor shape (uri, digest, name, download location, media type, annotations); the evidence content itself is not copied into this model.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-026", "SRC-021" ] }, { "id": "dep-tech-de-confidence", "name": "Confidence and limitations", "description": "Confidence statement for a discovered or inferred edge together with the named limitations of the method and an explicit falsification condition; the scale used must be named because no primary source prescribes one.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-026", "SRC-030" ] }, { "id": "dep-tech-de-completeness-assertion", "name": "Completeness assertion", "description": "Per-subject, per-kind and per-phase statement of completeness with an explicit known-unknown note and an as-of time; required before any edge set is published, and never inherited by transitive targets.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-021", "SRC-030" ] } ], "artifacts": [], "inline_only_rationale": "Determination method, confidence and completeness are qualifiers carried on the edge assertion record already declared in this layer, and the evidence itself is generated, signed and retained by the producing systems - build provenance attestations, lockfile resolutions, image inventories and observability records. Declaring a separate evidence artifact here would imply that this model produces, verifies or retains that evidence, which it does not; it holds only typed references to evidence owned elsewhere." } ] }, { "id": "dep-tech-impact-layer", "name": "Impact propagation licence and external alignment", "description": "How far a dependency fact may be carried downstream, and how it binds to external vocabularies and to neighbouring analyses that are projections rather than alternative sources of the same fact.", "source_refs": [ "SRC-018", "SRC-020", "SRC-021", "SRC-022", "SRC-001", "SRC-027", "SRC-028", "SRC-030" ], "findings": [ { "id": "dep-tech-propagation", "name": "Declarative impact propagation licence", "description": "For each kind, a declaration of whether a downstream consumer is permitted to traverse the edge when tracing impact, in which direction relative to the edge's canonical direction, with what transitivity limit, and under what stop conditions. The distinction is deliberate: dependency direction points from dependent to dependency, whereas impact usually flows the other way, so the licence names the traversal direction explicitly rather than leaving it implicit. Stop conditions include a bundled or vendored target (impact stops at the containing artifact), a platform-provided target (impact leaves the Dimension's boundary), an optional qualifier, a negative relation, a change of referent class, a deployment-environment boundary, and any relation whose nature is co-location or correlation. The model declares and withholds permission; it never performs traversal, never computes or stores closure, and never ranks or scores what is reached.", "source_refs": [ "SRC-021", "SRC-022", "SRC-023", "SRC-030" ], "questions": [ { "id": "dep-tech-q-pp-relationship", "text": "Does this dependency kind license traversal for downstream impact, and in which direction relative to the edge's canonical direction?", "kind": "relationship", "answer_data": [ "Propagation licence value (granted, granted-with-limits, withheld)", "Traversal direction relative to canonical edge direction", "Rationale referencing the kind's nature and endpoint classes" ] }, { "id": "dep-tech-q-pp-constraint", "text": "Is propagation transitive without limit, bounded by depth, phase or referent-class change, or forbidden outright for this kind?", "kind": "constraint", "answer_data": [ "Transitivity rule and any depth or hop bound", "Phase restriction under which traversal is valid", "Referent-class transitions that terminate traversal" ] }, { "id": "dep-tech-q-pp-decision", "text": "Which stop conditions terminate propagation along this kind, and what evidence must a consumer see before it applies one?", "kind": "decision", "answer_data": [ "Stop condition list with the qualifier or flag that triggers each", "Evidence required to apply a stop condition", "Behaviour when a stop condition and a licence conflict" ] }, { "id": "dep-tech-q-pp-authority", "text": "Who approves a propagation licence, and what additional evidence is required before a discovered or inferred kind is granted one?", "kind": "authority", "answer_data": [ "Approving role and approval event time", "Evidence threshold for discovered and inferred determination methods", "Reference to the consuming model that performs traversal and owns the resulting analysis" ] } ], "data_elements": [ { "id": "dep-tech-de-propagation-licence", "name": "Propagation licence", "description": "Whether the kind grants, conditionally grants or withholds permission for a downstream consumer to traverse the edge when tracing impact.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-021", "SRC-022" ] }, { "id": "dep-tech-de-traversal-direction", "name": "Traversal direction", "description": "Direction of impact traversal expressed relative to the edge's canonical direction, since impact commonly flows opposite to the dependency arrow.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-020", "SRC-022" ] }, { "id": "dep-tech-de-transitivity-rule", "name": "Transitivity rule", "description": "Whether traversal may continue beyond one hop, with any depth bound, phase restriction or referent-class transition that ends it.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-030", "SRC-021" ] }, { "id": "dep-tech-de-stop-condition", "name": "Stop condition", "description": "A named condition that terminates traversal, together with the qualifier, flag or boundary that triggers it; co-location and correlation relations always carry a terminating condition.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-023", "SRC-024", "SRC-022" ] } ], "artifacts": [ { "id": "dep-tech-propagation-licence-profile", "name": "Impact propagation licence profile", "description": "Declarative profile stating, per dependency kind and phase, the propagation licence, traversal direction relative to the canonical edge direction, transitivity rule and stop conditions, together with the approving role and the evidence threshold applied to discovered and inferred edges. It is a permission statement consumed by traversal-performing models; it contains no computed closure, no reachability verdict, no ranked impact set and no notification or enforcement instruction.", "media_or_form": [ "declarative permission profile keyed by kind and phase", "rule table with direction, transitivity and stop-condition columns" ], "serial": false, "identity_strategy": "Keyed by the Dimension-governed register namespace IRI plus the kind code and phase, qualified by monotonic profile version (namespace/kind-code/phase@version), bound to the kind-register version it was approved against. Revoking or narrowing a licence produces a new version; no date-derived component appears in the key.", "source_refs": [ "SRC-021", "SRC-022", "SRC-030" ] } ], "inline_only_rationale": null }, { "id": "dep-tech-interop-projection", "name": "External vocabulary alignment and neighbouring-analysis boundary", "description": "Bindings from local kinds, phases and qualifiers to external dependency vocabularies - SPDX relationship types and lifecycle scopes, CycloneDX dependsOn and provides with its compositions completeness assertion, TOSCA requirements and capabilities with occurrences, PROV influence and usage, package manifests and lockfiles, OpenAPI and AsyncAPI references, and infrastructure declarations - recorded with an explicit mapping strength and the residue that survives the mapping. Alignment is never conformance: a conformance claim requires published evidence. The same finding fixes the boundary against neighbouring analyses that consume or project dependency facts without being interchangeable with them: software composition analysis, vulnerability reachability, runtime call extraction and data lineage each answer a different question and are recorded as consumers or evidence producers, never as sources of typed dependency facts on equal footing.", "source_refs": [ "SRC-018", "SRC-020", "SRC-021", "SRC-015", "SRC-022", "SRC-001", "SRC-027", "SRC-028", "SRC-030" ], "questions": [ { "id": "dep-tech-q-ip-interoperability", "text": "Which external vocabulary term, at which vocabulary version, does this kind bind to, and is the mapping exact, broader, narrower or absent?", "kind": "interoperability", "answer_data": [ "External term and vocabulary identifier with version or edition", "Mapping strength code", "Direction normalisation applied where the external term is stated inversely" ] }, { "id": "dep-tech-q-ip-constraint", "text": "What semantics are lost or silently added when this edge is projected into a given external representation, and how is that residue recorded?", "kind": "constraint", "answer_data": [ "Residue note naming each dropped facet (phase, nature, qualifier, cardinality, alternative set, evidence)", "Facets the external representation would add or presume that the local edge does not assert", "Round-trip test result showing whether the projection is reversible" ] }, { "id": "dep-tech-q-ip-definition", "text": "Which neighbouring analyses are projections or consumers of dependency facts rather than sources of them, and what question does each actually answer?", "kind": "definition", "answer_data": [ "Neighbouring analysis name and the question it answers", "Whether it consumes edges, produces evidence, or both", "Explicit statement that its output is not a typed dependency fact" ] }, { "id": "dep-tech-q-ip-quality", "text": "What published evidence is required before conformance to an external vocabulary is claimed rather than mere alignment?", "kind": "quality", "answer_data": [ "Conformance evidence type and its publication reference", "Current claim status (aligned only, conformance claimed with evidence, conflict recorded)", "Recorded conflicts where two external vocabularies cannot both be satisfied" ] } ], "data_elements": [ { "id": "dep-tech-de-external-term", "name": "External vocabulary term binding", "description": "The external term, its vocabulary identifier and pinned version or edition, and the local kind, phase or qualifier it binds to.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-018", "SRC-020", "SRC-021", "SRC-015", "SRC-022", "SRC-001" ] }, { "id": "dep-tech-de-mapping-strength", "name": "Mapping strength", "description": "Exact, broader, narrower or no-match; a no-match is recorded rather than forced, and never silently upgraded to exact.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-020", "SRC-021" ] }, { "id": "dep-tech-de-mapping-residue", "name": "Mapping residue note", "description": "What is lost or added by a projection into a given external representation, including facets the target vocabulary cannot carry and presumptions it introduces.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-021", "SRC-022", "SRC-023" ] }, { "id": "dep-tech-de-claim-status", "name": "Alignment or conformance claim status", "description": "Whether the binding is an alignment only, a conformance claim supported by published evidence, or a recorded conflict; defaults to alignment only.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-015", "SRC-030" ] } ], "artifacts": [ { "id": "dep-tech-vocabulary-crosswalk", "name": "External dependency vocabulary crosswalk", "description": "Versioned crosswalk mapping each local kind, phase and qualifier to terms in SPDX 2.3 and 3.0.1, CycloneDX and ECMA-424, OASIS TOSCA 2.0, W3C PROV-O, package manifest and lockfile grammars, and OpenAPI and AsyncAPI reference constructs. Each row carries the external vocabulary version, mapping strength, direction normalisation, residue note, round-trip reversibility result and claim status, plus a conflicts section recording pairs of external terms that cannot both be honoured.", "media_or_form": [ "crosswalk table with mapping-strength and residue columns", "machine-readable mapping set with pinned vocabulary versions", "conflicts register" ], "serial": false, "identity_strategy": "Each row is keyed by the local kind code plus the external vocabulary identifier and its pinned version or edition, within the Dimension-governed crosswalk namespace IRI, qualified by monotonic crosswalk version. Where an external vocabulary publishes its own term IRI, that IRI is referenced rather than copied. No date-derived component appears in the key.", "source_refs": [ "SRC-018", "SRC-020", "SRC-021", "SRC-015", "SRC-022", "SRC-001", "SRC-027", "SRC-028" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "dep-soc-bundle-kind-taxonomy", "name": "Socio-operational dependency kind taxonomy", "description": "The catalogue of dependency kinds whose depended-on endpoint is an activity, capability, actor, arrangement, obligation, resource, time window, place or jurisdiction, each with its own endpoint rules and discriminating evidence.", "rationale": "No single authority types socio-operational reliance. BPMN types intra-process ordering and cross-participant messaging, W3C ORG types structural and reporting relations, ODRL types duties, DORA and CSDDD type third-party and chain reliance with different scopes, and UN/CEFACT separates buy, ship and pay strands. An untyped 'depends on' edge silently merges these, so the taxonomy must be assembled explicitly and each kind must carry its own falsification test.", "source_refs": [ "SRC-031", "SRC-032", "SRC-034", "SRC-035", "SRC-036", "SRC-043" ], "layers": [ { "id": "dep-soc-layer-work-capability", "name": "Work and capability reliance", "description": "Kinds whose depended-on endpoint is work to be performed: an activity or process step, or a capability, competence, qualification or authorisation that makes performance possible.", "source_refs": [ "SRC-031", "SRC-044", "SRC-035", "SRC-039" ], "findings": [ { "id": "dep-soc-finding-process-flow-reliance", "name": "Process and activity reliance, and the sequence-is-not-causation rule", "description": "A process dependency asserts that an activity cannot start, continue or complete without a specific output, decision or message from another activity or participant. BPMN sequence flow orders flow elements within one process and message flow crosses participant boundaries; neither is a causal claim, and Allen interval relations order intervals without asserting causation. This finding fixes when an observed ordering may be promoted to a declared reliance and what blocking mode applies.", "source_refs": [ "SRC-031", "SRC-033", "SRC-039" ], "questions": [ { "id": "dep-soc-q-process-construct", "text": "Which modelled construct grounds this reliance: an intra-process sequence flow, a cross-participant message flow, a data association, or none of these?", "kind": "classification", "answer_data": [ "Construct class code", "Reference to the source process model and element identifier", "Flag for unmodelled reliance" ] }, { "id": "dep-soc-q-process-consumed", "text": "What specific output, decision or message does the dependent activity consume from the depended-on activity?", "kind": "relationship", "answer_data": [ "Consumed output or message reference", "Producing activity reference", "Consuming activity reference" ] }, { "id": "dep-soc-q-process-blocking", "text": "If the depended-on activity does not complete, is the effect a hard stop, a degraded continuation, or a documented manual workaround?", "kind": "constraint", "answer_data": [ "Blocking mode code", "Workaround description and its own preconditions", "Tolerance window before the effect bites" ] }, { "id": "dep-soc-q-process-basis", "text": "What evidence separates this from mere observed ordering: a modelled flow, a written procedure, or only historical co-occurrence?", "kind": "evidence", "answer_data": [ "Evidence basis code", "Cited procedure or model version", "Result of the reordering test" ] }, { "id": "dep-soc-q-process-variant", "text": "For which process version, variant or participant lane does this assertion hold?", "kind": "process", "answer_data": [ "Process identifier and version", "Variant or lane identifier", "Applicability note for other variants" ] } ], "data_elements": [ { "id": "dep-soc-de-depended-activity-ref", "name": "Depended-on activity reference", "description": "Governed reference to the activity, task or process step relied upon, resolved in the owning process model repository.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-031" ] }, { "id": "dep-soc-de-flow-construct-code", "name": "Flow construct code", "description": "Code recording which BPMN-style construct grounds the reliance: sequence flow, message flow, data association, or unmodelled.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-031" ] }, { "id": "dep-soc-de-blocking-mode-code", "name": "Blocking mode code", "description": "Effect of non-performance on the dependent activity: hard-blocking, degrading, or advisory.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-031", "SRC-039" ] }, { "id": "dep-soc-de-consumed-output-ref", "name": "Consumed output reference", "description": "Reference to the output, decision or message that the dependent activity consumes.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-031" ] }, { "id": "dep-soc-de-process-variant-scope", "name": "Process variant scope", "description": "Process version, variant or lane for which the assertion is claimed to hold.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-031" ] } ], "artifacts": [], "inline_only_rationale": "The finding contributes typed relation semantics and reference data carried on the host subject record. The process models, procedures and execution logs that supply the evidence are artifacts of the process-model and operations neighbours; producing a local copy would duplicate a target-owned artifact and would drift from its version." }, { "id": "dep-soc-finding-capability-competence-reliance", "name": "Capability, competence and authorisation-to-perform reliance", "description": "Reliance on an ability to perform rather than on a named holder: a capability concept, a skill or competence, a qualification, or an authorisation or licence that permits performance. ESCO supplies governed occupation, skill and knowledge concepts mapped to ISCO, so the endpoint is a concept identifier rather than free text. Regulatory function tests such as the DORA critical-or-important-function materiality test show that the dependent side is often a function, not a system.", "source_refs": [ "SRC-044", "SRC-035", "SRC-042" ], "questions": [ { "id": "dep-soc-q-capability-nature", "text": "Is the depended-on endpoint a capability concept, a qualification, or an authorisation to perform, and how is each defined here?", "kind": "definition", "answer_data": [ "Endpoint nature code", "Local definition text", "Discriminating example and counterexample" ] }, { "id": "dep-soc-q-capability-concept-id", "text": "Which governed classification concept identifies the capability or competence, and at which scheme version?", "kind": "identity", "answer_data": [ "Concept identifier or IRI", "Scheme name and version", "Local extension flag where no governed concept exists" ] }, { "id": "dep-soc-q-capability-threshold", "text": "What minimum proficiency, coverage or number of qualified holders must exist for the dependent function to remain performable?", "kind": "requirement", "answer_data": [ "Minimum qualified holder count", "Proficiency or level threshold", "Coverage window such as shift or region" ] }, { "id": "dep-soc-q-capability-function-test", "text": "Is the dependent endpoint classified as a critical or important function under a cited regulatory test, and which test is applied?", "kind": "classification", "answer_data": [ "Function criticality code", "Citation of the applied test with jurisdiction", "Assessor and assessment reference" ] }, { "id": "dep-soc-q-capability-substitution", "text": "What substitution, delegation or temporary derogation is recognised when the capability is unavailable, and what does it not cover?", "kind": "exception", "answer_data": [ "Substitution allowed flag", "Permitted substitute concepts", "Explicit exclusions and approval authority reference" ] } ], "data_elements": [ { "id": "dep-soc-de-capability-concept-ref", "name": "Capability concept reference", "description": "Governed concept identifier for the capability, skill, knowledge or qualification relied upon.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-044" ] }, { "id": "dep-soc-de-capability-scheme-version", "name": "Capability scheme version", "description": "Name and version of the classification scheme from which the concept is drawn.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-044" ] }, { "id": "dep-soc-de-minimum-qualified-holders", "name": "Minimum qualified holders", "description": "Minimum number of holders with the capability required for the dependent function to remain performable.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-039" ] }, { "id": "dep-soc-de-authorisation-required-flag", "name": "Authorisation required flag", "description": "Whether performance additionally requires an authorisation, licence or registration beyond the competence itself.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-035", "SRC-042" ] }, { "id": "dep-soc-de-function-criticality-code", "name": "Function criticality code", "description": "Classification of the dependent function under a cited regulatory or internal criticality test, with the test recorded separately.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-035", "SRC-042" ] } ], "artifacts": [], "inline_only_rationale": "Capability reliance resolves to governed concept references plus thresholds held on the host record. The competence catalogue, qualification records and authorisation certificates are mastered by the classification authority and by the workforce and licensing models; reproducing them here would create a competing register." } ] }, { "id": "dep-soc-layer-actor-agreement", "name": "Actor, arrangement and obligation reliance", "description": "Kinds whose depended-on endpoint is an organization, unit, post, role holder, business partner, arrangement, or a normative rule cited from a contract, statute or policy.", "source_refs": [ "SRC-032", "SRC-041", "SRC-035", "SRC-036", "SRC-034", "SRC-042" ], "findings": [ { "id": "dep-soc-finding-org-role-reliance", "name": "Organizational, post and role reliance separated from ownership and reporting", "description": "W3C ORG models subOrganizationOf, hasUnit, reportsTo, Post, Role and time-bounded Membership; GLEIF Level 2 models direct and ultimate accounting consolidating parents. None of these is a dependency: a parent may supply nothing, and an unrelated supplier may be indispensable. This finding declares the reliance edge on an actor at a stated granularity and holds the tests that keep it distinct from control, ownership and reporting structure.", "source_refs": [ "SRC-032", "SRC-041", "SRC-045" ], "questions": [ { "id": "dep-soc-q-actor-identifier", "text": "Which identifier identifies the depended-on actor: a legal entity identifier, an internal organizational unit identifier, or a post identifier?", "kind": "identity", "answer_data": [ "Actor endpoint reference", "Identifier scheme and issuing authority", "Fallback identifier tier used and why" ] }, { "id": "dep-soc-q-actor-not-structural", "text": "Is the asserted edge a reliance on the actor's performance, or a structural, ownership or reporting relation already mastered elsewhere?", "kind": "relationship", "answer_data": [ "Structural relation excluded flag", "Reference to the structural relation that was ruled out", "Outcome of the ownership discrimination test" ] }, { "id": "dep-soc-q-actor-granularity", "text": "At what granularity is the reliance asserted: legal entity, organizational unit, post, or the individual holder of a post?", "kind": "composition", "answer_data": [ "Granularity code", "Justification for asserting below unit level", "Aggregation rule to the next level up" ] }, { "id": "dep-soc-q-actor-ownership", "text": "Who owns the depended-on actor record, and does a change of ownership or consolidation alter the reliance claim?", "kind": "ownership", "answer_data": [ "Owning master system reference", "Consolidation change sensitivity note", "Notification expectation on endpoint change" ] }, { "id": "dep-soc-q-actor-vacancy", "text": "How is the reliance re-evaluated when the post is vacant, the unit is merged, or the holder changes?", "kind": "lifecycle", "answer_data": [ "Vacancy handling rule", "Re-evaluation trigger list", "Default disposition pending re-evaluation" ] } ], "data_elements": [ { "id": "dep-soc-de-actor-endpoint-ref", "name": "Actor endpoint reference", "description": "Governed reference to the depended-on organization, unit, post or holder.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-032", "SRC-045" ] }, { "id": "dep-soc-de-actor-granularity-code", "name": "Actor granularity code", "description": "Level at which the reliance is asserted: legal entity, organizational unit, post, or individual holder.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-032" ] }, { "id": "dep-soc-de-structural-relation-excluded-flag", "name": "Structural relation excluded flag", "description": "Records that the assertion was tested against, and is not merely, a sub-organization, consolidation or reporting relation.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-032", "SRC-041" ] }, { "id": "dep-soc-de-vacancy-handling-note", "name": "Vacancy handling note", "description": "Rule applied when a depended-on post is vacant or its holder changes.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-032" ] } ], "artifacts": [], "inline_only_rationale": "The output is a typed edge plus discrimination flags attached to the host record. Organization charts, membership records and ownership hierarchies are artifacts of the organization register and of the LEI system; generating a local organizational artifact would duplicate a target-owned master and invite divergence." }, { "id": "dep-soc-finding-supplier-chain-reliance", "name": "Supplier, third-party and subcontracting-chain reliance", "description": "Reliance on external parties, distinguishing outsourcing of a function from purchase of goods or services and from informal reliance, recording chain position for direct and indirect partners and nth-tier subcontractors, and capturing substitutability as an assessment input. Scope differs by instrument: a CSDDD chain of activities excludes product disposal and, for regulated financial undertakings, downstream activities, while a DORA register of information covers ICT arrangements including subcontracting; the same counterparty can therefore be in one scope and outside another.", "source_refs": [ "SRC-035", "SRC-036", "SRC-040", "SRC-042", "SRC-038", "SRC-041" ], "questions": [ { "id": "dep-soc-q-supplier-arrangement-type", "text": "Is the arrangement outsourcing of a function, a purchase of goods or services, or a reliance with no contract at all?", "kind": "classification", "answer_data": [ "Arrangement type code", "Criteria applied and citing guidance", "Arrangement master record reference where one exists" ] }, { "id": "dep-soc-q-supplier-chain-position", "text": "What is the depended-on party's chain position, direct partner, indirect partner or nth-tier subcontractor, and through which intermediate parties?", "kind": "composition", "answer_data": [ "Chain position ordinal", "Intermediate party references in order", "Point at which visibility stops" ] }, { "id": "dep-soc-q-supplier-substitutability", "text": "How substitutable is the party, measured on what scale, and over what switching period?", "kind": "measurement", "answer_data": [ "Substitutability measure and unit", "Switching period as a duration", "Named alternatives and their own dependencies" ] }, { "id": "dep-soc-q-supplier-register-target", "text": "Which external register or reporting schema must this record populate, and what mandatory fields does that schema impose?", "kind": "interoperability", "answer_data": [ "Target schema identifier and version", "Field mapping table", "Unmapped or unavailable field list" ] }, { "id": "dep-soc-q-supplier-visibility-right", "text": "Which contractual right or supervisory power permits visibility into the sub-tier, and where does that right end?", "kind": "authority", "answer_data": [ "Cited clause or instrument reference", "Scope and limits of the visibility right", "Evidence that the sub-tier data was obtained under it" ] } ], "data_elements": [ { "id": "dep-soc-de-arrangement-type-code", "name": "Arrangement type code", "description": "Classification of the arrangement as outsourcing of a function, purchase of goods or services, or non-contractual reliance.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-042", "SRC-035" ] }, { "id": "dep-soc-de-arrangement-ref", "name": "Arrangement reference", "description": "Reference to the arrangement or contract record in the owning master system.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-035", "SRC-042" ] }, { "id": "dep-soc-de-chain-position-ordinal", "name": "Chain position ordinal", "description": "Hop count from the asserting subject to the depended-on party; one denotes a direct business partner.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-036", "SRC-038" ] }, { "id": "dep-soc-de-intermediate-party-ref", "name": "Intermediate party reference", "description": "Ordered references to parties standing between the subject and the depended-on party.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-035", "SRC-036" ] }, { "id": "dep-soc-de-substitutability-measure", "name": "Substitutability measure", "description": "Assessed replaceability of the party with its scale, unit and switching period; an input to, not a result of, risk evaluation.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-035", "SRC-040" ] }, { "id": "dep-soc-de-supported-function-ref", "name": "Supported function reference", "description": "The subject-side function or activity that the external party supports.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-035", "SRC-042" ] } ], "artifacts": [ { "id": "dep-soc-artifact-third-party-register-extract", "name": "Third-party dependency register extract", "description": "A read-only extract for one reporting scope listing depended-on parties, arrangement type, chain position, intermediate parties, supported functions and substitutability inputs, shaped so that it can populate an external arrangement or outsourcing register without this model interpreting the underlying obligation.", "media_or_form": [ "tabular register extract", "structured record set", "human-readable register report" ], "serial": true, "identity_strategy": "Each row is keyed by the arrangement identifier issued by the authoritative arrangement master system, plus the depended-on party's ISO 17442 legal entity identifier where one exists and a Dimension-assigned ULID only where neither is available. The extract itself is identified by scope key plus a monotonic sequence number and the kind-profile version; the reporting reference instant is carried as metadata and is never part of the identifier.", "source_refs": [ "SRC-035", "SRC-042", "SRC-040", "SRC-041", "SRC-045" ] } ], "inline_only_rationale": null }, { "id": "dep-soc-finding-obligation-vs-reliance", "name": "Normative obligation distinguished from operational reliance", "description": "An obligation is a deontic statement: a duty owed by or to a party under a contract, statute or policy, with an assigner, an assignee and a fulfilment condition. Operational reliance is a factual statement that performance fails without a counterparty's act. They frequently co-occur but are independent: a redundant duty can exist with no reliance, and an informal accommodation can create reliance with no duty. This finding carries only the citation, the deontic class asserted at the source, and the outcome of the independence test; the rule's text, remedies and fulfilment state stay with the instrument model.", "source_refs": [ "SRC-034", "SRC-037", "SRC-042" ], "questions": [ { "id": "dep-soc-q-obligation-nature", "text": "Is the asserted item a duty, a condition attached to a permission or prohibition, or a purely factual operational reliance?", "kind": "definition", "answer_data": [ "Deontic class code or none", "Local definition applied", "Discriminating example" ] }, { "id": "dep-soc-q-obligation-citation", "text": "Which legal act, contract clause or policy statement is cited, by governed identifier and version?", "kind": "provenance", "answer_data": [ "Instrument identifier such as an ELI URI or contract clause reference", "Version or consolidation point", "Retrieval reference and access constraints" ] }, { "id": "dep-soc-q-obligation-direction", "text": "Which party bears the duty and which benefits, and does that direction match the direction of the operational reliance?", "kind": "authority", "answer_data": [ "Obligated party reference", "Beneficiary party reference", "Direction agreement flag with explanation where they diverge" ] }, { "id": "dep-soc-q-obligation-consequence", "text": "What consequence does the cited rule attach to non-performance, and is that consequence recorded here or owned by the instrument model?", "kind": "constraint", "answer_data": [ "Consequence summary as a pointer only", "Owning model reference for remedies", "Explicit statement that this model records no fulfilment state" ] }, { "id": "dep-soc-q-obligation-independence", "text": "What test shows whether removing the obligation would remove the operational reliance?", "kind": "validation", "answer_data": [ "Reliance independent of duty flag", "Test description and date of execution", "Reviewer reference" ] } ], "data_elements": [ { "id": "dep-soc-de-normative-instrument-ref", "name": "Normative instrument reference", "description": "Governed citation to the legal act, contract clause or policy statement that creates the duty.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-037", "SRC-034" ] }, { "id": "dep-soc-de-deontic-class-code", "name": "Deontic class code", "description": "Class of the cited rule at its source: duty, permission condition, or prohibition condition.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-034" ] }, { "id": "dep-soc-de-obligated-party-ref", "name": "Obligated party reference", "description": "Party bearing the duty under the cited rule, recorded to test direction agreement with the reliance edge.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-034" ] }, { "id": "dep-soc-de-reliance-independent-of-duty-flag", "name": "Reliance independent of duty flag", "description": "Whether the operational reliance survives removal of the cited obligation.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-034", "SRC-042" ] } ], "artifacts": [], "inline_only_rationale": "This finding deliberately produces only citations, a deontic class code and a test outcome. Materialising an obligation artifact here would reproduce the instrument model's content and would risk presenting a derived summary as the operative legal text across jurisdictions with different interpretive rules." } ] }, { "id": "dep-soc-layer-situational-resource", "name": "Resource, time, place and jurisdiction reliance", "description": "Kinds whose depended-on endpoint is a fund, revenue stream, payment settlement, workforce or material resource, or a situational condition of time, location or jurisdiction.", "source_refs": [ "SRC-043", "SRC-033", "SRC-037", "SRC-007", "SRC-035", "SRC-039" ], "findings": [ { "id": "dep-soc-finding-financial-resource-reliance", "name": "Financial and non-financial resource reliance", "description": "Reliance on funding, revenue concentration, payment settlement, workforce capacity or material resources. The UN/CEFACT Buy-Ship-Pay model separates the buy, ship and pay strands, so reliance on a counterparty for settlement is a different assertion from reliance on the same counterparty for delivery or for the underlying agreement. Business impact analysis practice supplies the resource-requirement framing. Accounting recognition and any payment execution are excluded.", "source_refs": [ "SRC-043", "SRC-039", "SRC-040" ], "questions": [ { "id": "dep-soc-q-resource-strand", "text": "Which resource strand is relied upon: funding or budget, revenue, payment settlement, workforce capacity, or physical material?", "kind": "classification", "answer_data": [ "Resource strand code", "Counterparty or pool reference", "Note where several strands run to the same counterparty" ] }, { "id": "dep-soc-q-resource-measure", "text": "What quantity, share or concentration figure expresses the reliance, in which unit and over which period?", "kind": "measurement", "answer_data": [ "Reliance share value and unit", "Measurement period as a duration", "Measurement method and source system" ] }, { "id": "dep-soc-q-resource-target", "text": "Does the reliance run to a named counterparty, to a specific instrument or facility, or to an aggregate pool?", "kind": "relationship", "answer_data": [ "Endpoint kind code", "Endpoint reference", "Aggregation basis where a pool is used" ] }, { "id": "dep-soc-q-resource-state", "text": "What resource state does the reliance assume: committed, contingent, discretionary, or withdrawn?", "kind": "state", "answer_data": [ "Resource state code", "Basis for the state assertion", "Trigger that would change the state" ] }, { "id": "dep-soc-q-resource-alternative", "text": "Which contingency, reserve or alternative source is recognised, and what does it explicitly not cover?", "kind": "exception", "answer_data": [ "Alternative source references", "Coverage limits and exclusions", "Activation lead time" ] } ], "data_elements": [ { "id": "dep-soc-de-resource-strand-code", "name": "Resource strand code", "description": "Strand of resource reliance: funding, revenue, settlement, workforce capacity, or material.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-043", "SRC-039" ] }, { "id": "dep-soc-de-reliance-share", "name": "Reliance share", "description": "Quantified share or concentration expressing the extent of reliance, with unit.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-040" ] }, { "id": "dep-soc-de-measurement-period", "name": "Measurement period", "description": "Period over which the reliance share is measured.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007" ] }, { "id": "dep-soc-de-resource-state-code", "name": "Resource state code", "description": "Assumed state of the relied-upon resource: committed, contingent, discretionary, or withdrawn.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-039" ] }, { "id": "dep-soc-de-alternative-source-ref", "name": "Alternative source reference", "description": "References to recognised contingency, reserve or alternative resource sources.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-039", "SRC-040" ] } ], "artifacts": [], "inline_only_rationale": "Resource reliance is expressed as coded strands, measures and references held on the host record. Ledgers, budgets, funding agreements and workforce plans are mastered by finance and workforce models, and any figure restated here would be a stale copy of a controlled financial record." }, { "id": "dep-soc-finding-time-place-jurisdiction-reliance", "name": "Temporal, spatial and jurisdictional reliance", "description": "Three situational kinds. Temporal reliance binds the subject to a window, deadline, calendar or required lead time, expressed with Allen interval relations for topology and RFC 3339 instants for endpoints. Spatial reliance binds it to a site, access route or co-location using governed location codes. Jurisdictional reliance binds it to an authorisation, recognition or applicable-law condition of a named jurisdiction, cited by governed legal identifier. DORA's specific concern with subcontractors established in a third country is an example that jurisdictional reliance is material; it is used as an instance, not as universal doctrine.", "source_refs": [ "SRC-033", "SRC-007", "SRC-037", "SRC-043", "SRC-035" ], "questions": [ { "id": "dep-soc-q-temporal-relation", "text": "What temporal relation is asserted between which two intervals, and is a minimum lead time required?", "kind": "temporal", "answer_data": [ "Temporal relation code drawn from the interval relation set", "Interval endpoint instants with offsets", "Required lead time as a duration" ] }, { "id": "dep-soc-q-spatial-binding", "text": "Which governed location or site identifier bounds the reliance, and does the reliance survive relocation of that site?", "kind": "spatial", "answer_data": [ "Location code and code list version", "Site reference in the owning facility model", "Relocation sensitivity flag" ] }, { "id": "dep-soc-q-jurisdiction-nature", "text": "Is the jurisdictional element an authorisation to operate, a recognition or equivalence, a localisation constraint, or a choice of governing law?", "kind": "classification", "answer_data": [ "Jurisdictional element code", "Jurisdiction code and reference frame", "Citing instrument identifier" ] }, { "id": "dep-soc-q-situational-lapse", "text": "What becomes of the assertion when the window closes, the site becomes unavailable, or the authorisation lapses?", "kind": "state", "answer_data": [ "Lapse disposition code", "Automatic expiry rule", "Re-assertion requirement" ] }, { "id": "dep-soc-q-situational-codelists", "text": "Which code lists are used for country, subdivision and location, and at which versions?", "kind": "interoperability", "answer_data": [ "Code list identifiers and versions", "Mapping notes to alternative lists", "Handling of codes with no governed equivalent" ] } ], "data_elements": [ { "id": "dep-soc-de-temporal-relation-code", "name": "Temporal relation code", "description": "Interval relation asserted between the dependent and depended-on intervals, drawn from the standard thirteen elementary relations.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-033" ] }, { "id": "dep-soc-de-required-lead-time", "name": "Required lead time", "description": "Minimum interval that must elapse between the depended-on event and the dependent activity.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-033", "SRC-007" ] }, { "id": "dep-soc-de-validity-interval", "name": "Validity interval", "description": "Interval over which the assertion holds, with both bounds expressed as RFC 3339 instants carrying seconds and an explicit offset or Z.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-033" ] }, { "id": "dep-soc-de-location-code", "name": "Location code", "description": "Governed location or site code bounding a spatial reliance, with its code list version recorded.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-043" ] }, { "id": "dep-soc-de-jurisdiction-code", "name": "Jurisdiction code", "description": "Code for the jurisdiction whose authorisation, recognition or law the reliance depends upon, stated relative to a named reference frame.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-037", "SRC-035" ] }, { "id": "dep-soc-de-jurisdictional-basis-ref", "name": "Jurisdictional basis reference", "description": "Citation to the instrument or authorisation creating the jurisdictional reliance.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-037" ] } ], "artifacts": [], "inline_only_rationale": "These are qualifiers on an assertion rather than deliverables: coded relations, instants, location codes and citations. Licences, permits, site records and legal texts are artifacts of the licensing, facility and legal-instrument models, and copying them would import one jurisdiction's document form into a jurisdiction-neutral model." } ] } ] }, { "id": "dep-soc-bundle-declaration-discipline", "name": "Declaration discipline for socio-operational dependencies", "description": "The rules that make a typed socio-operational assertion checkable and refutable: per-kind direction, endpoint constraints, cardinality, cycle and transitivity rules, applicability conditions, evidence grading, discrimination tests and disposition.", "rationale": "A taxonomy without endpoint and direction rules yields edges that cannot be validated or refuted. PROV models influence rather than causation and supplies a qualified pattern for attributing an assertion to an agent, W3C ORG demonstrates that a plausible acyclicity assumption had to be withdrawn from a published vocabulary, and supervisory guidance expects a declared dependency to trace to a basis rather than to inference.", "source_refs": [ "SRC-001", "SRC-032", "SRC-040", "SRC-035", "SRC-007" ], "layers": [ { "id": "dep-soc-layer-relation-semantics", "name": "Relation semantics and applicability", "description": "Per-kind declaration of dependent and depended-on endpoint types, direction, cardinality, cycle and transitivity behaviour, applicability conditions and external alignments.", "source_refs": [ "SRC-001", "SRC-032", "SRC-031", "SRC-034" ], "findings": [ { "id": "dep-soc-finding-direction-endpoint-cardinality", "name": "Direction, endpoint constraints, cardinality and applicability per kind", "description": "Every kind in the taxonomy declares its permitted dependent and depended-on endpoint types, its canonical direction, whether an inverse is derived rather than stored, cardinality on each side, whether cycles are permitted, whether the relation is transitive across chain hops, and the conditions under which the assertion applies at all. The specialization pattern of a non-causal influence superproperty supplies the modelling idiom, the withdrawal of the reportsTo acyclicity claim shows that cycle behaviour must be declared and not assumed, and the sequence-versus-message distinction shows that endpoint scope differs by kind.", "source_refs": [ "SRC-001", "SRC-032", "SRC-031", "SRC-034" ], "questions": [ { "id": "dep-soc-q-kind-endpoint-types", "text": "For this kind, which dependent and depended-on endpoint types are permitted, and which are explicitly forbidden?", "kind": "composition", "answer_data": [ "Permitted endpoint type list per side", "Forbidden endpoint type list with reasons", "Owning model for each endpoint type" ] }, { "id": "dep-soc-q-kind-cardinality-cycles", "text": "What cardinality applies on each side of this kind, and is a cycle permitted?", "kind": "constraint", "answer_data": [ "Cardinality expression per side", "Cycle permitted flag with handling rule", "Validation behaviour when the constraint is breached" ] }, { "id": "dep-soc-q-kind-transitivity", "text": "Is this kind transitive across chain hops, and if not, how must multi-hop reliance be declared?", "kind": "relationship", "answer_data": [ "Transitivity flag", "Multi-hop declaration rule", "Inference block statement for consumers" ] }, { "id": "dep-soc-q-kind-applicability", "text": "Which conditions must hold for an assertion of this kind to be applicable, and what renders it inapplicable?", "kind": "requirement", "answer_data": [ "Applicability condition list", "Inapplicability triggers", "Default disposition when a condition fails" ] }, { "id": "dep-soc-q-kind-alignment-limit", "text": "Which external property or definition does this kind align to, and at exactly which point does the alignment stop?", "kind": "interoperability", "answer_data": [ "External property or term identifier with version", "Alignment type such as broader, narrower or related", "Explicit non-conformance note where semantics diverge" ] } ], "data_elements": [ { "id": "dep-soc-de-kind-identifier", "name": "Kind identifier", "description": "Stable identifier of the dependency kind within the owning Dimension namespace.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-032", "SRC-001" ] }, { "id": "dep-soc-de-kind-profile-version", "name": "Kind profile version", "description": "Ordered version label of the profile under which an assertion was made; never a date used as identity.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-007" ] }, { "id": "dep-soc-de-permitted-endpoint-types", "name": "Permitted endpoint types", "description": "Declared endpoint type sets for the dependent and depended-on sides of the kind.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-032", "SRC-031" ] }, { "id": "dep-soc-de-cardinality-constraint", "name": "Cardinality constraint", "description": "Cardinality expression for each side of the relation as declared by the profile.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-032" ] }, { "id": "dep-soc-de-transitivity-flag", "name": "Transitivity flag", "description": "Whether consumers may infer a multi-hop edge for this kind.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-032" ] }, { "id": "dep-soc-de-cycle-permitted-flag", "name": "Cycle permitted flag", "description": "Whether cycles are permitted for this kind, following the explicit withdrawal of a general acyclicity assumption in published organizational vocabularies.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-032" ] }, { "id": "dep-soc-de-alignment-mapping", "name": "Alignment mapping", "description": "Mappings from the kind to external properties or terms, with the version and the point at which the alignment ceases to hold.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-034", "SRC-043" ] } ], "artifacts": [ { "id": "dep-soc-artifact-kind-profile", "name": "Dependency kind profile", "description": "The versioned, machine-readable declaration of one dependency kind: endpoint types per side, canonical direction, cardinality, cycle and transitivity behaviour, applicability conditions, required evidence grade, applicable false-positive tests, and external alignment mappings with their limits.", "media_or_form": [ "versioned profile record", "vocabulary or schema fragment", "human-readable kind definition page" ], "serial": false, "identity_strategy": "Identified by the kind identifier minted in the owning Dimension package namespace, expressed as a stable IRI where the Dimension publishes one, paired with an ordered version label. The owning package is identified by its master-system identifier and, where it is a legal entity, its ISO 17442 identifier. Publication and review dates are metadata and never form part of the identifier.", "source_refs": [ "SRC-032", "SRC-001", "SRC-031", "SRC-045" ] } ], "inline_only_rationale": null } ] }, { "id": "dep-soc-layer-evidence-discrimination", "name": "Evidence, discrimination and refutation", "description": "The basis on which a socio-operational dependency may be declared, how it is graded and attributed, the four discrimination tests it must survive, and how a refuted assertion is dispositioned without deletion.", "source_refs": [ "SRC-001", "SRC-041", "SRC-040", "SRC-007" ], "findings": [ { "id": "dep-soc-finding-evidence-false-positive", "name": "Evidence basis, discrimination tests and false-positive disposition", "description": "Every declared dependency records its basis (modelled artefact, written agreement, cited legal act, interview, observed telemetry, statistical association), an evidence grade, an asserting agent possibly acting on behalf of another, and an assertion time held separately from the observation time. It also records the outcomes of four discrimination tests: ownership is not dependency, sequence is not causation, correlation is not a declared dependency, and obligation is not reliance. Assertions supported only by association are downgraded to candidate rather than published. Refutation is a disposition on the assertion, retained rather than deleted. This model records the disposition and emits attribution entries; the enforcement, risk-scoring and audit-trail engines that consume them are owned elsewhere.", "source_refs": [ "SRC-001", "SRC-041", "SRC-033", "SRC-034", "SRC-007", "SRC-040" ], "questions": [ { "id": "dep-soc-q-evidence-basis", "text": "What is the basis of this assertion, and what evidence grade does that basis carry?", "kind": "evidence", "answer_data": [ "Evidence basis codes", "Evidence grade code and grading rule version", "References to the cited items with their versions" ] }, { "id": "dep-soc-q-evidence-attribution", "text": "Who asserted the dependency, on whose behalf, and at what assertion time as distinct from the observation time?", "kind": "provenance", "answer_data": [ "Asserter reference and delegating party where applicable", "Assertion time in RFC 3339 with offset", "Observation or ingestion time where it differs" ] }, { "id": "dep-soc-q-evidence-tests", "text": "Which discrimination tests were run for ownership, sequence, correlation and obligation, and what were their outcomes?", "kind": "validation", "answer_data": [ "Outcome per test with reason", "Tester reference and execution time", "Resulting status of declared, candidate or refuted" ] }, { "id": "dep-soc-q-evidence-falsifier", "text": "What observation would falsify this dependency, and has that check actually been performed?", "kind": "quality", "answer_data": [ "Falsification criterion statement", "Check performed flag and result", "Reason where the check is impracticable" ] }, { "id": "dep-soc-q-evidence-review-cycle", "text": "What review interval or trigger applies, and how is a refuted assertion dispositioned without deleting it?", "kind": "lifecycle", "answer_data": [ "Review interval or trigger list", "Disposition code and reason", "Supersession reference where a replacement assertion exists" ] } ], "data_elements": [ { "id": "dep-soc-de-evidence-basis-code", "name": "Evidence basis code", "description": "Coded basis of the assertion: modelled artefact, written agreement, cited legal act, interview, observed telemetry, or statistical association.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001", "SRC-040" ] }, { "id": "dep-soc-de-evidence-grade-code", "name": "Evidence grade code", "description": "Grade assigned to the strongest supporting basis under the profile's grading rule.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-040", "SRC-038" ] }, { "id": "dep-soc-de-asserter-ref", "name": "Asserter reference", "description": "Agent that made the assertion, with any delegating party recorded separately.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001" ] }, { "id": "dep-soc-de-assertion-time", "name": "Assertion time", "description": "Instant at which the assertion was made, in RFC 3339 with seconds and an explicit offset or Z.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-007" ] }, { "id": "dep-soc-de-observation-time", "name": "Observation time", "description": "Instant at which the underlying condition was observed or the record ingested, recorded whenever it differs from the assertion time.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-001" ] }, { "id": "dep-soc-de-discrimination-outcome-set", "name": "Discrimination outcome set", "description": "Structured outcomes of the ownership, sequence, correlation and obligation tests, each with reason and tester.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-041", "SRC-033", "SRC-034", "SRC-001" ] }, { "id": "dep-soc-de-disposition-code", "name": "Disposition code", "description": "Current disposition of the assertion: declared, candidate, withdrawn, refuted, expired, or superseded.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-040", "SRC-035" ] } ], "artifacts": [ { "id": "dep-soc-artifact-evidence-pack", "name": "Dependency declaration evidence pack", "description": "The compiled set of references and test outcomes supporting one declared dependency at one review point: cited artefacts with versions, discrimination-test results, falsification criterion and check result, asserter attribution, and the resulting disposition. It is a compiled record for review, not an audit trail; audit-trail storage, immutability and review remain with the adopting Dimension's audit model.", "media_or_form": [ "structured evidence record", "reference bundle with citations", "human-readable review note" ], "serial": true, "identity_strategy": "Keyed by the assertion identifier from the authoritative master system holding the dependency record, plus a monotonic review sequence number per assertion. Where no master system governs the assertion, a Dimension-assigned ULID is used and marked Dimension-local. The review instant is metadata; it never serves as the identifier.", "source_refs": [ "SRC-001", "SRC-040", "SRC-007" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "dep-cond-declared-condition", "name": "Declared Dependency Condition", "description": "Everything an agent must know to author or read one dependency condition as declared: what it is, which way it points, how strong it is, when it applies, what may satisfy it, and what it forbids.", "rationale": "Every authoritative dependency vocabulary examined separates the act of declaring a relationship from the act of satisfying it: SPDX models a relationship as its own element with a type, completeness and lifecycle scope; TOSCA requirements are declared on a node and fulfilled later by a processor; Debian and RPM declare graded, guarded, alternative and negative relations in package metadata that dpkg or the depsolver later interprets. Grouping the declaration surface into one bundle keeps the mixin usable without any resolver present.", "source_refs": [ "SRC-018", "SRC-019", "SRC-023", "SRC-047", "SRC-022" ], "layers": [ { "id": "dep-cond-declaration-core", "name": "Condition Core: Identity, Direction, Type and Scope", "description": "The header of a dependency condition: its own identifier, the canonical dependent-to-prerequisite orientation, the endpoints or selectors it binds, its typed kind, and the lifecycle phase in which it applies.", "source_refs": [ "SRC-018", "SRC-019", "SRC-046", "SRC-022" ], "findings": [ { "id": "dep-cond-core-declaration", "name": "Condition identity, canonical direction, endpoints, typed kind and lifecycle scope", "description": "A dependency condition is an addressable assertion in its own right, not a property of either endpoint. Its source endpoint is always the dependent and its target is always the prerequisite, matching the SPDX from-to orientation and the CycloneDX ref-to-dependsOn orientation. Some vocabularies declare from the prerequisite side (Debian Enhances, RPM Supplements and Enhances) or use inverse relationship names, so a recorded normalization step is required before the condition can be read in canonical form. The typed kind additionally carries provisioning meaning that must not be confused with strength: SPDX hasProvidedDependency marks a dependency assumed to be provided rather than distributed, and static versus dynamic linkage is a typing distinction, not a strength distinction. The lifecycle scope (build, design, development, runtime, test, other) bounds where the condition applies at all, and a scope-bounded condition is not an unconditional edge.", "source_refs": [ "SRC-018", "SRC-019", "SRC-046", "SRC-023", "SRC-047", "SRC-022" ], "questions": [ { "id": "dep-cond-q-core-identity", "text": "What stable identifier addresses this dependency condition itself, independently of the two endpoints it connects?", "kind": "identity", "answer_data": [ "Authoritative master-system condition identifier and its issuing system", "Governed IRI or namespaced key where the Dimension publishes one", "UUID or ULID assigned by the adopting Dimension as last resort", "Identifier scheme name and uniqueness scope" ] }, { "id": "dep-cond-q-core-direction", "text": "Which endpoint is the dependent and which is the prerequisite under the canonical dependent-to-prerequisite direction?", "kind": "relationship", "answer_data": [ "Dependent endpoint reference", "Prerequisite endpoint reference or abstract target selector", "Direction marker asserting canonical orientation", "Whether the pair was swapped during normalization" ] }, { "id": "dep-cond-q-core-normalization", "text": "Was the condition originally expressed in a reverse, prerequisite-side or inverse-named form, and what normalization was applied?", "kind": "provenance", "answer_data": [ "Native field or relationship term as authored, for example Enhances, Supplements or an inverse relationship name", "Source vocabulary and version", "Normalization rule identifier and crosswalk profile version", "Actor or process that performed the normalization and when" ] }, { "id": "dep-cond-q-core-kind", "text": "Which typed dependency kind classifies this condition, and does that kind carry provisioning or linkage meaning that must not be read as strength?", "kind": "classification", "answer_data": [ "Neutral typed-kind code", "Provisioning mode: bundled, assumed provided externally, or satisfied by a virtual or abstract target", "Linkage mode where applicable, for example static or dynamic", "Explicit flag that the kind does not encode obligation level" ] }, { "id": "dep-cond-q-core-scope", "text": "In which lifecycle phases does this condition apply, and is it inapplicable outside them?", "kind": "lifecycle", "answer_data": [ "Lifecycle scope codes such as build, design, development, runtime, test or other", "Whether the scope list is exhaustive or open", "Statement that outside scope the condition is inapplicable rather than satisfied", "Source vocabulary term that supplied the scope" ] } ], "data_elements": [ { "id": "dep-cond-de-core-id", "name": "Condition identifier", "description": "Stable identifier for the dependency condition as a first-class assertion, following the model's identity priority.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-018", "SRC-046" ] }, { "id": "dep-cond-de-core-dependent", "name": "Dependent endpoint reference", "description": "Reference to the host subject that carries the dependency; always the source of the canonical direction.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-018", "SRC-046", "SRC-022" ] }, { "id": "dep-cond-de-core-target", "name": "Prerequisite target specification", "description": "Concrete reference to the prerequisite, or an abstract selector such as a capability type, node filter, virtual name or label expression when the target is unresolved.", "value_kind": "object", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-023", "SRC-051", "SRC-022" ] }, { "id": "dep-cond-de-core-kind", "name": "Typed dependency kind", "description": "Neutral code for the kind of dependency asserted, distinct from obligation level and from ordering.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-018", "SRC-048" ] }, { "id": "dep-cond-de-core-provisioning", "name": "Provisioning mode", "description": "Whether the prerequisite is bundled with the dependent, assumed to be provided by the environment, or satisfied through a virtual or abstract name.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-018", "SRC-023" ] }, { "id": "dep-cond-de-core-scope", "name": "Lifecycle scope", "description": "Phase or phases in which the condition applies; outside these the condition is inapplicable rather than satisfied or violated.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-019", "SRC-023" ] }, { "id": "dep-cond-de-core-normalization", "name": "Direction normalization record", "description": "Native term, source vocabulary, crosswalk profile version and actor for any transformation applied to reach canonical direction.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-023", "SRC-047" ] }, { "id": "dep-cond-de-core-resolution-state", "name": "Endpoint resolution state", "description": "Whether the prerequisite target is resolved to a concrete entity, expressed only as a selector, or left deliberately dangling for later fulfilment by an external processor.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-022" ] } ], "artifacts": [ { "id": "dep-cond-type-crosswalk-profile", "name": "Dependency type and direction crosswalk profile", "description": "A governed, versioned mapping between the model's neutral typed-kind and direction vocabulary and each adopted external vocabulary, recording for every term whether the mapping is exact, broader, narrower or unmapped, and which source terms are prerequisite-side declarations requiring inversion.", "media_or_form": [ "versioned mapping table", "machine-readable crosswalk document", "human-readable profile note" ], "serial": true, "identity_strategy": "Authoritative master-system profile identifier from the system of record where one exists; otherwise a governed IRI in the adopting Dimension's namespace; otherwise a UUID or ULID assigned at issue. The profile version is a separate ordered attribute and the publication date is never used as the identifier.", "source_refs": [ "SRC-018", "SRC-023", "SRC-047", "SRC-022" ] } ], "inline_only_rationale": null } ] }, { "id": "dep-cond-strength-and-order", "name": "Strength, Obligation and Ordering", "description": "The two independent axes that authoritative vocabularies keep separate: how binding the condition is, and whether it also constrains sequence and prerequisite state at a stage boundary.", "source_refs": [ "SRC-023", "SRC-048", "SRC-051", "SRC-052" ], "findings": [ { "id": "dep-cond-strength-grade", "name": "Obligation level, optionality encoding and preference weight", "description": "Strength is expressed in at least three incompatible ways across authorities: as a distinct relationship type (SPDX dependsOn versus hasOptionalDependency), as a distinct field with graded meaning (Debian Pre-Depends, Depends, Recommends, Suggests; RPM Requires, Recommends, Suggests), and as a cardinality lower bound of zero (TOSCA count range). Kubernetes adds a fourth encoding in which hard rules block the operation and soft rules carry a weight from 1 to 100 that is summed during scoring. RFC 2119 supplies a domain-neutral three-level scale in which SHOULD explicitly admits justified departure. The model therefore records one normalized obligation level plus the native encoding, and refuses to assert a single total order across scales, because an ordinal field grade and a cardinal scheduling weight are not commensurable.", "source_refs": [ "SRC-018", "SRC-023", "SRC-047", "SRC-051", "SRC-022", "SRC-052" ], "questions": [ { "id": "dep-cond-q-strength-level", "text": "What normalized obligation level does this condition carry: absolute requirement, recommended, optional or informational?", "kind": "requirement", "answer_data": [ "Normalized obligation-level code", "Native term and source vocabulary", "Whether the level is an absolute requirement or admits justified departure", "Reference to the strength scale profile version used" ] }, { "id": "dep-cond-q-strength-encoding", "text": "Is optionality encoded as a separate relationship type, a separate field name, or a cardinality lower bound of zero?", "kind": "classification", "answer_data": [ "Optionality encoding code", "Cardinality lower and upper bounds where cardinality is the encoding", "Relationship type or field name where typing is the encoding", "Note on whether the encodings coexist in the source record" ] }, { "id": "dep-cond-q-strength-weight", "text": "If the condition is soft, what preference weight or rank is declared and on what scale is it defined?", "kind": "measurement", "answer_data": [ "Weight or rank value", "Scale identifier, bounds and whether values are additive across rules", "Whether the value is ordinal or cardinal", "Explicit statement that weights are not comparable across scales" ] }, { "id": "dep-cond-q-strength-consequence", "text": "What non-binding statement of consequence for the dependent accompanies the condition in its source vocabulary?", "kind": "decision", "answer_data": [ "Declared consequence note as authored, for example that the operation still proceeds when unmet", "Whether the note is normative in the source vocabulary or descriptive", "Explicit disclaimer that enforcement of any consequence is external", "Source reference for the consequence wording" ] }, { "id": "dep-cond-q-strength-loss", "text": "Which strength distinctions are lost when this condition is projected into a target vocabulary that has no strength axis?", "kind": "interoperability", "answer_data": [ "Target vocabulary and version", "Lossiness classification: exact, weakened, strengthened or dropped", "Compensating annotation carried alongside the projection", "Refusal marker where projection would misrepresent an optional condition as mandatory" ] } ], "data_elements": [ { "id": "dep-cond-de-strength-level", "name": "Obligation level", "description": "Normalized level of bindingness for the condition, from absolute requirement through recommended and optional to informational.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-023", "SRC-052" ] }, { "id": "dep-cond-de-strength-encoding", "name": "Optionality encoding", "description": "How the source expressed optionality: relationship typing, distinct field, cardinality lower bound of zero, or scheduler-style required-versus-preferred flag.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-018", "SRC-051", "SRC-022" ] }, { "id": "dep-cond-de-strength-weight", "name": "Preference weight", "description": "Declared numeric preference for a soft condition, always accompanied by its scale identifier and bounds.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-051" ] }, { "id": "dep-cond-de-strength-scale", "name": "Strength scale reference", "description": "Reference to the strength scale profile version that defines the level vocabulary and the weight scale used by this condition.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-052" ] }, { "id": "dep-cond-de-strength-consequence", "name": "Declared unmet-consequence note", "description": "Descriptive statement carried from the source vocabulary about what is expected to happen when the condition is unmet; never an enforcement instruction.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-023", "SRC-048", "SRC-051" ] } ], "artifacts": [ { "id": "dep-cond-strength-scale-profile", "name": "Strength and obligation scale profile", "description": "A governed, versioned definition of the model's obligation levels and any numeric preference scales, together with the crosswalk to external strength encodings and an explicit non-commensurability statement listing which pairs of scales must not be ordered against each other.", "media_or_form": [ "versioned scale definition", "machine-readable crosswalk document", "human-readable profile note" ], "serial": true, "identity_strategy": "Authoritative master-system profile identifier where the system of record issues one; otherwise a governed IRI in the adopting Dimension's namespace; otherwise a UUID or ULID assigned at issue, with the profile version held as an ordered attribute rather than as a date-derived key.", "source_refs": [ "SRC-023", "SRC-051", "SRC-052" ] } ], "inline_only_rationale": null }, { "id": "dep-cond-ordering-mode", "name": "Ordered prerequisites and the ordering-versus-existence distinction", "description": "Ordering is a separate axis from existence. The systemd unit model states that ordering settings are independent of and orthogonal to requirement dependencies, so a unit can require another without ordering against it, and can order against a unit it does not require. Debian Pre-Depends instead couples the two, requiring the prerequisite to be fully installed before the dependent's installation starts, with staged acceptance criteria that differ between unpack and configure and an explicit prohibition on circular pre-dependencies. Requisite adds a further distinction: the prerequisite must already be in the required state and will not be brought into it as part of satisfying the condition. The model therefore records the ordering assertion, the required prerequisite state, the stage boundary being gated, and whether pre-existence is demanded, without computing any sequence.", "source_refs": [ "SRC-018", "SRC-023", "SRC-048" ], "questions": [ { "id": "dep-cond-q-order-axis", "text": "Does this condition assert ordering, existence, or both as separately recorded assertions?", "kind": "relationship", "answer_data": [ "Ordering assertion present or absent", "Existence requirement present or absent", "Whether the source vocabulary couples the two axes", "Separate identifiers for the ordering and existence assertions where both are present" ] }, { "id": "dep-cond-q-order-state", "text": "Which state must the prerequisite have reached before the dependent may proceed past the gated stage?", "kind": "state", "answer_data": [ "Required prerequisite state code, for example present, unpacked, configured, active or complete", "Stage boundary of the dependent that the condition gates", "Whether acceptance criteria differ between stages", "Source vocabulary term supplying the state" ] }, { "id": "dep-cond-q-order-preexistence", "text": "Must the prerequisite already be in the required state, or may it be brought into that state as part of satisfying the condition?", "kind": "constraint", "answer_data": [ "Pre-existence mode code", "Whether co-activation is permitted", "Declared failure mode when pre-existence is absent", "Native term such as Requisite or Pre-Depends" ] }, { "id": "dep-cond-q-order-cycle", "text": "Are circular ordered prerequisites permitted for this condition, and how is a declared cycle recorded rather than resolved?", "kind": "validation", "answer_data": [ "Cycle permission flag as declared by the source vocabulary", "Reference to any externally produced cycle report", "Marker that cycle detection and breaking are outside this model", "Provenance of the party that asserted the cycle" ] } ], "data_elements": [ { "id": "dep-cond-de-order-assertion", "name": "Ordering assertion", "description": "Whether the condition constrains sequence, recorded separately from any existence requirement on the same pair of endpoints.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-048" ] }, { "id": "dep-cond-de-order-required-state", "name": "Required prerequisite state", "description": "State the prerequisite must have reached, expressed in the host domain's state vocabulary.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-023", "SRC-048" ] }, { "id": "dep-cond-de-order-gate-stage", "name": "Gated stage boundary", "description": "The stage of the dependent whose start or completion the condition gates.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-023" ] }, { "id": "dep-cond-de-order-preexistence", "name": "Pre-existence mode", "description": "Whether the prerequisite must already be in the required state or may be brought into it as part of satisfying the condition.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-048" ] }, { "id": "dep-cond-de-order-cycle-flag", "name": "Cycle permission flag", "description": "Declared statement about whether circular ordered prerequisites are admissible for this condition type.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-023" ] } ], "artifacts": [], "inline_only_rationale": "Ordering semantics are attributes of a single condition declaration carried inside the host record; there is no separable, independently addressable document here. Any sequence plan, topological order or execution schedule that would be a genuine artifact is produced by a resolver, scheduler or init system that owns execution, so materialising one in this model would import operational semantics that the boundary excludes." } ] }, { "id": "dep-cond-condition-expression", "name": "Condition Expression: Alternatives, Guards, Predicates and Exclusions", "description": "The logical form of the condition: what set of targets may satisfy it, under what applicability guard it holds at all, against which comparison predicate or range, and what it forbids.", "source_refs": [ "SRC-023", "SRC-047", "SRC-049", "SRC-051", "SRC-053" ], "findings": [ { "id": "dep-cond-alternative-set", "name": "Alternative sets, cardinality bounds and n-of-m satisfaction thresholds", "description": "A single condition may be satisfiable by any of several targets. Debian expresses this with the pipe operator and treats the listed order as meaningful, with autobuilders discarding architecture-mismatched options and taking the first remaining name. RPM expresses it with or, and adds with, which requires all operands to be satisfied by the same package, and without, which requires a package satisfying the first operand but not the second. TOSCA expresses multiplicity as a count range, so the satisfaction threshold is a bounded interval rather than a boolean. Kubernetes allows several soft rules to contribute weights independently, which is a scored rather than a thresholded form. The model records the member set, the threshold, whether members must bind to the same target, and whether any preference order is normative or conventional.", "source_refs": [ "SRC-023", "SRC-047", "SRC-051", "SRC-022" ], "questions": [ { "id": "dep-cond-q-alt-members", "text": "Which candidate targets form the alternative set able to satisfy this single condition?", "kind": "composition", "answer_data": [ "Ordered list of alternative member specifications", "Whether each member is a concrete reference or a selector", "Whether the set is closed or extensible by later declarations", "Source expression from which the set was parsed" ] }, { "id": "dep-cond-q-alt-threshold", "text": "How many members must hold for the condition to count as satisfied, and is the threshold a minimum, an exact count or a bounded range?", "kind": "constraint", "answer_data": [ "Threshold lower bound, upper bound and exactness", "Whether a lower bound of zero makes the whole condition optional", "Whether unbounded upper multiplicity is permitted", "Native cardinality expression" ] }, { "id": "dep-cond-q-alt-preference", "text": "Is a preference order declared among alternatives, and is that order normative or merely conventional?", "kind": "decision", "answer_data": [ "Preference rank per member", "Normativity classification of the order", "Known tool behaviour that relies on the order, recorded as observation not as rule", "Explicit note that selection among alternatives is performed externally" ] }, { "id": "dep-cond-q-alt-binding", "text": "Must the satisfying members be provided by one and the same target, or may satisfaction be spread across several targets?", "kind": "constraint", "answer_data": [ "Same-target binding flag", "Scope over which the binding applies", "Native operator that expressed the binding", "Behaviour when the binding cannot be represented in a projection" ] } ], "data_elements": [ { "id": "dep-cond-de-alt-members", "name": "Alternative member set", "description": "Ordered collection of candidate target specifications any of which may satisfy the condition.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-023", "SRC-047" ] }, { "id": "dep-cond-de-alt-threshold", "name": "Satisfaction threshold", "description": "Lower bound, upper bound and exactness governing how many members must hold for the condition to be satisfied.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-022" ] }, { "id": "dep-cond-de-alt-rank", "name": "Alternative preference rank", "description": "Declared ordinal preference for a member, together with whether the order is normative or conventional.", "value_kind": "number", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-023" ] }, { "id": "dep-cond-de-alt-same-target", "name": "Same-target binding flag", "description": "Whether all satisfying operands must be met by a single target rather than by a combination.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-047" ] } ], "artifacts": [], "inline_only_rationale": "An alternative set is an internal structure of one condition expression and has no life outside the condition that carries it; it is neither separately addressable nor separately versioned. Externalising it would create a shadow catalogue of candidate targets, which belongs to the host subject and target-registry models rather than to this mixin." }, { "id": "dep-cond-guard-applicability", "name": "Guards, applicability predicates and the inapplicable-versus-failed distinction", "description": "A guarded condition holds only when its guard is true, and a false guard makes the condition inapplicable rather than unsatisfied. RPM makes this explicit with if, if-else, unless and unless-else, and constrains their combination so that if cannot appear with or and unless cannot appear with and. Debian restricts relationships by architecture in square brackets, with negation, and by build profile in angle brackets interpreted as disjunctive normal form. systemd separates Condition directives, where an unmet condition causes the unit start to be mostly silently skipped without entering a failed state, from Assert directives, where failure is an error. Kubernetes scopes matching to scheduling and ignores it during execution, so guard evaluation timing is itself part of the declaration. The critical compositional rule is that a guarded condition must never be flattened into an unconditional edge in any projection.", "source_refs": [ "SRC-023", "SRC-047", "SRC-048", "SRC-051" ], "questions": [ { "id": "dep-cond-q-guard-predicate", "text": "Under what declared guard predicate does this condition become applicable at all?", "kind": "constraint", "answer_data": [ "Guard expression in the model's neutral form", "Variables, facts or environment attributes the guard references", "Native guard syntax and vocabulary", "Whether the guard is a positive applicability test or a negative exclusion test" ] }, { "id": "dep-cond-q-guard-outcome", "text": "When the guard is false, is the condition inapplicable and silently skipped, or is falsity itself a failure?", "kind": "exception", "answer_data": [ "Unmet-guard outcome code: not-applicable or failure", "Native directive family that determined the outcome", "Whether the outcome differs by lifecycle scope", "Statement that acting on the outcome is external to this model" ] }, { "id": "dep-cond-q-guard-timing", "text": "Is the guard tied to a single stage boundary or continuously applicable, and does a later change reopen applicability?", "kind": "temporal", "answer_data": [ "Guard evaluation scope: at a stage boundary or continuous", "Whether later changes are ignored after the boundary", "Any declared revalidation expectation, marked as expectation not as trigger", "Observation and event timestamps of any recorded guard state" ] }, { "id": "dep-cond-q-guard-projection", "text": "Can the guard survive projection into the target vocabulary, and what must be refused if it cannot?", "kind": "interoperability", "answer_data": [ "Target vocabulary guard capability assessment", "Flattening prohibition flag for this condition", "Compensating annotation or explicit omission record", "Grammar restrictions in the target, such as operators that may not be combined" ] } ], "data_elements": [ { "id": "dep-cond-de-guard-expression", "name": "Guard expression", "description": "Neutral representation of the applicability predicate that gates the condition, retaining the operator structure of the source.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-023", "SRC-047" ] }, { "id": "dep-cond-de-guard-refs", "name": "Guard variable references", "description": "Facts, attributes or environment dimensions the guard depends on, such as architecture, build profile, platform label or feature flag.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-023", "SRC-051" ] }, { "id": "dep-cond-de-guard-outcome", "name": "Unmet-guard outcome", "description": "Whether a false guard renders the condition not applicable or constitutes a declared failure.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-048" ] }, { "id": "dep-cond-de-guard-timing", "name": "Guard evaluation scope", "description": "Whether the guard is bound to a stage boundary or is continuously applicable.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-051" ] }, { "id": "dep-cond-de-guard-flatten-flag", "name": "Unconditional projection prohibition", "description": "Flag, defaulting to prohibited, that forbids emitting this guarded condition as an unconditional edge in any projection or export.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-046", "SRC-047" ] } ], "artifacts": [], "inline_only_rationale": "A guard is a predicate belonging to exactly one condition and is meaningless when detached from it; keeping it inline is what prevents the guard from being dropped and the condition from silently becoming unconditional. Any evaluated guard outcome is produced by an external evaluator, so no evaluation artifact is claimed here." }, { "id": "dep-cond-range-predicate", "name": "Comparison predicates, compatibility ranges and quantitative thresholds", "description": "Conditions are frequently expressed against a value rather than a bare existence test. Debian defines the version relations strictly earlier, earlier or equal, exactly equal, later or equal and strictly later. The OSV schema shows that a range is only interpretable under a declared ordering scheme: semantic-version precedence, uninterpreted ecosystem strings that need an explicit enumerated version list, or a commit graph that must be consulted; and it fixes the half-open reading in which the fixing endpoint is excluded. Kubernetes supplies set and existence operators and warns that its greater-than and less-than comparisons are lexicographic on label values. TOSCA constrains target selection through node filters over property constraints. The model therefore records the operator, the operands, the endpoint inclusivity, the ordering scheme reference and, for quantitative thresholds, the unit and measurement basis; it never performs the comparison.", "source_refs": [ "SRC-023", "SRC-049", "SRC-051", "SRC-022", "SRC-053" ], "questions": [ { "id": "dep-cond-q-range-operator", "text": "Which comparison or membership operator and which operands define the acceptable prerequisite values?", "kind": "constraint", "answer_data": [ "Operator code covering ordering, equality, set membership and existence", "Operand values or value sets", "Property or attribute path the operator applies to", "Native operator token and vocabulary" ] }, { "id": "dep-cond-q-range-scheme", "text": "Which ordering or comparison scheme makes the operands comparable, and is that ordering total?", "kind": "measurement", "answer_data": [ "Ordering scheme reference, for example a semantic-version precedence rule, an ecosystem-specific ordering or a commit graph", "Whether the ordering is total, partial or undefined", "Whether lexicographic comparison is being used on non-lexicographic values", "External resource needed to evaluate the ordering" ] }, { "id": "dep-cond-q-range-endpoints", "text": "Are the interval endpoints inclusive or exclusive, and is the range half-open?", "kind": "definition", "answer_data": [ "Lower endpoint value and inclusivity", "Upper endpoint value and inclusivity", "Explicit half-open marker where the upper endpoint is excluded", "Open-ended marker where no upper endpoint is declared" ] }, { "id": "dep-cond-q-range-quantity", "text": "For a quantitative threshold, what unit, precision and measurement basis apply to the operand?", "kind": "quality", "answer_data": [ "Unit of measure and unit system", "Precision or tolerance", "Measurement basis such as nominal, minimum guaranteed or observed", "Whether the threshold is a capacity, a rate or a count" ] }, { "id": "dep-cond-q-range-enumeration", "text": "When the ordering scheme is undefined for the operands, what enumerated value set stands in for the range?", "kind": "interoperability", "answer_data": [ "Explicit enumerated value list", "Completeness statement for the enumeration", "Reason the range could not be expressed as an interval", "Reference to the registry that supplies admissible values" ] } ], "data_elements": [ { "id": "dep-cond-de-range-operator", "name": "Predicate operator", "description": "Comparison, membership or existence operator applied to the prerequisite attribute.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-023", "SRC-051" ] }, { "id": "dep-cond-de-range-endpoints", "name": "Range endpoints", "description": "Lower and upper operands with explicit inclusivity, including the half-open form in which the upper endpoint is excluded.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-053" ] }, { "id": "dep-cond-de-range-scheme", "name": "Ordering scheme reference", "description": "Reference to the externally owned scheme under which operands are comparable; without it a range has no meaning.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-053" ] }, { "id": "dep-cond-de-range-enumeration", "name": "Enumerated admissible values", "description": "Explicit list of acceptable values used where the ordering scheme is uninterpreted or unavailable.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-053" ] }, { "id": "dep-cond-de-range-quantity", "name": "Threshold quantity", "description": "Numeric threshold with unit, precision and measurement basis for non-version quantitative conditions.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-051", "SRC-022" ] } ], "artifacts": [], "inline_only_rationale": "Predicates and range endpoints are operands of one condition and are carried as reference data alongside a pointer to an externally governed ordering scheme. The ordering scheme itself, and any evaluation of the predicate, are owned by the version-identity model and by the evaluator respectively, so this finding holds only inline operands and references." }, { "id": "dep-cond-exclusion-conflict", "name": "Negative conditions and declared incompatibilities", "description": "Not all dependency conditions are positive. Debian defines Conflicts, which prevents two packages from being unpacked simultaneously, and Breaks, which prevents configuration of a broken package while the breaking package is unpacked, alongside Replaces. RPM permits boolean expressions in Conflicts and provides unless and without as negative forms, and states that Provides may not carry boolean expressions. systemd defines Conflicts as a negative requirement in which starting one unit stops the other, and Kubernetes uses NotIn and DoesNotExist to express anti-affinity. A negative condition is therefore a first-class declaration with the same identity, direction, scope and strength machinery as a positive one, and two declarations can be mutually contradictory as authored. This finding records exclusions and asserted contradictions; it does not detect, rank or resolve them.", "source_refs": [ "SRC-023", "SRC-047", "SRC-048", "SRC-051" ], "questions": [ { "id": "dep-cond-q-neg-polarity", "text": "Is this condition positive, requiring presence, or negative, requiring absence or non-coexistence?", "kind": "classification", "answer_data": [ "Polarity code", "Negative subtype such as must-not-be-present, must-not-coexist-at-a-stage, or must-not-match-attribute", "Scope over which the exclusion applies", "Native term and vocabulary" ] }, { "id": "dep-cond-q-neg-stage", "text": "At which stage or state does the exclusion bite, and does it forbid coexistence or only a particular transition?", "kind": "state", "answer_data": [ "Stage or state at which the exclusion applies", "Whether coexistence is forbidden outright or only concurrent transition", "Declared effect on the other party, recorded descriptively", "Whether the exclusion is symmetric or one-directional" ] }, { "id": "dep-cond-q-neg-contradiction", "text": "Which other declared conditions are asserted to be mutually contradictory with this one, and who asserted that?", "kind": "validation", "answer_data": [ "References to the conflicting condition identifiers", "Nature of the contradiction, for example disjoint ranges or presence versus absence", "Asserting actor, method and timestamp", "Reference to any externally produced consistency report" ] }, { "id": "dep-cond-q-neg-unsatisfiable", "text": "Is the declared condition set recorded as unsatisfiable as authored, without any attempt to resolve it?", "kind": "evidence", "answer_data": [ "Unsatisfiability marker with scope", "Evidence reference supporting the marker", "Explicit statement that resolution, relaxation and precedence are outside this model", "Confidence or method note from the asserting party" ] } ], "data_elements": [ { "id": "dep-cond-de-neg-polarity", "name": "Condition polarity", "description": "Whether the condition requires presence or requires absence or non-coexistence.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-023", "SRC-048" ] }, { "id": "dep-cond-de-neg-subtype", "name": "Exclusion subtype", "description": "The specific negative form asserted, such as non-coexistence at a stage, attribute anti-match, or supersession.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-023", "SRC-051" ] }, { "id": "dep-cond-de-neg-symmetry", "name": "Exclusion symmetry", "description": "Whether the exclusion is declared to apply in both directions or only from the dependent to the prerequisite.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-048" ] }, { "id": "dep-cond-de-neg-contradiction", "name": "Asserted contradiction reference", "description": "Reference to another condition asserted to contradict this one, with the asserting actor, method and time.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-023", "SRC-049" ] } ], "artifacts": [], "inline_only_rationale": "An exclusion is a condition declaration carried on the host record using the same inline structure as a positive condition, and an asserted contradiction is a typed cross-reference between two such declarations. A consistency or solver report that would justify an artifact is produced and retained by the external checker, and claiming it here would import evaluation and audit semantics the boundary excludes." } ] } ] }, { "id": "dep-cond-state-and-epistemics", "name": "Satisfaction State and Epistemic Disclosure", "description": "How a declared condition relates to what is actually known: recorded satisfaction, violation, inapplicability, unknown state and deviation, and the completeness of the declaration set as a whole.", "rationale": "Every authority examined insists on this separation. SHACL keeps a declarative shapes graph apart from a validation report produced by an external processor and defines conformance as the absence of results with no failure reported. CycloneDX warns that absence from the dependency graph must be treated as opaque rather than as evidence of having no dependencies. SPDX provides complete, incomplete and noAssertion as explicit completeness statements. OWL 2 states the open-world assumption directly. Modelling declaration and knowledge in one undifferentiated structure would convert missing information into false information.", "source_refs": [ "SRC-014", "SRC-046", "SRC-049", "SRC-050" ], "layers": [ { "id": "dep-cond-observed-state", "name": "Observed Satisfaction, Violation and Deviation", "description": "The per-condition record of what is known about satisfaction at a point in time, including inapplicability, unknown state and any recorded deviation, all carried as references to externally owned results and decisions.", "source_refs": [ "SRC-048", "SRC-049", "SRC-052" ], "findings": [ { "id": "dep-cond-satisfaction-record", "name": "Declared condition versus recorded satisfaction, violation, inapplicability, unknown state and deviation", "description": "The declared condition and any statement about its satisfaction are different objects with different provenance and different time bases. Following the SHACL separation, this model carries a status snapshot and a reference to the externally produced result, never the evaluation itself: conformance in SHACL is defined as an empty result set with no reported failure, and the report is produced by a processor. The status vocabulary must distinguish satisfied, violated, not-applicable (the guard was false, which systemd treats as a silent skip rather than a failure) and unknown, since silence is not satisfaction. Severity is a declared qualifier of a result, as in the SHACL Violation, Warning and Info scale, and is not the same as the condition's obligation level. A deviation, whether a waiver, a concession or a declared deactivation in the sense of a shape that is switched off while remaining defined, is recorded as a reference to a decision owned elsewhere, together with its subject binding and declared validity window, on the requirement-level principle that departure from a recommended item demands that its implications be understood and weighed.", "source_refs": [ "SRC-048", "SRC-049", "SRC-052" ], "questions": [ { "id": "dep-cond-q-state-status", "text": "What is the last recorded satisfaction status of this condition, and does the vocabulary separate unknown from not-applicable?", "kind": "state", "answer_data": [ "Status code: satisfied, violated, not-applicable, unknown or indeterminate", "Whether not-applicable arises from a false guard or from being out of lifecycle scope", "Whether unknown means not yet observed or not observable", "Severity qualifier attached to the result, distinct from obligation level" ] }, { "id": "dep-cond-q-state-source", "text": "Which external evaluator produced the result, and where is the full result retained?", "kind": "provenance", "answer_data": [ "Evaluator or processor identity and version", "Reference to the externally retained result or report", "Evaluation context, input scope and any configuration reference", "Explicit statement that evaluation logic, report structure and report retention are owned by the evaluator" ] }, { "id": "dep-cond-q-state-time", "text": "What are the event time of the observed state change and the separate observation or ingestion time of this record?", "kind": "temporal", "answer_data": [ "Event time in RFC 3339 with seconds and explicit offset or Z", "Observation or ingestion time in the same format", "Declared validity window or staleness horizon for the snapshot", "Whether the two times were reported by different systems" ] }, { "id": "dep-cond-q-state-deviation", "text": "Is a waiver, concession or deactivation recorded against this condition, and which decision record authorises it?", "kind": "exception", "answer_data": [ "Deviation type: waiver, concession, temporary exception or declared deactivation", "Reference to the externally owned decision record", "Subject binding: which condition, which scope, which endpoints", "Declared validity window and any stated conditions of the deviation" ] }, { "id": "dep-cond-q-state-authority", "text": "Which model owns the approval, verification and retention of the deviation decision referenced here?", "kind": "authority", "answer_data": [ "Authority or decision-record model reference", "Statement that approval workflow and authority verification are not modelled here", "Local fields limited to reference, binding and validity", "Escalation or review pointer without any local enforcement rule" ] } ], "data_elements": [ { "id": "dep-cond-de-state-status", "name": "Recorded satisfaction status", "description": "Last known status of the condition drawn from a vocabulary that separates satisfied, violated, not-applicable, unknown and indeterminate.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-048", "SRC-049" ] }, { "id": "dep-cond-de-state-severity", "name": "Result severity qualifier", "description": "Declared severity attached to a result by the producing processor, recorded as a qualifier and never conflated with obligation level.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-049" ] }, { "id": "dep-cond-de-state-result-ref", "name": "External result reference", "description": "Pointer to the externally produced and externally retained evaluation or validation result, with producer identity and version.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-049" ] }, { "id": "dep-cond-de-state-event-time", "name": "State event time", "description": "RFC 3339 timestamp with seconds and explicit offset or Z for when the observed state came about at source.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-049" ] }, { "id": "dep-cond-de-state-observed-time", "name": "Observation or ingestion time", "description": "RFC 3339 timestamp with seconds and explicit offset or Z for when this model recorded the status, always distinct from the event time.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-049" ] }, { "id": "dep-cond-de-state-deviation-ref", "name": "Deviation decision reference", "description": "Reference to an externally owned waiver, concession, exception or deactivation decision that applies to this condition.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-049", "SRC-052" ] }, { "id": "dep-cond-de-state-deviation-window", "name": "Deviation validity window", "description": "Declared start and end of the deviation's applicability, expressed as RFC 3339 timestamps with explicit offsets.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-052" ] } ], "artifacts": [], "inline_only_rationale": "The only defensible local content is a status snapshot plus references: the evaluation result and the deviation decision are produced, versioned and retained by the evaluator and the authority model respectively. Declaring an artifact here would amount to owning an evaluation output or an audit trail, which the boundary explicitly assigns elsewhere, so the finding is deliberately reference-only." } ] }, { "id": "dep-cond-assertion-scope", "name": "Completeness, Open-World Assumptions and Assertion Scope", "description": "Statements about the declaration set as a whole rather than about any single condition: how exhaustive it is, over what scope, and how absence must be read.", "source_refs": [ "SRC-014", "SRC-046", "SRC-050" ], "findings": [ { "id": "dep-cond-openworld-disclosure", "name": "Completeness assertion, open-world default and the reading of absence", "description": "A set of declared conditions is not a closed world unless someone says so. SPDX makes this explicit with complete, incomplete and noAssertion, meaning the relationship is known to be exhaustive, known not to be exhaustive, or carries no claim. CycloneDX makes the operational consequence explicit: a component with no dependencies must be declared as an empty element, whereas a component absent from the graph may have unknown dependencies and should be treated as opaque rather than dependency-free. OWL 2 states the underlying epistemics, that a fact absent from a document may simply be missing but possibly true. The model therefore defaults to the open-world reading, requires an explicit empty declaration to assert that a subject genuinely has no conditions of a given kind, and treats completeness as an attributed, scoped assertion with its own provenance rather than as an inferred property.", "source_refs": [ "SRC-014", "SRC-046", "SRC-050" ], "questions": [ { "id": "dep-cond-q-open-completeness", "text": "For this subject and scope, is the declared condition set asserted to be exhaustive, non-exhaustive, or is no claim made?", "kind": "evidence", "answer_data": [ "Completeness value: complete, incomplete or no assertion", "Scope of the assertion: subject, condition kind, lifecycle phase, polarity", "Issuing actor and issue time", "Method or evidence basis for the claim" ] }, { "id": "dep-cond-q-open-absence", "text": "How must the absence of a condition be read: as no condition, as an unknown condition, or as out of scope?", "kind": "definition", "answer_data": [ "Declared reading of absence for this scope", "Explicit empty declaration where the subject genuinely has no conditions", "Default open-world statement where no explicit empty declaration exists", "Warning that absence is opaque and is not evidence of independence" ] }, { "id": "dep-cond-q-open-negation", "text": "When a negative condition is declared, is it a classical assertion of absence or an artefact of failure to find evidence?", "kind": "validation", "answer_data": [ "Negation semantics: asserted absence versus absence of evidence", "Search or discovery scope actually covered", "Confidence statement from the asserting party", "Reference to the discovery process, marked as externally owned" ] }, { "id": "dep-cond-q-open-supersession", "text": "Which earlier completeness assertion does this one supersede, and over what scope does the supersession run?", "kind": "provenance", "answer_data": [ "Reference to the superseded assertion identifier", "Scope overlap between the two assertions", "Reason for supersession", "Whether the earlier assertion remains valid for any residual scope" ] }, { "id": "dep-cond-q-open-retention", "text": "How long must a superseded completeness assertion be retained, and who owns that retention rule?", "kind": "retention", "answer_data": [ "Retention period or trigger for superseded assertions", "Owning records or retention policy of the adopting Dimension", "Whether any external consumer relies on the superseded assertion", "Disposition reference recorded on the tombstone" ] } ], "data_elements": [ { "id": "dep-cond-de-open-completeness", "name": "Completeness value", "description": "Whether the declared condition set for a scope is exhaustive, known not to be exhaustive, or carries no assertion.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-014" ] }, { "id": "dep-cond-de-open-scope", "name": "Assertion scope", "description": "The subject, condition kinds, lifecycle phases and polarities over which the completeness value is claimed.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-014", "SRC-019" ] }, { "id": "dep-cond-de-open-empty-declaration", "name": "Explicit empty declaration", "description": "Positive statement that a subject has no conditions of the stated kind and scope, required because absence alone conveys nothing.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-046" ] }, { "id": "dep-cond-de-open-negation-basis", "name": "Negation basis", "description": "Whether a declared absence is an asserted fact or merely absence of evidence within a stated discovery scope.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-050" ] }, { "id": "dep-cond-de-open-supersedes", "name": "Superseded assertion reference", "description": "Reference to a prior completeness assertion that this one replaces, with the overlapping scope.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-014" ] } ], "artifacts": [ { "id": "dep-cond-completeness-assertion", "name": "Dependency declaration completeness assertion", "description": "A scoped, attributed statement declaring whether the set of dependency conditions for a subject, condition kind and lifecycle phase is exhaustive, non-exhaustive or carries no claim, together with the issuing actor, the basis of the claim and any assertion it supersedes.", "media_or_form": [ "attributed statement record", "machine-readable assertion", "human-readable disclosure note" ], "serial": true, "identity_strategy": "Authoritative master-system assertion identifier where the issuing system of record provides one; otherwise a governed IRI in the adopting Dimension's namespace; otherwise a UUID or ULID assigned at issue. Scope, issuing actor and issue timestamp are attributes; the issue date is never used as the identifier.", "source_refs": [ "SRC-014", "SRC-046", "SRC-050" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "dep-evd-provenance-authority-bundle", "name": "Claim provenance, authority and evidentiary strength", "description": "Everything that establishes where a dependency or impact claim came from and how much weight it can carry: the epistemic mode, the registered procedure that produced it, the accountable agent and authority basis, the binding to retrievable evidence, and the declared confidence, uncertainty and applicability limits.", "rationale": "Standards that carry dependency assertions consistently separate the assertion from its warrant: CycloneDX records identity evidence with techniques, per-method confidence and occurrence locations; in-toto binds a predicate to a digest-identified subject inside a signed envelope; RFC 9334 separates Evidence producers from appraisal; PROV-O supplies attribution and derivation. Grouping these into one bundle keeps warrant metadata cohesive and keeps it out of the core edge model.", "source_refs": [ "SRC-001", "SRC-056", "SRC-057", "SRC-021", "SRC-059" ], "layers": [ { "id": "dep-evd-origin-layer", "name": "Claim origin and discovery method", "description": "How the claim was established and by which described procedure, distinguishing manifest-declared statements from static discovery, runtime observation, heuristic inference and third-party attestation.", "source_refs": [ "SRC-054", "SRC-057", "SRC-021", "SRC-020" ], "findings": [ { "id": "dep-evd-epistemic-mode", "name": "Epistemic mode and evidentiary force of a dependency claim", "description": "Classifies how a dependency or impact claim was established - declared in a manifest or by a supplier, discovered by static inspection of source or binaries, observed in a running or instrumented system, inferred by similarity or heuristic, or attested by a signed third-party statement - and fixes that each mode carries different evidentiary force. CycloneDX separates manifest-analysis from binary-analysis, instrumentation, dynamic-analysis, ast-fingerprint, hash-comparison and attestation; SPDX names DEPENDENCY_OF specifically for dependencies explicitly stated in machine-readable files; RFC 9334 separates Evidence from Endorsements; PROV separates direct-knowledge sources (hadPrimarySource) from derivations. The mode is recorded, never re-derived, and never used here to decide which of several claims is correct.", "source_refs": [ "SRC-001", "SRC-056", "SRC-057", "SRC-021", "SRC-020" ], "questions": [ { "id": "dep-evd-q-mode-assignment", "text": "Which epistemic mode established this dependency claim - declared, discovered, observed, inferred or attested?", "kind": "classification", "answer_data": [ "Epistemic mode code from the governed mode vocabulary", "Vocabulary identifier and pinned version", "Reference to the external technique or relationship term the mode was mapped from" ] }, { "id": "dep-evd-q-mode-force", "text": "What evidentiary force does the recorded mode carry, and which modes must never be silently merged into one edge claim?", "kind": "constraint", "answer_data": [ "Declared force rank or ordering statement for the mode vocabulary", "Merge-prohibition rule set (for example inferred claims may not be folded into declared claims)", "Justification text where a mode of lower force is used as sole support" ] }, { "id": "dep-evd-q-mode-multiplicity", "text": "How is an edge supported by several modes at once represented without collapsing their distinct force?", "kind": "composition", "answer_data": [ "One claim record per mode, each with its own method profile and strength", "Sibling-claim grouping reference for the same edge", "Flag marking whether modes agree, differ in scope or conflict" ] }, { "id": "dep-evd-q-mode-derivation", "text": "When the mode is inferred or restated, which prior claim or source claim was it derived from?", "kind": "provenance", "answer_data": [ "Derived-from claim references (PROV wasDerivedFrom)", "Primary-source indicator distinguishing direct knowledge from restatement", "Inference rule or similarity basis identifier" ] }, { "id": "dep-evd-q-mode-directness", "text": "Does this record assert direct knowledge of the dependency or a secondary restatement of another party's assertion?", "kind": "evidence", "answer_data": [ "Primary-source boolean (PROV hadPrimarySource semantics)", "Upstream publisher reference where the claim is a restatement", "Restatement fidelity note (verbatim, mapped, summarised)" ] } ], "data_elements": [ { "id": "dep-evd-de-mode-code", "name": "Epistemic mode code", "description": "Coded mode of establishment for the claim: declared, discovered, observed, inferred or attested.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-021", "SRC-020" ] }, { "id": "dep-evd-de-mode-vocab-version", "name": "Mode vocabulary version pin", "description": "Identifier and version of the governed vocabulary the mode code is drawn from, so historic claims remain interpretable after vocabulary change.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-021" ] }, { "id": "dep-evd-de-primary-source-flag", "name": "Primary-source indicator", "description": "Whether the asserting agent had direct knowledge of the dependency or is restating another party's claim, following PROV hadPrimarySource.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-001" ] }, { "id": "dep-evd-de-derived-from-claim", "name": "Derived-from claim reference", "description": "Reference to one or more upstream claim records this claim was derived from or restates.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "dep-evd-de-mode-rationale", "name": "Mode assignment rationale", "description": "Short free text recording why the mode was assigned when the mapping from an external technique term is not one-to-one.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-021", "SRC-020" ] } ], "artifacts": [], "inline_only_rationale": "The epistemic mode is a small set of coded attributes carried on the claim record itself, together with references to upstream claims. Every cited standard expresses it as a field on an existing assertion (a CycloneDX technique value, an SPDX relationship type, a PROV property), never as a separate document. Minting an artifact here would create a parallel record of the claim and invite drift from the claim it qualifies." }, { "id": "dep-evd-method-procedure", "name": "Discovery method, procedure and tool identification", "description": "Identifies the reusable procedure that produced a claim by reference to a registered, versioned method profile: analysis technique class, tool identity and version, configuration or rule-set version, reference-data version, and the method's declared blind spots. This mirrors sosa:usedProcedure (a described, reusable procedure rather than an executing system), the CycloneDX technique and tools structure, and the DQV notion of a metric as a defined procedure. The profile is descriptive metadata; this partition never executes, schedules or configures a detector.", "source_refs": [ "SRC-054", "SRC-055", "SRC-057", "SRC-021" ], "questions": [ { "id": "dep-evd-q-method-identity", "text": "Which registered method profile and version produced this claim?", "kind": "identity", "answer_data": [ "Method profile identifier and semantic version", "Configuration digest in force for the producing run", "Reference to the profile registration record" ] }, { "id": "dep-evd-q-method-technique", "text": "Which analysis technique class does the method belong to and what are its documented blind spots?", "kind": "quality", "answer_data": [ "Technique class code aligned to the CycloneDX technique enumeration", "Declared limitation statements (for example dynamic linking not visible to manifest analysis)", "Known false-positive and false-negative modes recorded as text" ] }, { "id": "dep-evd-q-method-config", "text": "What rule-set, signature database or reference-data version was in force when the method ran?", "kind": "provenance", "answer_data": [ "Rule-set or reference-data identifier and version", "Reference values or baseline set reference", "Digest of the effective configuration bundle" ] }, { "id": "dep-evd-q-method-change", "text": "Which changes to a method profile require existing claims to be re-derived rather than merely reinterpreted?", "kind": "lifecycle", "answer_data": [ "Profile change classification (editorial, additive, semantic-breaking)", "Re-derivation requirement flag per change class", "Superseded profile version reference retained for historic claims" ] } ], "data_elements": [ { "id": "dep-evd-de-method-profile-ref", "name": "Method profile reference", "description": "Reference to the registered method profile version that produced the claim.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-054", "SRC-021" ] }, { "id": "dep-evd-de-technique-code", "name": "Analysis technique code", "description": "Technique class of the method, aligned to the CycloneDX technique enumeration (source-code-analysis, binary-analysis, manifest-analysis, ast-fingerprint, hash-comparison, instrumentation, dynamic-analysis, filename, attestation, other).", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-021" ] }, { "id": "dep-evd-de-tool-identity", "name": "Tool identity record", "description": "Structured identity of each tool involved: name, publisher, version and, where available, tool binary digest.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-057", "SRC-021" ] }, { "id": "dep-evd-de-ruleset-version", "name": "Rule-set or reference-data version", "description": "Version of the rules, signatures or reference values applied during the producing run.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-056", "SRC-021" ] }, { "id": "dep-evd-de-method-limitations", "name": "Declared method limitation", "description": "Documented blind spot or systematic limitation of the method, carried so downstream consumers do not read absence of a claim as absence of a dependency.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-055", "SRC-060" ] } ], "artifacts": [ { "id": "dep-evd-artifact-method-profile", "name": "Method profile descriptor", "description": "A versioned, citable descriptor of one detection or declaration procedure: technique class, tool identity set, configuration and rule-set version pins, applicable subject classes, declared limitations and the confidence scale it emits. Claims reference the descriptor rather than restating the procedure, and the descriptor holds no executable configuration and no scan results.", "media_or_form": [ "structured descriptor record", "human-readable procedure page", "citable reference entry in a Dimension-governed method registry" ], "serial": true, "identity_strategy": "Dimension-governed method-profile identifier plus semantic version, with a configuration digest as content identity; superseded versions are retained and referenced by historic claims.", "source_refs": [ "SRC-054", "SRC-055", "SRC-021" ] } ], "inline_only_rationale": null } ] }, { "id": "dep-evd-authority-layer", "name": "Attribution, authority and evidence binding", "description": "Who stands behind a claim, on what authority, and how the claim is bound to a retrievable piece of external evidence without importing the evidence itself.", "source_refs": [ "SRC-001", "SRC-056", "SRC-057", "SRC-021", "SRC-058" ], "findings": [ { "id": "dep-evd-agent-attribution", "name": "Asserting agent, role and authority basis", "description": "Records the accountable agent for a claim, its role in the evidence chain and the basis of its authority. PROV-O supplies wasAttributedTo and qualifiedAttribution; RFC 9334 distinguishes Attester (produces Evidence), Endorser (vouches for capability), Reference Value Provider and Verifier; OpenVEX requires an author and permits a role and supplier; CISA lists the author of SBOM data as a required attribute. The agent record distinguishes the party that observed from the party that published, and names the authority basis (supplier of record, delegated, self-asserted, third-party). Signature verification and trust decisions about the agent are external.", "source_refs": [ "SRC-001", "SRC-056", "SRC-057", "SRC-058", "SRC-060" ], "questions": [ { "id": "dep-evd-q-agent-accountable", "text": "Which agent is accountable for this claim and in what role within the evidence chain?", "kind": "ownership", "answer_data": [ "Agent reference resolved in the external party registry", "Role code aligned to attester, endorser, reference-value provider, tool or reviewer", "Qualified attribution record carrying role plus time of attribution" ] }, { "id": "dep-evd-q-authority-basis", "text": "On what authority basis is the claim made - supplier of record, delegated authority, self-assertion or third-party assertion?", "kind": "authority", "answer_data": [ "Authority basis code", "Delegation reference or mandate identifier where authority is delegated", "Scope of the authority (which subjects or product lines it covers)" ] }, { "id": "dep-evd-q-envelope-binding", "text": "Which signed envelope or attestation carries this claim, and where is its signature verified?", "kind": "security", "answer_data": [ "Attestation envelope or statement reference with predicate type", "Signer key or identity reference as recorded by the producer", "Named external verification service that owns signature and trust-anchor evaluation" ] }, { "id": "dep-evd-q-observer-publisher", "text": "How are the agent that observed and the agent that published the claim kept distinguishable?", "kind": "provenance", "answer_data": [ "Separate observing-agent and publishing-agent references", "On-behalf-of / delegation chain reference", "Indicator that observation and publication were performed by the same agent" ] } ], "data_elements": [ { "id": "dep-evd-de-asserting-agent-ref", "name": "Asserting agent reference", "description": "Reference to the agent accountable for the claim, resolved in the external party or agent registry.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-058", "SRC-060" ] }, { "id": "dep-evd-de-agent-role-code", "name": "Evidence-chain role code", "description": "Role of the agent in the evidence chain, aligned to RATS roles and to tool/reviewer roles.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-056" ] }, { "id": "dep-evd-de-authority-basis-code", "name": "Authority basis code", "description": "Coded basis for the agent's standing to make the claim: supplier of record, delegated, self-asserted or third-party.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-056", "SRC-058" ] }, { "id": "dep-evd-de-observing-agent-ref", "name": "Observing agent reference", "description": "Reference to the agent or system that actually made the observation, where different from the publisher.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-054" ] }, { "id": "dep-evd-de-envelope-ref", "name": "Attestation envelope reference", "description": "Reference to the external signed envelope or statement carrying the claim, with its predicate type; the envelope body is not stored here.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-057" ] } ], "artifacts": [], "inline_only_rationale": "Attribution is pure reference data: pointers into an externally owned party registry plus coded role and authority values on the claim. The signed envelope that would be the natural artifact is created, versioned and verified outside this partition under in-toto or equivalent rules, so declaring a local artifact would duplicate an externally owned record and imply ownership of signature semantics this partition explicitly disclaims." }, { "id": "dep-evd-source-locator", "name": "Evidence source locator, fragment selector and payload exclusion", "description": "Binds a claim to the specific external evidence that supports it: a resolvable locator, a content digest that pins the exact revision, a fragment selector (file path, line, byte offset, symbol, call-stack frame, statement identifier), the media type, and any retrieval constraint. In-toto matches subjects purely by digest; CycloneDX occurrences carry location, line, offset and symbol; OpenVEX documents carry an IRI @id. The invariant is that no payload bytes, extracted secrets or excerpt text beyond a minimal locating selector are copied into this model, and that a broken or mismatched reference degrades the claim's resolvability without rewriting history.", "source_refs": [ "SRC-001", "SRC-057", "SRC-021", "SRC-058" ], "questions": [ { "id": "dep-evd-q-locator-resolution", "text": "How is the supporting evidence located again later, and which identifier pins the exact revision that was seen?", "kind": "identity", "answer_data": [ "Resolvable locator (URI or system-of-record reference)", "Content digest with named algorithm", "Retrieval hints such as media type, repository or snapshot reference" ] }, { "id": "dep-evd-q-fragment-selector", "text": "Which fragment of the evidence actually supports the claim?", "kind": "evidence", "answer_data": [ "Selector structure: path, line, byte offset, symbol or call-stack frame", "Statement or record identifier inside a structured evidence document", "Selector syntax identifier and version" ] }, { "id": "dep-evd-q-payload-exclusion", "text": "What must never be copied out of the evidence payload into this model?", "kind": "privacy", "answer_data": [ "Payload-exclusion rule set (no source excerpts, no credentials, no personal data, no full documents)", "Maximum permitted selector granularity", "Escalation path when a locator alone is insufficient to support the claim" ] }, { "id": "dep-evd-q-locator-decay", "text": "What happens to a claim when its evidence reference becomes unresolvable or its digest no longer matches?", "kind": "exception", "answer_data": [ "Reference resolvability state code (resolvable, unresolvable, digest-mismatch)", "Time the resolvability state was last checked and by whom", "Rule that resolvability state never alters the historic claim record and never triggers deletion" ] } ], "data_elements": [ { "id": "dep-evd-de-evidence-locator", "name": "Evidence locator", "description": "Resolvable identifier of the external evidence entity supporting the claim.", "value_kind": "identifier", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-057", "SRC-058" ] }, { "id": "dep-evd-de-content-digest", "name": "Evidence content digest", "description": "Digest of the referenced evidence with named algorithm, pinning the revision that was actually seen.", "value_kind": "identifier", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-057" ] }, { "id": "dep-evd-de-fragment-selector", "name": "Evidence fragment selector", "description": "Structured pointer to the supporting fragment: path, line, offset, symbol, call-stack frame or statement identifier.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-021" ] }, { "id": "dep-evd-de-evidence-media-type", "name": "Evidence media type", "description": "Media type or format identifier of the referenced evidence, used to select the correct selector syntax.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-057", "SRC-021" ] }, { "id": "dep-evd-de-reference-state", "name": "Reference resolvability state", "description": "Current state of the evidence reference: resolvable, unresolvable or digest-mismatch, with the time of the last resolution attempt.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-057" ] }, { "id": "dep-evd-de-no-evidence-rationale", "name": "No-evidence rationale", "description": "Mandatory explanation when a claim is recorded with no evidence reference at all, so that unsupported claims stay visibly unsupported.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-058", "SRC-060" ] } ], "artifacts": [ { "id": "dep-evd-artifact-reference-manifest", "name": "Evidence reference manifest", "description": "A serialised set of locator, digest, selector and media-type rows for one claim set or observation run, listing where the supporting evidence lives and which fragments were relied on. It is a reference index only: it contains no payload bytes, no excerpts beyond selectors, and it neither versions nor retains the evidence it points at.", "media_or_form": [ "structured reference index", "tabular manifest export", "attachment to a claim-set transfer package" ], "serial": true, "identity_strategy": "Manifest identifier scoped to the claim set or observation run, plus a monotonic sequence number and the manifest's own content digest; each row is keyed by evidence locator plus digest.", "source_refs": [ "SRC-057", "SRC-021", "SRC-058" ] } ], "inline_only_rationale": null } ] }, { "id": "dep-evd-strength-layer", "name": "Evidentiary strength, uncertainty and applicability limits", "description": "How strongly a claim is asserted, under what measurement conditions, and how far the claim may legitimately be generalised.", "source_refs": [ "SRC-055", "SRC-056", "SRC-021", "SRC-059" ], "findings": [ { "id": "dep-evd-strength-limits", "name": "Confidence, uncertainty, applicable scope and reproducibility conditions", "description": "Captures the strength a producer asserted and the conditions that bound it. CycloneDX carries a confidence value on an identity conclusion and on each contributing method; VIM defines measurement uncertainty as a non-negative parameter characterising the dispersion of values attributed to a measurand based on the information used, and distinguishes repeatability from reproducibility conditions; DQV structures a measurement as a value against a defined metric. This finding requires the scale to be named and versioned, the conditions under which the result was obtained to be stated, the applicability envelope (platform, build profile, configuration, population) to be declared, and comparability across methods to be governed by an explicit rule. It records these values; it never computes a score, threshold or verdict.", "source_refs": [ "SRC-055", "SRC-056", "SRC-021", "SRC-059" ], "questions": [ { "id": "dep-evd-q-confidence-scale", "text": "On which named scale is confidence expressed and what exactly does its value denote?", "kind": "measurement", "answer_data": [ "Confidence value plus scale identifier and version", "Scale definition: range, ordering, whether values are probabilities, ordinal ranks or opaque tool scores", "Per-method confidence values where several methods contributed" ] }, { "id": "dep-evd-q-uncertainty-conditions", "text": "Under which repeatability, intermediate precision or reproducibility conditions was the result obtained?", "kind": "quality", "answer_data": [ "Condition class code (repeatability, intermediate, reproducibility)", "Statement of what was held constant and what varied (operator, tool version, environment, time)", "Uncertainty statement or dispersion parameter where the producer supplied one" ] }, { "id": "dep-evd-q-applicability-envelope", "text": "To which configurations, platforms or build profiles does this claim apply, and where does it stop applying?", "kind": "constraint", "answer_data": [ "Applicability envelope: platform, architecture, build profile, feature flags, deployment class", "Explicit non-applicability exclusions", "Rule that a claim outside its envelope is unsupported rather than false" ] }, { "id": "dep-evd-q-strength-comparability", "text": "May confidence values produced by different methods be compared or aggregated, and under what recorded rule?", "kind": "interoperability", "answer_data": [ "Comparability rule identifier or an explicit not-comparable declaration", "Mapping table reference between scales where one exists", "Prohibition on arithmetic across unmapped scales" ] }, { "id": "dep-evd-q-strength-ceiling", "text": "What remains unknowable from this method even at its maximum stated confidence?", "kind": "evidence", "answer_data": [ "Method ceiling statement inherited from the method profile limitations", "Distinction between not-detected and not-present", "Recommended corroborating mode for claims at the ceiling" ] } ], "data_elements": [ { "id": "dep-evd-de-confidence-value", "name": "Confidence value", "description": "Producer-asserted confidence for the claim, meaningless without its scale reference.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-021" ] }, { "id": "dep-evd-de-confidence-scale-ref", "name": "Confidence scale reference", "description": "Identifier and version of the scale that defines the confidence value's range, ordering and interpretation; mandatory whenever a confidence value is present.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-055", "SRC-021" ] }, { "id": "dep-evd-de-uncertainty-statement", "name": "Uncertainty statement", "description": "Dispersion parameter or qualitative uncertainty statement supplied by the producer, following the VIM notion of uncertainty based on the information used.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-059" ] }, { "id": "dep-evd-de-condition-class", "name": "Measurement condition class", "description": "Whether the result was obtained under repeatability, intermediate precision or reproducibility conditions.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-059" ] }, { "id": "dep-evd-de-applicability-envelope", "name": "Applicability envelope", "description": "Structured statement of the configurations, platforms, build profiles or populations to which the claim applies, with explicit exclusions.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-054", "SRC-060" ] }, { "id": "dep-evd-de-comparability-rule", "name": "Comparability rule reference", "description": "Reference to the recorded rule permitting or forbidding comparison and aggregation of this confidence value with values from other scales.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-055", "SRC-059" ] } ], "artifacts": [], "inline_only_rationale": "Strength values are attributes of an individual claim and are only meaningful attached to it; the reusable part - the scale definition and the method's limitations - already lives in the governed confidence-scale vocabulary and in the method profile descriptor declared elsewhere in this model. Emitting a separate strength document would either duplicate those registered definitions or create a scoring record that edges toward the assessment role this partition disclaims." } ] } ] }, { "id": "dep-evd-observation-state-bundle", "name": "Observation record, currency and claim-state resolution", "description": "The observation event that produced a claim, the several distinct times attached to it, the declared window in which the claim remains assertable, and the resolution states a claim can occupy: complete or unknown enumeration, contradicted, superseded or retracted.", "rationale": "SOSA separates phenomenon time from result time, SPDX 3.0.1 gives a relationship its own start and end time, and RFC 9334 treats freshness as an explicit property demonstrated by timestamp, nonce or epoch identifier. Separately, SPDX RelationshipCompleteness, CycloneDX compositions aggregate and CISA's known-unknowns requirement all show that unknown enumeration must be stated rather than inferred, while OpenVEX and PROV invalidation show that assertions are superseded and retracted rather than deleted. These concerns share one lifecycle and belong in one bundle.", "source_refs": [ "SRC-001", "SRC-054", "SRC-056", "SRC-013", "SRC-014", "SRC-058", "SRC-060" ], "layers": [ { "id": "dep-evd-observation-layer", "name": "Observation event and time semantics", "description": "The discrete observation or assertion event, its subject binding and environment, and the several times that must be kept apart.", "source_refs": [ "SRC-001", "SRC-054", "SRC-056", "SRC-013" ], "findings": [ { "id": "dep-evd-observation-event", "name": "Observation event, subject binding and environment", "description": "Records the discrete act that produced a claim, following the SOSA pattern of an Observation carried out by a procedure on a feature of interest. Here the feature of interest is the dependency edge or the artifact under inspection, referenced - never redefined - through the core partition and external endpoint registries. The record captures the environment instance in which the observation was made (build run, deployment, target environment, as RFC 9334 separates Target from Attesting Environment), the run grouping that keeps sibling claims from one execution linked, and whether the whole population or a sample was inspected.", "source_refs": [ "SRC-001", "SRC-054", "SRC-056", "SRC-021" ], "questions": [ { "id": "dep-evd-q-observation-subject", "text": "Which dependency edge or endpoint was the subject of this observation, and how is that subject referenced?", "kind": "relationship", "answer_data": [ "Reference to the edge claim in the core dependency partition", "Endpoint references resolved in external registries, including subject digest where the subject is an artifact", "Feature-of-interest kind (edge, source endpoint, target endpoint, package archive)" ] }, { "id": "dep-evd-q-observation-environment", "text": "In which environment instance, build run or deployment was the observation made?", "kind": "event", "answer_data": [ "Environment instance reference (build identifier, cluster, host class, target environment)", "Environment kind code distinguishing build-time, test, staging and production", "Note on how representative the environment is of the environment the claim will be used for" ] }, { "id": "dep-evd-q-observation-sampling", "text": "Was the whole population inspected or only a sample, and how was that sample selected?", "kind": "measurement", "answer_data": [ "Coverage basis: exhaustive, sampled or opportunistic", "Sampling method and selection criteria", "Observed population size and inspected count where known" ] }, { "id": "dep-evd-q-observation-run-grouping", "text": "Which observation run does this record belong to so that all claims from one execution stay linked?", "kind": "identity", "answer_data": [ "Observation run identifier", "Procedure run reference linking to the method profile version used", "Count and list reference of sibling claims produced by the same run" ] } ], "data_elements": [ { "id": "dep-evd-de-observation-event-id", "name": "Observation event identifier", "description": "Identifier of the discrete observation or assertion act that produced the claim.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-054" ] }, { "id": "dep-evd-de-subject-edge-ref", "name": "Subject edge reference", "description": "Reference to the dependency or impact edge claim being qualified; the edge itself is owned by the core partition.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-013", "SRC-020" ] }, { "id": "dep-evd-de-environment-instance-ref", "name": "Environment instance reference", "description": "Reference to the build run, deployment or target environment in which the observation was made.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-056", "SRC-021" ] }, { "id": "dep-evd-de-observation-run-ref", "name": "Observation run reference", "description": "Grouping reference tying all claims produced by one execution of a method profile together.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-054" ] }, { "id": "dep-evd-de-coverage-basis", "name": "Coverage basis", "description": "Whether the observation was exhaustive over its scope, sampled or opportunistic, with the sampling method where applicable.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-054", "SRC-060" ] } ], "artifacts": [], "inline_only_rationale": "The observation event is a structured record on the claim graph consisting of identifiers and references to externally owned environments, runs and subjects. Materialising it as an artifact would create a second copy of scanner or pipeline run records that the producing system already owns, which conflicts with the rule that this partition is not a monitoring or scanning system and holds no execution state." }, { "id": "dep-evd-time-freshness", "name": "Time model and freshness inputs", "description": "Keeps four kinds of time distinct: the time the asserted dependency relation actually held (SPDX 3.0.1 relationship startTime and endTime; SOSA phenomenonTime), the time the observation completed (SOSA resultTime), the time the claim was recorded in this model (ingestion), and the declared validity boundary after which the claim should be re-observed. It also records which freshness mechanism demonstrates recency of the underlying evidence - signed timestamp, nonce or epoch identifier, as enumerated by RFC 9334 - and notes RFC 9334's warning that claim values may have been generated long before they were signed. This finding supplies freshness inputs; whether a claim is too stale to rely on is decided by an external appraisal or policy service.", "source_refs": [ "SRC-001", "SRC-054", "SRC-056", "SRC-013", "SRC-058" ], "questions": [ { "id": "dep-evd-q-relation-time", "text": "When did the asserted dependency relation actually hold, as distinct from when it was observed?", "kind": "temporal", "answer_data": [ "Relation start time and end time as RFC 3339 values with offset", "Phenomenon time or interval where the relation is instantaneous", "Indicator that relation time is unknown rather than open-ended" ] }, { "id": "dep-evd-q-record-times", "text": "When was the observation completed and when was the resulting claim recorded here?", "kind": "provenance", "answer_data": [ "Observation result time", "Ingestion time recorded by this model", "Producer-asserted publication time where the producing document carries one" ] }, { "id": "dep-evd-q-validity-window", "text": "For how long does this claim remain assertable before it must be re-observed?", "kind": "state", "answer_data": [ "Declared validity boundary or maximum age", "Basis for the boundary (method profile default, producer declaration, subject volatility)", "Behaviour after the boundary: still readable, marked stale, never auto-deleted" ] }, { "id": "dep-evd-q-freshness-mechanism", "text": "By which mechanism is the recency of the underlying evidence demonstrated - signed timestamp, nonce or epoch identifier?", "kind": "validation", "answer_data": [ "Freshness mechanism code (timestamp, nonce, epoch identifier, none)", "Challenge value or epoch identifier reference where one was used", "Note on clock trust and possible lag between value generation and signing" ] } ], "data_elements": [ { "id": "dep-evd-de-relation-start-time", "name": "Relation start time", "description": "RFC 3339 time from which the asserted dependency relation is stated to hold.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-054", "SRC-013" ] }, { "id": "dep-evd-de-relation-end-time", "name": "Relation end time", "description": "RFC 3339 time after which the asserted dependency relation is stated no longer to hold.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013" ] }, { "id": "dep-evd-de-observation-result-time", "name": "Observation result time", "description": "RFC 3339 time at which the observation or assertion act completed, following sosa:resultTime.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-054" ] }, { "id": "dep-evd-de-ingestion-time", "name": "Ingestion time", "description": "RFC 3339 time at which this model recorded the claim, always stored separately from observation time.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-058" ] }, { "id": "dep-evd-de-validity-boundary", "name": "Declared validity boundary", "description": "Time or maximum age after which the claim should be re-observed before further reliance.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-056", "SRC-058" ] }, { "id": "dep-evd-de-freshness-mechanism", "name": "Freshness mechanism code", "description": "Mechanism used to demonstrate recency of the underlying evidence: timestamp, nonce, epoch identifier or none.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-056" ] }, { "id": "dep-evd-de-freshness-challenge-ref", "name": "Freshness challenge reference", "description": "Reference to the nonce or epoch identifier that was incorporated by the producer, without reproducing the challenge protocol.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-056" ] } ], "artifacts": [], "inline_only_rationale": "These are timestamp fields and one coded mechanism value on the claim record. No cited standard produces a separate time document, and any derived age figure is a read-only projection over fields already stored; publishing it as an artifact would imply an acceptability judgement that belongs to the external appraisal service." } ] }, { "id": "dep-evd-claim-state-layer", "name": "Unknowns, contradiction, supersession and retraction", "description": "Explicit statements about what is not known, and the governed states a claim moves through when it is disputed, replaced or withdrawn.", "source_refs": [ "SRC-001", "SRC-021", "SRC-013", "SRC-014", "SRC-058", "SRC-060" ], "findings": [ { "id": "dep-evd-completeness-unknown", "name": "Completeness declarations and known unknowns", "description": "Requires an explicit statement of whether an enumerated dependency set for a stated scope is exhaustive, known to be partial, or not asserted at all. SPDX 3.0.1 defines completeness as complete, incomplete or noAssertion, and distinguishes a NoneElement target (asserting no relationships exist) from a NoAssertionElement target (no assertion made); CycloneDX compositions carry an aggregate value including unknown and not-specified; CISA requires SBOM authors to identify known unknowns explicitly where the full dependency graph is not enumerated, and sets depth expectations from direct dependencies upward. The governing rule adopted here is that a missing completeness statement is read as incomplete, never as complete.", "source_refs": [ "SRC-021", "SRC-013", "SRC-014", "SRC-020", "SRC-060" ], "questions": [ { "id": "dep-evd-q-completeness-state", "text": "Is the enumerated dependency set for this scope exhaustive, known to be partial, or not asserted at all?", "kind": "classification", "answer_data": [ "Completeness code aligned to complete, incomplete and noAssertion", "External aggregate value where imported from a composition-style document", "Agent and time of the completeness declaration" ] }, { "id": "dep-evd-q-none-versus-unknown", "text": "How is 'this node has no further dependencies' distinguished from 'its dependencies are unknown'?", "kind": "definition", "answer_data": [ "Explicit no-further-dependencies assertion flag", "Unknown-enumeration marker with reason code", "Rule forbidding an empty dependency list from being read as either" ] }, { "id": "dep-evd-q-completeness-scope", "text": "Which scope does the completeness statement cover - direct dependencies only, a stated depth, or the transitive closure?", "kind": "composition", "answer_data": [ "Scope reference (node, subgraph, product release)", "Declared depth: direct only, n levels, transitive closure", "Dependency classes included or excluded (build, dev, test, optional, provided, runtime)" ] }, { "id": "dep-evd-q-completeness-default", "text": "What is the default interpretation when no completeness statement is present at all?", "kind": "constraint", "answer_data": [ "Recorded default rule: absent means incomplete", "Warning or flag emitted to consumers on absent declarations", "Migration rule for legacy records ingested without a declaration" ] } ], "data_elements": [ { "id": "dep-evd-de-completeness-code", "name": "Completeness code", "description": "Completeness of the enumerated dependency set for the stated scope: complete, incomplete or no-assertion.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-014" ] }, { "id": "dep-evd-de-completeness-scope-ref", "name": "Completeness scope reference", "description": "Reference to the node, subgraph or release the completeness statement covers.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-013", "SRC-060" ] }, { "id": "dep-evd-de-declared-depth", "name": "Declared enumeration depth", "description": "Depth to which enumeration was attempted: direct dependencies only, a stated number of levels, or transitive closure.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-060" ] }, { "id": "dep-evd-de-no-further-dependencies", "name": "No-further-dependencies assertion", "description": "Affirmative assertion that the subject has no further dependencies, distinct from an empty or absent enumeration.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013", "SRC-060" ] }, { "id": "dep-evd-de-unknown-reason-code", "name": "Unknown-enumeration reason code", "description": "Why enumeration is incomplete or not asserted: method limitation, access restriction, supplier non-disclosure, opaque binary, not attempted.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-021", "SRC-060" ] }, { "id": "dep-evd-de-included-dependency-classes", "name": "Included dependency classes", "description": "Dependency classes the enumeration covered (build, development, test, optional, provided, runtime), so partial scope is not read as partial completeness.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-020" ] } ], "artifacts": [], "inline_only_rationale": "A completeness declaration is a coded assertion scoped to a node or subgraph and carried with the claim set it qualifies. In the cited standards it is a field on a relationship or a composition, never a standalone document, and separating it into an artifact would let a graph and its completeness statement drift apart, which is the exact failure the known-unknowns requirement exists to prevent." }, { "id": "dep-evd-contradiction-retraction", "name": "Contradiction registration, supersession and retraction", "description": "Governs the states a claim can occupy after assertion. Contradiction is registered as a pairwise relation between claims about the same edge whose scopes overlap but whose content disagrees; supersession follows the OpenVEX pattern where a later statement from the same authority overrides and enriches an earlier one; retraction follows PROV invalidation (wasInvalidatedBy, invalidatedAtTime), leaving the retracted record inspectable rather than deleted, with a required reason in the spirit of OpenVEX's mandatory justification. This partition registers and routes these states; it never decides which contradictory claim is true, and per RFC 9334 that appraisal belongs to the Verifier or an equivalent external adjudicator.", "source_refs": [ "SRC-001", "SRC-055", "SRC-056", "SRC-058" ], "questions": [ { "id": "dep-evd-q-contradiction-definition", "text": "When are two claims about the same edge genuinely contradictory rather than merely different in scope or time?", "kind": "definition", "answer_data": [ "Contradiction test: overlapping subject, overlapping applicability envelope, overlapping validity interval, incompatible assertion", "Non-contradiction cases: disjoint envelopes, disjoint time intervals, different dependency classes", "Recorded contradiction kind (existence, direction, class, completeness)" ] }, { "id": "dep-evd-q-supersession-ordering", "text": "Which claim supersedes which, and on what recorded basis does that ordering hold?", "kind": "lifecycle", "answer_data": [ "Supersedes and superseded-by references", "Ordering basis: same-authority document version, producer-asserted sequence, or explicit operator decision", "Explicit not-ordered marker where the claims come from different authorities" ] }, { "id": "dep-evd-q-retraction-record", "text": "How is a retraction recorded so that the retracted claim remains inspectable afterwards?", "kind": "retention", "answer_data": [ "Claim state transition to retracted with invalidation time", "Retained original claim record and its evidence references", "Tombstone content rules where evidence-bearing fields are minimised" ] }, { "id": "dep-evd-q-retraction-authority", "text": "Who may retract or supersede a claim, and what reason must accompany the action?", "kind": "authority", "answer_data": [ "Permitted actor set: original asserting agent, delegated steward, or authority named in the mandate", "Mandatory reason code plus free-text justification", "Rule that a third party may register a contradiction but may not retract another agent's claim" ] }, { "id": "dep-evd-q-contradiction-routing", "text": "Where is a registered contradiction sent for resolution, given that this partition does not adjudicate truth?", "kind": "decision", "answer_data": [ "Referral reference to the external appraisal, review or governance process", "Referral state (open, referred, resolved-elsewhere) with no local verdict field", "Back-reference recording the external outcome identifier only" ] } ], "data_elements": [ { "id": "dep-evd-de-claim-state-code", "name": "Claim state code", "description": "Current state of the claim: asserted, superseded, retracted or contradicted.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-058" ] }, { "id": "dep-evd-de-supersedes-ref", "name": "Supersedes claim reference", "description": "Reference to the earlier claim or claims this record overrides, following the OpenVEX sequence pattern.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-058" ] }, { "id": "dep-evd-de-state-effective-time", "name": "State effective time", "description": "RFC 3339 time from which the supersession or retraction takes effect, recorded separately from the ingestion time of the state change.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-058" ] }, { "id": "dep-evd-de-retraction-reason", "name": "Retraction or supersession reason", "description": "Mandatory coded reason with optional free text explaining why the claim was withdrawn or replaced.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-058" ] }, { "id": "dep-evd-de-contradiction-pair-ref", "name": "Contradiction pair reference", "description": "Reference to the counterpart claim with which this claim is registered as contradictory, plus the contradiction kind.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-055", "SRC-056" ] }, { "id": "dep-evd-de-referral-ref", "name": "Adjudication referral reference", "description": "Reference to the external review, appraisal or governance case handling the contradiction; carries no local verdict.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-056" ] } ], "artifacts": [ { "id": "dep-evd-artifact-claim-state-notice", "name": "Claim revision and retraction notice", "description": "A dated, versioned notice that records supersession or retraction of one or more previously published claims: prior claim identifiers, new state, effective time, reason and issuing agent. Modelled on the OpenVEX document pattern of versioned statements that override earlier ones, it exists so that consumers who already received a claim can be told it changed. It contains no verdict on which claim is true and no audit record of who read it.", "media_or_form": [ "structured notice record", "published change notice for downstream consumers", "entry in a claim-set change feed" ], "serial": true, "identity_strategy": "Notice identifier with a monotonically increasing version per issuing agent and claim scope, carrying the identifiers of every affected prior claim; sequence numbers are never reused after retraction.", "source_refs": [ "SRC-001", "SRC-058" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "dep-life-assertion-lifecycle-bundle", "name": "Dependency assertion lifecycle and continuity", "description": "Everything needed to know what state a dependency assertion is in, who may move it, how its identity persists across change, how it is deprecated or superseded, and where the assertion's lifecycle stops and the endpoint's own lifecycle begins.", "rationale": "Registry practice treats a recorded assertion as an administered item with a governed status ladder and a named change controller, while state-management standards treat a managed resource's own state as a separate axis owned elsewhere. Conflating the two is the most common modelling failure in dependency records, so the two lifecycles are separated at bundle level.", "source_refs": [ "SRC-066", "SRC-068", "SRC-062", "SRC-013" ], "layers": [ { "id": "dep-life-registration-layer", "name": "Assertion registration states and transitions", "description": "The controlled state vocabulary an individual dependency assertion may hold, the permitted moves between those states, the preconditions declared for each move, and the authority required.", "source_refs": [ "SRC-066", "SRC-068", "SRC-001" ], "findings": [ { "id": "dep-life-state-vocabulary", "name": "Registration lifecycle state vocabulary", "description": "A governed, versioned set of registration states for a single dependency assertion - proposed, in-review, active, deprecated, superseded, retired - with, for each, a definition, whether it is terminal, and whether an assertion in that state may be relied on for downstream decisions. This is the assertion's administrative status only; it says nothing about whether the dependency is currently being met and nothing about the endpoints' own operational state.", "source_refs": [ "SRC-066", "SRC-068", "SRC-067", "SRC-013" ], "questions": [ { "id": "dep-life-q-state-set", "text": "Which registration states may a dependency assertion hold, and which of them are terminal?", "kind": "lifecycle", "answer_data": [ "Enumerated state codes with definitions", "Terminal-state flag per state", "Ordering or precedence among non-terminal states" ] }, { "id": "dep-life-q-state-usability", "text": "What does each state assert about whether the dependency may be relied on for a downstream decision?", "kind": "definition", "answer_data": [ "Decision-usability classification per state", "Narrative semantics of each state", "Explicit statement that usability is independent of current condition" ] }, { "id": "dep-life-q-state-authority", "text": "Which registration authority or role may place an assertion into each state?", "kind": "authority", "answer_data": [ "Authorised role or registration authority reference per state", "Registration policy strength, from open recording to review-gated", "Named change controller for the assertion class" ] }, { "id": "dep-life-q-state-vocab-binding", "text": "Which version of the state vocabulary governs a given assertion record, and how is a retired term still resolved?", "kind": "interoperability", "answer_data": [ "Vocabulary identifier and version", "Term identifier or IRI per state", "Deprecated-term resolution rule" ] } ], "data_elements": [ { "id": "dep-life-de-registration-state", "name": "Registration state", "description": "The current administrative state of the dependency assertion, drawn from the governed state vocabulary.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-066" ] }, { "id": "dep-life-de-state-terminal-flag", "name": "Terminal state indicator", "description": "Whether the state admits any outgoing transition other than correction.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-066" ] }, { "id": "dep-life-de-state-vocabulary-ref", "name": "State vocabulary binding", "description": "Reference to the identifier and version of the vocabulary release that defines the recorded state code.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-068", "SRC-067" ] }, { "id": "dep-life-de-decision-usability", "name": "Decision usability class", "description": "Whether an assertion in this state may be used as input to downstream reasoning, may be used with caution, or must not be used.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-066" ] } ], "artifacts": [ { "id": "dep-life-art-state-vocabulary", "name": "Assertion lifecycle state vocabulary release", "description": "The published, versioned term set of registration states with definitions, terminal flags, decision-usability classes and deprecation notes for withdrawn terms.", "media_or_form": [ "Controlled vocabulary / code list", "Term definitions with resolvable term identifiers", "Deprecation and replacement notes per term" ], "serial": true, "identity_strategy": "Governed vocabulary identifier issued by the adopting Dimension's registration authority, plus a monotonic version tag. The publication date is metadata on the release and is never part of the identifier.", "source_refs": [ "SRC-066", "SRC-068", "SRC-067" ] } ], "inline_only_rationale": null }, { "id": "dep-life-transition-control", "name": "Permitted transitions, guards and transition events", "description": "The explicit matrix of allowed state pairs, the preconditions declared for each move, the justification and evidence that must accompany a transition request, and the transition event record naming requester, approver and event time. Guards are declared here in a checkable form; their runtime evaluation and any enforcement action are performed by an external rule or workflow engine.", "source_refs": [ "SRC-066", "SRC-068", "SRC-001", "SRC-062" ], "questions": [ { "id": "dep-life-q-transition-matrix", "text": "Which state transitions are permitted, and which state pairs are explicitly forbidden?", "kind": "constraint", "answer_data": [ "From-state and to-state pairs with allowed or forbidden marking", "Reason text for each forbidden pair", "Whether the matrix is closed, so that unlisted pairs are forbidden by default" ] }, { "id": "dep-life-q-transition-preconditions", "text": "What preconditions and supporting evidence must be declared before a transition may be requested?", "kind": "requirement", "answer_data": [ "Guard expression or checklist reference per transition", "Required evidence reference types", "Whether the precondition is blocking or advisory" ] }, { "id": "dep-life-q-transition-event", "text": "What is recorded when a transition occurs, and who requested it as against who approved it?", "kind": "event", "answer_data": [ "Transition event time in RFC 3339 form", "Requesting actor reference and approving actor reference", "Resulting state and prior state", "Free-text justification" ] }, { "id": "dep-life-q-transition-rejection", "text": "How is a rejected, withdrawn or expired proposal represented without deleting the proposal record?", "kind": "exception", "answer_data": [ "Outcome code for rejection, withdrawal or expiry", "Retention treatment of the unsuccessful proposal", "Whether the same assertion key may be re-proposed and under what conditions" ] }, { "id": "dep-life-q-guard-executor", "text": "Which external component evaluates the declared guards at request time, and what does it return?", "kind": "process", "answer_data": [ "Reference to the evaluating rule or workflow service", "Evaluation outcome codes accepted by this model", "Statement that this model stores outcomes and never executes evaluation" ] } ], "data_elements": [ { "id": "dep-life-de-transition-from-state", "name": "Transition source state", "description": "The registration state held immediately before the transition.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-066" ] }, { "id": "dep-life-de-transition-to-state", "name": "Transition target state", "description": "The registration state entered by the transition.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-066" ] }, { "id": "dep-life-de-transition-guard-ref", "name": "Declared guard reference", "description": "Reference to the precondition expression or checklist that must hold for the transition, evaluated externally.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-068" ] }, { "id": "dep-life-de-transition-event-time", "name": "Transition event time", "description": "The instant at which the transition took effect, recorded separately from the instant the transition was written to the record store.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-069", "SRC-001" ] }, { "id": "dep-life-de-transition-actor-ref", "name": "Transition actor references", "description": "References to the requesting party and, where the transition is review-gated, the approving authority.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-068", "SRC-001" ] }, { "id": "dep-life-de-transition-justification", "name": "Transition justification", "description": "Narrative reason recorded with the transition, required for deprecation, retirement and annulment.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-066" ] }, { "id": "dep-life-de-transition-outcome", "name": "Transition outcome code", "description": "Whether the requested transition was applied, rejected, withdrawn or expired.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-068" ] } ], "artifacts": [ { "id": "dep-life-art-transition-table", "name": "Assertion state transition table", "description": "The governed matrix of from-state and to-state pairs with allowed or forbidden marking, the guard reference and required approval role for each permitted transition, and the closed-world statement for unlisted pairs.", "media_or_form": [ "State-transition matrix", "Guard declaration list with references to externally evaluated expressions", "Approval-role assignment per transition" ], "serial": true, "identity_strategy": "Governed transition-table identifier assigned by the adopting Dimension, plus a monotonic revision number aligned to the state vocabulary version it constrains; publication date is a qualifier, never an identifier.", "source_refs": [ "SRC-066", "SRC-068" ] } ], "inline_only_rationale": null } ] }, { "id": "dep-life-continuity-layer", "name": "Identity continuity, supersession and historical state", "description": "How an assertion keeps its identity through change, how a replaced assertion is linked to its successor, and how deprecated and retired assertions stay readable for reconstruction rather than being erased.", "source_refs": [ "SRC-013", "SRC-001", "SRC-066", "SRC-067" ], "findings": [ { "id": "dep-life-weak-identity", "name": "Weak, host-dependent assertion identity", "description": "A dependency assertion has no independent global identity. It is keyed relative to the host record that carries the mixin, together with the dependent and provider endpoint references, the dependency type and any lifecycle scope. Identity survives changes of registration state, condition value and effective interval, all of which are qualifiers of a record version rather than components of the key. Dates and timestamps are never key components.", "source_refs": [ "SRC-013", "SRC-001", "SRC-066", "SRC-069" ], "questions": [ { "id": "dep-life-q-identity-key", "text": "Which attributes compose the identity key of a dependency assertion within its host record?", "kind": "identity", "answer_data": [ "Host record reference", "Ordered list of key attributes with the dependency type and endpoint references", "Explicit exclusion list naming state, condition and time values as non-key" ] }, { "id": "dep-life-q-identity-stability", "text": "Does a change of registration state, condition or effective interval create a new assertion or a new record version of the same assertion?", "kind": "lifecycle", "answer_data": [ "Change-class to identity-effect mapping", "Record-version number of the affected assertion", "Rule stating which attribute changes force a new key" ] }, { "id": "dep-life-q-identity-host-versioning", "text": "How is an assertion identified when the host record is itself versioned, replaced or merged?", "kind": "composition", "answer_data": [ "Host version reference or host lineage reference", "Carry-forward rule for assertions on a replaced host", "Merge and split handling for colliding assertion keys" ] }, { "id": "dep-life-q-identity-surrogate", "text": "What surrogate identifier may the adopting Dimension assign, and what precedence does it have against an authoritative master-system identifier?", "kind": "provenance", "answer_data": [ "Surrogate identifier value and issuing scheme", "Authoritative master-system identifier where one exists", "Precedence rule placing the master-system identifier first" ] } ], "artifacts": [], "inline_only_rationale": "Identity here is a key-composition rule plus a small set of reference fields carried on the host record. Publishing it as a separate artifact would create a second, competing identity anchor for something the model deliberately declares weak and host-dependent, so the context stays inline as declared key attributes and their exclusions.", "data_elements": [ { "id": "dep-life-de-host-record-ref", "name": "Host record reference", "description": "Reference to the record that carries the dependency mixin and therefore scopes the assertion's identity.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-013" ] }, { "id": "dep-life-de-assertion-key", "name": "Assertion identity key", "description": "The composed key of host reference, endpoint references, dependency type and lifecycle scope that identifies the assertion within its host.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-013", "SRC-066" ] }, { "id": "dep-life-de-assertion-surrogate-id", "name": "Dimension-assigned surrogate identifier", "description": "Optional UUID or ULID minted by the adopting Dimension for addressing convenience; subordinate to any authoritative master-system identifier.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-066" ] }, { "id": "dep-life-de-record-version-number", "name": "Record version number", "description": "Monotonic version counter distinguishing successive record versions of the same assertion identity.", "value_kind": "number", "cardinality": "1", "required": true, "source_refs": [ "SRC-070", "SRC-061" ] } ] }, { "id": "dep-life-supersession-chain", "name": "Deprecation, supersession chains and historical state", "description": "How an assertion that is discouraged but still true is distinguished from one that is no longer asserted at all, how a successor assertion is linked to its predecessor, how chains are traversed and kept acyclic, and why retired assertions remain readable instead of being erased. Reuse of a retired assertion key is treated as an interoperability hazard.", "source_refs": [ "SRC-067", "SRC-066", "SRC-001", "SRC-068" ], "questions": [ { "id": "dep-life-q-supersession-link", "text": "Which successor assertion replaces a superseded one, and is the replacement total or partial?", "kind": "relationship", "answer_data": [ "Replaced-by reference on the predecessor", "Replaces reference on the successor", "Replacement scope code distinguishing total from partial replacement" ] }, { "id": "dep-life-q-chain-traversal", "text": "How far back may a supersession chain be traversed, and how are cycles detected and prevented?", "kind": "constraint", "answer_data": [ "Chain depth limit or unbounded declaration", "Acyclicity constraint statement", "Traversal direction supported by the record" ] }, { "id": "dep-life-q-deprecation-vs-retirement", "text": "What distinguishes deprecation, where the dependency is discouraged but still holds, from retirement, where it is no longer asserted?", "kind": "classification", "answer_data": [ "Deprecation reason code", "Whether the assertion still contributes to downstream reasoning", "Retirement decision reference and effective moment" ] }, { "id": "dep-life-q-key-reuse", "text": "Under what conditions, if any, may a retired assertion key be reused for a different dependency?", "kind": "decision", "answer_data": [ "Reuse permitted or forbidden flag", "Quarantine period expressed as a duration, not a date", "Interoperability risk note recorded with any permitted reuse" ] } ], "artifacts": [], "inline_only_rationale": "Supersession is expressed entirely as typed references and reason codes between assertion records, and the successor assertion is itself the payload that carries the replacement. Materialising a separate supersession document would duplicate those references and create a third place where the chain could disagree with itself.", "data_elements": [ { "id": "dep-life-de-replaces-ref", "name": "Replaces reference", "description": "Reference from the successor assertion to each assertion it supplants or supersedes.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-067" ] }, { "id": "dep-life-de-replaced-by-ref", "name": "Replaced-by reference", "description": "Reference from a superseded assertion to the assertion now preferred for use.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-067", "SRC-066" ] }, { "id": "dep-life-de-supersession-scope", "name": "Supersession scope", "description": "Whether the successor replaces the predecessor entirely or only for part of its endpoint set or lifecycle scope.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013", "SRC-067" ] }, { "id": "dep-life-de-deprecation-reason", "name": "Deprecation reason", "description": "Coded reason the assertion is discouraged while remaining true, for example superseded design, vendor withdrawal or pending replacement.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-066", "SRC-068" ] }, { "id": "dep-life-de-retirement-time", "name": "Retirement event time", "description": "The instant from which the assertion is no longer asserted, recorded in RFC 3339 form with seconds and an explicit offset.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-069" ] }, { "id": "dep-life-de-key-reuse-policy", "name": "Key reuse policy reference", "description": "Reference to the adopting Dimension's rule on whether a retired assertion key may be reused, and after what quarantine duration.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-068" ] } ] } ] }, { "id": "dep-life-endpoint-boundary-layer", "name": "Endpoint lifecycle boundary", "description": "The explicit separation between the assertion's own lifecycle and the administrative and operational lifecycles of the endpoints it names, which are owned by their master systems.", "source_refs": [ "SRC-062", "SRC-063", "SRC-013" ], "findings": [ { "id": "dep-life-endpoint-state-reference", "name": "Externally owned endpoint state referenced, not maintained", "description": "The dependent and provider endpoints each have their own administrative state, governing whether use is permitted, and operational state, governing whether the resource is operable. Both are attributes of the managed entity and are owned by its master system. This model holds a reference to the owning system, optionally a copied state snapshot, and the instant that snapshot was read, so that a condition determination can be explained later. It never transitions endpoint state, never polls for it, and never treats a copied snapshot as authoritative after its read time.", "source_refs": [ "SRC-062", "SRC-063", "SRC-001", "SRC-013" ], "questions": [ { "id": "dep-life-q-endpoint-owner", "text": "Which system is the authoritative owner of each endpoint's administrative and operational state?", "kind": "ownership", "answer_data": [ "Endpoint reference", "Owning master-system reference", "Statement of which state axes that system governs" ] }, { "id": "dep-life-q-endpoint-snapshot", "text": "Which endpoint state value was used when a condition was determined, and when was that value read?", "kind": "provenance", "answer_data": [ "Copied administrative and operational state values", "Snapshot read time in RFC 3339 form", "Reference to the source record or response the value came from" ] }, { "id": "dep-life-q-endpoint-decommission", "text": "How does an assertion behave when a referenced endpoint is decommissioned or its state becomes unknown?", "kind": "exception", "answer_data": [ "Assertion outcome code for a vanished or unknown endpoint", "Whether the assertion is retired, left active with undetermined condition, or flagged for review", "Escalation reference to the owning system" ] }, { "id": "dep-life-q-endpoint-prohibitions", "text": "What actions on endpoint state are explicitly forbidden to this model?", "kind": "constraint", "answer_data": [ "Prohibition list covering transition, polling, remediation and authoritative caching", "Snapshot staleness rule expressed as a maximum age duration", "Named model that owns each forbidden capability" ] } ], "artifacts": [], "inline_only_rationale": "Endpoint state is a record owned and published by each endpoint's master system. Only a reference, an explicitly non-authoritative copied value and its read time belong here, and producing an artifact would publish a second copy of a record this model has no authority to maintain or correct.", "data_elements": [ { "id": "dep-life-de-endpoint-ref", "name": "Endpoint reference", "description": "Reference to each endpoint named by the assertion in its dependent or provider role.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-013" ] }, { "id": "dep-life-de-endpoint-state-owner-ref", "name": "Endpoint state owner reference", "description": "Reference to the master system that authoritatively governs the endpoint's administrative and operational state.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-062", "SRC-063" ] }, { "id": "dep-life-de-endpoint-state-snapshot", "name": "Copied endpoint state snapshot", "description": "Non-authoritative copy of the endpoint's administrative and operational state values as used in a condition determination.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-062" ] }, { "id": "dep-life-de-endpoint-state-read-time", "name": "Snapshot read time", "description": "The instant the copied state value was read from its owning system, distinct from any event time within that system.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-069", "SRC-064" ] }, { "id": "dep-life-de-endpoint-snapshot-max-age", "name": "Snapshot maximum age", "description": "Declared duration after which a copied endpoint state value must not be used to support a condition determination.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-064" ] } ] } ] } ] }, { "id": "dep-life-health-temporal-bundle", "name": "Dependency condition and temporal reconstruction", "description": "Whether the asserted dependency is currently met, on what declared criteria and evidence, over which effective interval, and how a consumer reconstructs what was believed at any chosen past moment despite late evidence and later corrections.", "rationale": "Observation standards separate the time a result applies to from the time it became available, and temporal database standards separate the period a fact holds in the world from the period a row was recorded. Both separations are required before a health statement about a dependency can be replayed honestly, so condition and time are governed together and kept apart from the administrative lifecycle.", "source_refs": [ "SRC-064", "SRC-070", "SRC-061", "SRC-065", "SRC-062" ], "layers": [ { "id": "dep-life-health-layer", "name": "Condition determination and its evidence", "description": "The controlled condition vocabulary for the assertion, the declared criteria mapping evidence to each value, and the referenced observations that support a determination.", "source_refs": [ "SRC-062", "SRC-064", "SRC-065" ], "findings": [ { "id": "dep-life-condition-vocabulary", "name": "Condition values: satisfied, degraded, broken, restored, undetermined", "description": "A controlled vocabulary describing whether the asserted dependency is currently met, partially met, unmet, has returned to met after being unmet, or cannot be determined, together with the declared criteria that map referenced evidence to each value and the severity ordering between them. Condition is a derived property of the assertion, distinct from the assertion's registration state and from any endpoint's operational state.", "source_refs": [ "SRC-062", "SRC-063", "SRC-065", "SRC-013" ], "questions": [ { "id": "dep-life-q-condition-values", "text": "Which condition values may a dependency assertion carry, and how are they ordered by severity?", "kind": "classification", "answer_data": [ "Enumerated condition codes with definitions", "Severity rank per code", "Statement of which codes are mutually exclusive at one instant" ] }, { "id": "dep-life-q-condition-criteria", "text": "What declared criteria map referenced evidence to each condition value, including the threshold separating degraded from broken?", "kind": "measurement", "answer_data": [ "Criterion expression or threshold reference per condition value", "Units and comparison operator where a threshold is numeric", "Reference to the externally evaluated criterion where evaluation is automated" ] }, { "id": "dep-life-q-condition-determiner", "text": "Who or what determined the condition value, and was the determination automated or asserted by a person?", "kind": "authority", "answer_data": [ "Determining actor or procedure reference", "Determination mode code for automated or human assertion", "Approval role where a human assertion overrides an automated one" ] }, { "id": "dep-life-q-condition-restoration", "text": "How is restoration distinguished in the record from a dependency that was never broken?", "kind": "state", "answer_data": [ "Prior condition value carried with the current determination", "Reference to the determination that recorded the breakage", "Duration of the unmet period derived from effective intervals" ] }, { "id": "dep-life-q-condition-undetermined", "text": "What is recorded when the condition cannot be determined from available evidence?", "kind": "quality", "answer_data": [ "Undetermined condition code with a reason code", "Missing or stale evidence references", "Confidence or reliability qualifier on the determination" ] } ], "data_elements": [ { "id": "dep-life-de-condition-value", "name": "Condition value", "description": "The current condition of the assertion drawn from the governed condition vocabulary.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-062", "SRC-065" ] }, { "id": "dep-life-de-condition-severity-rank", "name": "Condition severity rank", "description": "Ordinal severity of the condition value, permitting comparison and worst-case selection across assertions.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-062" ] }, { "id": "dep-life-de-condition-criteria-ref", "name": "Condition criterion reference", "description": "Reference to the declared criterion or threshold whose satisfaction yields this condition value, evaluated outside this model.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-064", "SRC-065" ] }, { "id": "dep-life-de-condition-determined-time", "name": "Condition determination time", "description": "The instant the condition value was determined, held separately from the interval over which the condition is asserted to hold.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-064", "SRC-069" ] }, { "id": "dep-life-de-condition-determiner-ref", "name": "Condition determiner reference", "description": "Reference to the actor, procedure or service that made the determination.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-064" ] }, { "id": "dep-life-de-condition-prior-value", "name": "Prior condition value", "description": "The condition value immediately preceding this determination, enabling restoration and degradation to be recognised without recomputing history.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-062", "SRC-070" ] }, { "id": "dep-life-de-condition-confidence", "name": "Determination confidence", "description": "Coded confidence or reliability qualifier attached to the condition determination.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-064", "SRC-065" ] } ], "artifacts": [ { "id": "dep-life-art-condition-vocabulary", "name": "Dependency condition vocabulary with criteria bindings", "description": "The published term set of condition values with definitions, severity ranks, mutual-exclusion rules, and the binding of each value to the declared criteria or thresholds that yield it.", "media_or_form": [ "Controlled vocabulary / code list", "Criteria-to-value mapping table", "Severity ordering declaration" ], "serial": true, "identity_strategy": "Governed vocabulary identifier plus monotonic version tag issued by the adopting Dimension; each release cites the criterion references it binds. Release date is metadata, never part of the identifier.", "source_refs": [ "SRC-062", "SRC-065", "SRC-066" ] } ], "inline_only_rationale": null }, { "id": "dep-life-health-observation-record", "name": "Health observations referenced as evidence", "description": "Observations about endpoint or dependency health are produced, stored and quality-assured elsewhere. This finding governs which observations were used as evidence for a determination and how their two times are carried: the phenomenon time to which the result applies, and the result time at which the result became available. Observations that arrive out of order are linked to the determination they should have informed without altering determinations already made.", "source_refs": [ "SRC-064", "SRC-065", "SRC-001", "SRC-069" ], "questions": [ { "id": "dep-life-q-evidence-set", "text": "Which observations were used as evidence for this condition determination, and where are they held?", "kind": "evidence", "answer_data": [ "Observation references with owning system", "Observed property and procedure references copied for interpretation", "Whether the evidence set is complete or partial" ] }, { "id": "dep-life-q-evidence-two-times", "text": "What is the phenomenon time of each referenced observation, and when did its result become available to this model?", "kind": "temporal", "answer_data": [ "Phenomenon time per observation", "Result time per observation", "Ingestion time at which this model first saw the observation" ] }, { "id": "dep-life-q-evidence-out-of-order", "text": "How is an observation whose result arrives after a later determination linked to the determination it should have informed?", "kind": "provenance", "answer_data": [ "Back-link from the late observation to the affected determination", "Flag marking the affected determination as revisable", "Whether a corrected determination was issued and its reference" ] }, { "id": "dep-life-q-evidence-quality", "text": "What quality or reliability qualifiers must accompany referenced observation evidence?", "kind": "quality", "answer_data": [ "Reliability or quality code copied from the observation", "Maximum acceptable evidence age", "Rule for excluding evidence that fails the quality bar" ] }, { "id": "dep-life-q-evidence-owner", "text": "Which model owns collection, sampling, procedure definition and storage of these observations?", "kind": "interoperability", "answer_data": [ "Reference to the owning observation model or service", "Reference resolution mechanism and stability guarantee", "Statement that this model contributes no observation production capability" ] } ], "artifacts": [], "inline_only_rationale": "Observations are created and retained by a referenced observation model that owns their procedure, sampling feature and result. This finding contributes only evidence references and copied time and quality qualifiers, so producing an artifact here would republish another model's payload and imply monitoring semantics the boundary notes exclude.", "data_elements": [ { "id": "dep-life-de-evidence-observation-ref", "name": "Evidence observation reference", "description": "Reference to each externally held observation used to support the condition determination.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-064", "SRC-065" ] }, { "id": "dep-life-de-observation-phenomenon-time", "name": "Observation phenomenon time", "description": "Copied time to which the observation's result applies, as distinct from when the result became available.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-064", "SRC-069" ] }, { "id": "dep-life-de-observation-result-time", "name": "Observation result time", "description": "Copied time at which the observation result became available, typically when the producing procedure completed.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-064", "SRC-065" ] }, { "id": "dep-life-de-evidence-ingest-time", "name": "Evidence ingestion time", "description": "The instant this model first became aware of the observation, used to detect late arrival relative to determinations already made.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-070", "SRC-069" ] }, { "id": "dep-life-de-evidence-completeness", "name": "Evidence completeness", "description": "Whether the referenced evidence set is known exhaustive, known non-exhaustive, or carries no assertion of completeness.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013" ] }, { "id": "dep-life-de-evidence-reliability", "name": "Evidence reliability qualifier", "description": "Copied quality or reliability code accompanying the observation, used to gate its admissibility.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-064", "SRC-065" ] } ] } ] }, { "id": "dep-life-temporal-layer", "name": "Effective intervals, as-of reconstruction and correction", "description": "The two independent time dimensions of the record - the interval over which an assertion or condition holds in the world, and the interval over which the record itself was believed - and the rules that let a consumer replay any past moment and correct a mistake without rewriting history.", "source_refs": [ "SRC-070", "SRC-033", "SRC-061", "SRC-001" ], "findings": [ { "id": "dep-life-effective-interval", "name": "Effective intervals of assertions and conditions", "description": "Each assertion and each condition determination carries an effective interval with an inclusive start and an exclusive end, left open where it remains current, optionally narrowed to a lifecycle scope such as build or runtime. Intervals are qualifiers of a record version, never components of identity; successive intervals for the same assertion and the same time dimension must not overlap, and closing an interval is an append, not an edit.", "source_refs": [ "SRC-070", "SRC-033", "SRC-013", "SRC-067", "SRC-069" ], "questions": [ { "id": "dep-life-q-interval-bounds", "text": "What are the effective start and end of this assertion, and is the interval still open?", "kind": "temporal", "answer_data": [ "Effective-from instant in RFC 3339 form", "Effective-to instant or an explicit open marker", "Derived duration where both bounds are known" ] }, { "id": "dep-life-q-interval-convention", "text": "Which interval boundary convention applies, and may two intervals for the same assertion overlap?", "kind": "constraint", "answer_data": [ "Boundary convention code, normally closed-open", "Non-overlap constraint statement per time dimension", "Gap handling rule where consecutive intervals do not meet" ] }, { "id": "dep-life-q-interval-scope", "text": "To which lifecycle scope does the effective interval apply, given that a dependency may hold at build time but not at run time?", "kind": "classification", "answer_data": [ "Lifecycle scope code referenced from the typing area", "Whether unscoped means all scopes or unknown scope", "Per-scope interval set where scopes differ" ] }, { "id": "dep-life-q-interval-closure", "text": "How is an interval closed when the assertion stops holding, without deleting or editing the earlier record?", "kind": "lifecycle", "answer_data": [ "Closing instant and the reason the assertion ceased", "New record version created by the closure", "Reference from the closing version to the version it closes" ] } ], "artifacts": [], "inline_only_rationale": "An effective interval is two timestamp fields plus a boundary-convention code carried directly on each assertion and condition record. There is no separable document to publish, and materialising one would risk being read as an authoritative anchor for something the model treats strictly as a qualifier.", "data_elements": [ { "id": "dep-life-de-effective-from", "name": "Effective from", "description": "Inclusive instant from which the assertion or condition is asserted to hold in the world.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-070", "SRC-069" ] }, { "id": "dep-life-de-effective-to", "name": "Effective to", "description": "Exclusive instant at which the assertion or condition ceases to hold; absent while the interval remains open.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-070", "SRC-033" ] }, { "id": "dep-life-de-interval-open-flag", "name": "Open interval indicator", "description": "Explicit marker that the interval is unbounded on the right, distinguishing currency from an unrecorded end.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-033" ] }, { "id": "dep-life-de-interval-boundary-convention", "name": "Interval boundary convention", "description": "Declared inclusivity of the interval bounds, normally closed on the left and open on the right.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-033", "SRC-070" ] }, { "id": "dep-life-de-lifecycle-scope", "name": "Lifecycle scope of the interval", "description": "Optional narrowing of the interval to a lifecycle phase such as design, build, test or runtime, referenced from the typing area.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-019", "SRC-015" ] }, { "id": "dep-life-de-interval-cease-reason", "name": "Interval closure reason", "description": "Coded reason the interval was closed, distinguishing a real-world change from a superseding assertion.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-067" ] } ] }, { "id": "dep-life-asof-correction", "name": "As-of reconstruction, late observation and correction without rewriting history", "description": "Two independent time dimensions - the effective interval over which a fact holds and the record interval over which it was believed - allow a consumer to ask what was asserted as of a chosen pair of times. A change in the world extends the effective dimension; a mistake is corrected by appending a new record version that closes the record interval of the erroneous version and, where the earlier statement was never true, annuls it with an explicit reason. Prior record versions are immutable so that a citation to a past state stays stable.", "source_refs": [ "SRC-070", "SRC-061", "SRC-065", "SRC-001", "SRC-069" ], "questions": [ { "id": "dep-life-q-asof-parameters", "text": "Which pair of times must a consumer supply to reconstruct the assertion set as of a chosen moment?", "kind": "temporal", "answer_data": [ "Effective-time parameter", "Record-time parameter with a default of now", "Result set semantics when only one parameter is supplied" ] }, { "id": "dep-life-q-correction-vs-change", "text": "How is a correction of a mistaken record distinguished from a genuine change in the world?", "kind": "decision", "answer_data": [ "Change-class code separating correction from real-world change", "Which time dimension is modified in each case", "Whether the effective interval of the earlier version is preserved unchanged" ] }, { "id": "dep-life-q-annulment", "text": "What is recorded when an earlier assertion is annulled as never having been true?", "kind": "validation", "answer_data": [ "Annulment flag and reason code", "Reference to the annulled record version", "Instruction that annulled versions remain readable but must not be used for reasoning" ] }, { "id": "dep-life-q-version-citation", "text": "How is a prior record version addressed so that a downstream citation remains stable and resolvable?", "kind": "provenance", "answer_data": [ "Version address composed of assertion key and record-version number", "Immutability guarantee for a cited version", "Enumeration of available versions for an assertion" ] }, { "id": "dep-life-q-correction-authority", "text": "Who may issue a correction or annulment, and what evidence must accompany it?", "kind": "authority", "answer_data": [ "Authorised role for correction and for annulment", "Required evidence or justification references", "Whether a second approver is required for annulment" ] } ], "data_elements": [ { "id": "dep-life-de-record-time-from", "name": "Record time from", "description": "Instant from which this record version was the believed statement; the left bound of the record/decision dimension.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-070", "SRC-069" ] }, { "id": "dep-life-de-record-time-to", "name": "Record time to", "description": "Instant at which this record version ceased to be the believed statement; absent for the current version.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-070", "SRC-061" ] }, { "id": "dep-life-de-correction-of-ref", "name": "Correction-of reference", "description": "Reference from a corrected version to the record version it revises, without altering that version.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-065" ] }, { "id": "dep-life-de-change-class", "name": "Change class", "description": "Whether the new version records a real-world change, a correction of a mistaken record, or an annulment.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-070", "SRC-065" ] }, { "id": "dep-life-de-annulled-flag", "name": "Annulment indicator", "description": "Marks a record version as entered in error and excluded from reasoning while remaining readable.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-065", "SRC-001" ] }, { "id": "dep-life-de-correction-reason", "name": "Correction reason", "description": "Coded reason for the correction or annulment, such as wrong endpoint, wrong dependency type or misread evidence.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-065", "SRC-066" ] }, { "id": "dep-life-de-asof-query-parameters", "name": "As-of reconstruction parameters", "description": "The effective-time and record-time pair, with any lifecycle-scope filter, that defines a reconstruction request.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-070", "SRC-061" ] } ], "artifacts": [ { "id": "dep-life-art-record-version-series", "name": "Assertion record-version series", "description": "The ordered, append-only series of record versions for one assertion identity, each carrying its effective interval, record interval, change class and any correction or annulment reference, so that any past belief state can be reconstructed and cited.", "media_or_form": [ "Ordered record-version series", "Time-indexed snapshot set with an enumerable version list", "Append-only change log of this model's own assertion records" ], "serial": true, "identity_strategy": "Series identified by the weak assertion key; each member addressed by that key plus a monotonically increasing record-version number. Record time is a qualifier on the member and never forms part of its address; once published a member is immutable.", "source_refs": [ "SRC-070", "SRC-061", "SRC-001" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "dep-graph-asserted-fact-base", "name": "Asserted edge base and propagation gating", "description": "The primary-fact layer of the dependency graph: what an asserted edge is, how it stays addressable and immutable, how derived or postulated relations are kept distinguishable from it, and the explicit gate that decides whether impact may travel along an edge at all.", "rationale": "Every defensible impact answer resolves to a set of asserted edges plus a rule that permitted traversal. SPDX 3.0.1 models a relationship as an addressable assertion with from, to, type, completeness and a validity interval; SPDX lifecycle scope records that a build dependency and an operational dependency have different implications; OpenVEX shows that a present component can still be non-impacting for a stated reason. PROV-CONSTRAINTS and RDF 1.1 Semantics jointly forbid assuming transitivity or materialisation. Grouping these into one bundle keeps the fact base auditable and prevents propagation policy from leaking into stored facts.", "source_refs": [ "SRC-013", "SRC-014", "SRC-019", "SRC-071", "SRC-073", "SRC-075", "SRC-076" ], "layers": [ { "id": "dep-graph-edge-assertion", "name": "Edge assertion and relation modality", "description": "How a single dependency edge is asserted, addressed, typed, scoped and time-bounded, and how direct, transitive, inferred and hypothetical relations remain separable in storage and in answers.", "source_refs": [ "SRC-013", "SRC-019", "SRC-071", "SRC-072", "SRC-073" ], "findings": [ { "id": "dep-graph-edge-fact", "name": "Asserted dependency edge as a primary fact", "description": "An asserted edge is a first-class, addressable statement that a source subject depends on one or more target subjects under a named relation type, a lifecycle scope, a validity interval, an asserting agent and a confidence value. It is treated as immutable: corrections are made by superseding assertions, never by silent edit, so that any projection computed over an earlier edge set remains explainable. Endpoints are references into an owning inventory model, never copies of the entities.", "source_refs": [ "SRC-013", "SRC-019", "SRC-075", "SRC-030" ], "questions": [ { "id": "dep-graph-q-edge-identity", "text": "What identifier makes this asserted dependency edge addressable independently of its endpoints?", "kind": "identity", "answer_data": [ "Composite edge key over source reference, relation type, target reference, lifecycle scope and validity start", "Master-system assertion identifier or governed IRI where the asserting system issues one", "Minting authority and scheme for locally assigned surrogate identifiers" ] }, { "id": "dep-graph-q-edge-typing", "text": "Which typed relation does the edge assert, in which direction, and under which lifecycle scope?", "kind": "classification", "answer_data": [ "Relation type code drawn from a governed vocabulary such as SPDX RelationshipType or CycloneDX dependsOn/provides", "Direction convention fixing which endpoint is the dependant and which is the dependency", "Zero or more lifecycle scope codes (design, development, build, test, runtime, other)" ] }, { "id": "dep-graph-q-edge-validity-window", "text": "Over which validity interval is the asserted edge held to be true, and when was that observed?", "kind": "temporal", "answer_data": [ "Edge start time and end time as RFC 3339 values with explicit offset or Z", "Separate assertion or observation timestamp for when the claim was recorded", "Marker for an open-ended or unknown interval end" ] }, { "id": "dep-graph-q-edge-assertion-provenance", "text": "Who or what asserted the edge, from which evidence, and with what confidence?", "kind": "provenance", "answer_data": [ "Asserting agent, tool or document reference", "Evidence reference such as a build manifest, scan result, declared dependency file or human declaration", "Confidence value together with the identifier of the scale that defines it" ] }, { "id": "dep-graph-q-edge-endpoint-binding", "text": "How do the edge endpoints resolve to entities owned by an external inventory model?", "kind": "interoperability", "answer_data": [ "Endpoint reference scheme (SPDX Element identifier, CycloneDX bom-ref, purl, CPE, master-data key)", "Identifier of the inventory or asset model that owns each endpoint", "Behaviour when an endpoint reference fails to resolve, including quarantine rather than silent drop" ] } ], "data_elements": [ { "id": "dep-graph-de-edge-key", "name": "Edge key", "description": "Stable, date-free identifier for the asserted edge, resolved by the identity priority rule.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-013" ] }, { "id": "dep-graph-de-source-ref", "name": "Source endpoint reference", "description": "Reference to the dependant subject, owned by an external inventory model.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-013", "SRC-075" ] }, { "id": "dep-graph-de-target-ref", "name": "Target endpoint reference", "description": "One or more references to depended-on subjects; a distinguished none-marker asserts that no such dependency exists, and is not the same as omission.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-013", "SRC-075" ] }, { "id": "dep-graph-de-edge-type", "name": "Relation type code", "description": "Governed code for the asserted relation, bound to an external vocabulary by namespace.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-013" ] }, { "id": "dep-graph-de-lifecycle-scope", "name": "Lifecycle scope", "description": "Zero or more lifecycle contexts in which the dependency holds, following the SPDX lifecycle scope vocabulary.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-019" ] }, { "id": "dep-graph-de-validity-window", "name": "Edge validity window", "description": "Start and end of the interval over which the asserted edge is claimed valid, recorded separately from assertion time.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013" ] }, { "id": "dep-graph-de-assertion-provenance", "name": "Assertion provenance", "description": "Asserting agent or tool, evidence references and assertion timestamp for the edge.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-071", "SRC-030" ] }, { "id": "dep-graph-de-assertion-confidence", "name": "Assertion confidence", "description": "Confidence attached to the edge assertion, with an explicit scale reference; consumed by propagation licensing thresholds.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-076" ] } ], "artifacts": [ { "id": "dep-graph-art-edge-assertion-record", "name": "Edge assertion record", "description": "The format-neutral record of one asserted dependency edge, carrying key, endpoints, type, scope, validity window, provenance and confidence, plus any supersession pointer. Projectable to an SPDX Relationship, a CycloneDX dependency entry, a reified RDF statement or a property-graph edge without loss of the declared semantics.", "media_or_form": [ "structured record, format-neutral", "projection to SPDX 3.0.1 Relationship", "projection to CycloneDX 1.6 dependency entry", "projection to a qualified RDF statement or property-graph edge" ], "serial": false, "identity_strategy": "Authoritative master-system assertion identifier where the asserting system of record issues one; otherwise a governed IRI from a published namespace; otherwise a Dimension-minted UUID or ULID recorded with its minting authority. The composite edge key is retained as a natural key for deduplication but never replaces the assigned identifier.", "source_refs": [ "SRC-013", "SRC-073", "SRC-075" ] } ], "inline_only_rationale": null }, { "id": "dep-graph-relation-modality", "name": "Direct, transitive, inferred and hypothetical modality", "description": "Every dependency statement carries a modality discriminator plus, for non-direct modalities, the basis that licensed it. Direct means asserted by an agent about an immediate relation. Transitive means produced by composing asserted edges under a declared closure with a stated depth bound. Inferred means entailed by a declared property characteristic, property chain or rule. Hypothetical means postulated for what-if analysis and not claimed to hold. PROV-CONSTRAINTS establishes that derivation is not transitive by default, and RDF 1.1 Semantics establishes that a valid inference need not be materialised, so both transitivity and materialisation must be declared rather than assumed.", "source_refs": [ "SRC-071", "SRC-072", "SRC-073" ], "questions": [ { "id": "dep-graph-q-modality-definition", "text": "How are direct, transitive, inferred and hypothetical relations defined so that they never collapse into one another?", "kind": "definition", "answer_data": [ "Closed modality vocabulary with one definition per term and mutually exclusive assignment", "Rule that a statement carries exactly one modality and that modality survives export to any storage projection", "Prohibition on promoting a derived statement to direct without a new agent assertion" ] }, { "id": "dep-graph-q-modality-derivation-basis", "text": "For an inferred or transitive relation, which rule, property characteristic or closure method licensed it?", "kind": "relationship", "answer_data": [ "Reference to a declared transitive property or object property chain, with the OWL 2 global-restriction check recorded", "Closure method identifier and the traversal depth actually applied", "Ordered list of asserted edge keys consumed as premises" ] }, { "id": "dep-graph-q-modality-materialization", "text": "Is a derived relation materialised as a stored statement, and how is it kept distinguishable from asserted facts?", "kind": "state", "answer_data": [ "Materialisation flag with the projection or run that produced the statement", "Storage rule keeping derived statements outside the asserted edge set", "Invalidation trigger when a premise edge is superseded or its validity window closes" ] }, { "id": "dep-graph-q-hypothetical-quarantine", "text": "Under what conditions may a hypothetical relation enter an impact answer, and how is that answer labelled?", "kind": "decision", "answer_data": [ "Scenario identifier that scopes the hypothetical edge set", "Mandatory labelling of any answer that consumed hypothetical edges", "Default exclusion of hypothetical edges from actual-state answers" ] } ], "data_elements": [ { "id": "dep-graph-de-modality", "name": "Relation modality", "description": "Discriminator with values direct, transitive, inferred or hypothetical, carried on every dependency statement.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-071", "SRC-073" ] }, { "id": "dep-graph-de-derivation-basis", "name": "Derivation basis", "description": "For transitive or inferred statements: the property characteristic, property chain, rule or closure method reference plus the depth applied and the premise edge keys.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-071", "SRC-072" ] }, { "id": "dep-graph-de-materialization-flag", "name": "Materialisation flag", "description": "Whether the derived statement is stored or is recomputed on demand; a valid inference does not oblige materialisation.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-073" ] }, { "id": "dep-graph-de-hypothesis-scenario-ref", "name": "Hypothesis scenario reference", "description": "Identifier of the what-if scenario that scopes a hypothetical edge, including which edges it adds or removes.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-077", "SRC-078" ] } ], "artifacts": [], "inline_only_rationale": "Modality is a discriminator and a small justification structure carried on records that already exist elsewhere in the model: the edge assertion record for asserted facts and the analysis run descriptor and result sets for derived statements. Materialising it as its own artifact would create a second addressable object for the same statement and would immediately raise a synchronisation problem between the artifact and the statement it qualifies. The controlled modality vocabulary and the property-characteristic definitions it points to are governed outside this model, in OWL 2 and in the adopting Dimension's namespace registry, so this finding contributes constraints and reference bindings rather than a stored artifact of its own." } ] }, { "id": "dep-graph-propagation-gate", "name": "Propagation licensing and exclusion", "description": "The explicit gate that decides whether impact may traverse an asserted edge: positive licence profiles keyed on type, scope, direction, condition and confidence, and negative typed exclusions that suppress a present edge for a stated and evidenced reason.", "source_refs": [ "SRC-019", "SRC-076", "SRC-077" ], "findings": [ { "id": "dep-graph-propagation-condition", "name": "Conditions under which an edge licenses propagation", "description": "An edge is a fact; it is not automatically a channel for impact. A propagation licence profile states which combinations of relation type, lifecycle scope, direction, validity overlap and minimum confidence permit traversal for a given impact question. Because SPDX records that a build dependency carries different implications from an operational dependency, the same asserted edge can license propagation in one scope and not in another. The default is deny: an edge that matches no profile is not traversed, and the resulting answer says so rather than silently omitting a branch.", "source_refs": [ "SRC-013", "SRC-019", "SRC-075", "SRC-077" ], "questions": [ { "id": "dep-graph-q-licence-scope", "text": "Which combination of relation type, lifecycle scope and direction licenses impact to propagate along an edge?", "kind": "constraint", "answer_data": [ "Licence profile matching relation type codes to permitted propagation directions", "Lifecycle scopes in which the licence applies and those in which it is withheld", "Impact question class the profile is written for, since one profile does not serve every question" ] }, { "id": "dep-graph-q-licence-default", "text": "What is the default when no propagation licence profile matches an edge?", "kind": "requirement", "answer_data": [ "Explicit deny-by-default rule with no implicit fallback", "Required reporting of unmatched edges as a distinct category in the result", "Escalation path for requesting a new profile" ] }, { "id": "dep-graph-q-licence-confidence-floor", "text": "What minimum assertion confidence must an edge carry before it may be traversed for a published impact answer?", "kind": "measurement", "answer_data": [ "Confidence threshold per profile and the scale it is expressed on", "Treatment of edges with absent confidence values", "Whether below-threshold edges are dropped or reported as a separate low-confidence frontier" ] }, { "id": "dep-graph-q-licence-temporal-overlap", "text": "How must an edge validity window overlap the analysis reference time for traversal to be permitted?", "kind": "temporal", "answer_data": [ "Reference instant or interval the analysis is asked about", "Overlap predicate (contains, intersects, starts-before) applied to edge validity windows", "Handling of edges with open or unknown interval ends" ] }, { "id": "dep-graph-q-licence-authority", "text": "Who owns and versions a propagation licence profile, and how are competing profiles resolved?", "kind": "authority", "answer_data": [ "Owning role and approval record for each profile version", "Deterministic precedence rule when several profiles match the same edge", "Change class that makes a profile revision breaking for existing projections" ] } ], "data_elements": [ { "id": "dep-graph-de-licence-profile-id", "name": "Propagation licence profile identifier", "description": "Versioned identifier of the profile that governs traversal for a class of impact questions.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-019" ] }, { "id": "dep-graph-de-licensed-edge-type", "name": "Licensed relation types", "description": "Relation type codes the profile permits to be traversed.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-013", "SRC-075" ] }, { "id": "dep-graph-de-propagation-direction", "name": "Permitted propagation direction", "description": "Whether impact may travel along the edge downstream, upstream or in both directions for this profile.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-013", "SRC-077" ] }, { "id": "dep-graph-de-licence-condition", "name": "Licence condition", "description": "Additional predicate that must hold for traversal, such as a configuration flag, deployment condition or lifecycle scope match.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-019", "SRC-076" ] }, { "id": "dep-graph-de-confidence-threshold", "name": "Confidence threshold", "description": "Minimum edge assertion confidence required by the profile, with its scale reference.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-076" ] } ], "artifacts": [ { "id": "dep-graph-art-propagation-licence-profile", "name": "Propagation licence profile", "description": "A versioned, format-neutral rule set binding relation types, lifecycle scopes, directions, temporal overlap predicates and confidence thresholds to a permission to traverse for a named class of impact question, together with its deny-by-default statement and precedence rank.", "media_or_form": [ "versioned rule set, format-neutral", "tabular decision matrix over relation type and lifecycle scope", "declarative predicate document referenced by an analysis run" ], "serial": false, "identity_strategy": "Governed profile identifier issued by the owning package in the adopting Dimension's namespace, with an explicit semantic version; date-free. Superseded versions remain resolvable so historical projections stay interpretable.", "source_refs": [ "SRC-013", "SRC-019", "SRC-077" ] } ], "inline_only_rationale": null }, { "id": "dep-graph-propagation-exclusion", "name": "Typed exclusion of a present edge", "description": "An edge that exists and matches a licence profile may still be excluded from a specific impact answer for a stated, evidenced reason. OpenVEX demonstrates the pattern with machine-readable justifications such as the vulnerable code not being present, not being on the execute path, not being controllable by an adversary, or being covered by inline mitigations. Generalised here, an exclusion is a typed, scoped, expiring statement over an edge, an edge class or a subgraph. The critical rule is reporting: an excluded edge must be visible in the result as suppressed, never rendered as absent, because absence carries a completeness claim that an exclusion does not.", "source_refs": [ "SRC-014", "SRC-075", "SRC-076" ], "questions": [ { "id": "dep-graph-q-exclusion-justification", "text": "Which machine-readable justification explains why a present edge does not propagate impact in this case?", "kind": "exception", "answer_data": [ "Justification code from a governed vocabulary aligned to OpenVEX status justifications", "Free-text elaboration bound to the code, never replacing it", "Rule that an exclusion without a justification code is invalid" ] }, { "id": "dep-graph-q-exclusion-scope-and-expiry", "text": "What is the applicability scope of an exclusion and when does it lapse?", "kind": "temporal", "answer_data": [ "Scope as a single edge, a relation-type class, a subgraph or an endpoint neighbourhood", "Effective-from and expiry timestamps in RFC 3339 with offset", "Re-review trigger when a premise edge or configuration changes" ] }, { "id": "dep-graph-q-exclusion-evidence", "text": "What evidence supports the exclusion and who reviewed it?", "kind": "evidence", "answer_data": [ "Evidence references such as configuration proof, call-graph analysis or build settings", "Reviewing role and approval record", "Evidence strength or confidence recorded on the same scale as edge confidence" ] }, { "id": "dep-graph-q-exclusion-visibility", "text": "How is an excluded edge reported so that a consumer can tell suppression from absence?", "kind": "quality", "answer_data": [ "Result section listing suppressed edges with their justification codes", "Prohibition on removing suppressed edges from the traversal record", "Counts reported separately for traversed, suppressed and unmatched edges" ] } ], "data_elements": [ { "id": "dep-graph-de-exclusion-id", "name": "Exclusion identifier", "description": "Addressable identifier of the exclusion statement.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-076" ] }, { "id": "dep-graph-de-exclusion-scope", "name": "Exclusion scope", "description": "The edge, relation-type class, subgraph or neighbourhood over which the exclusion applies, plus the impact question class it applies to.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-076" ] }, { "id": "dep-graph-de-exclusion-justification", "name": "Exclusion justification code", "description": "Governed code stating why propagation is withheld despite the edge being present.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-076" ] }, { "id": "dep-graph-de-exclusion-expiry", "name": "Exclusion expiry", "description": "Timestamp after which the exclusion no longer applies and the edge returns to normal licensing.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013", "SRC-076" ] }, { "id": "dep-graph-de-exclusion-evidence-ref", "name": "Exclusion evidence reference", "description": "References to the evidence and the approval record supporting the exclusion.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-076", "SRC-030" ] } ], "artifacts": [ { "id": "dep-graph-art-exclusion-statement", "name": "Propagation exclusion statement", "description": "A standalone, addressable statement that a present edge or edge class is suppressed for a named impact question, carrying justification code, scope, effective and expiry times, evidence references and approver. Kept separate from the edge record so the underlying fact is never mutated by a policy decision.", "media_or_form": [ "standalone statement record, format-neutral", "projection to a VEX-style justification document", "annotation attached to a released projection's suppressed-edge section" ], "serial": false, "identity_strategy": "Master-system identifier where an upstream exception or exploitability system issues one; otherwise a governed IRI; otherwise a Dimension-minted UUID or ULID. The referenced edge key is carried as a foreign reference, never as the exclusion's own identity.", "source_refs": [ "SRC-076" ] } ], "inline_only_rationale": null } ] }, { "id": "dep-graph-closed-world", "name": "Completeness and closed-world declaration", "description": "The declarations that must exist before any statement about absence, non-reachability or 'no impact' may be published, including the enumeration frontier actually covered and the gaps declared as known unknowns.", "source_refs": [ "SRC-014", "SRC-073", "SRC-075", "SRC-030" ], "findings": [ { "id": "dep-graph-completeness-declaration", "name": "Completeness declaration and enumeration frontier", "description": "Absence of an edge is not evidence of absence of dependency. CycloneDX states plainly that objects not represented in the dependency graph may have unknown dependencies and that implementations should treat this as opaque rather than as dependency-freedom; RDF is a purely assertional language with no way to express absence; SPDX therefore carries an explicit three-valued completeness marker on the relationship itself. This finding requires a scoped completeness declaration naming the node scope, relation types and traversal depth actually enumerated, the gaps recorded as known unknowns, and the flag that licenses a closed-world reading. Any negative conclusion must cite a resolvable declaration that covers the queried scope.", "source_refs": [ "SRC-014", "SRC-073", "SRC-075", "SRC-030" ], "questions": [ { "id": "dep-graph-q-completeness-value", "text": "Is the enumerated edge set for this scope complete, incomplete, or is no assertion made?", "kind": "validation", "answer_data": [ "Three-valued completeness code aligned to SPDX complete, incomplete and noAssertion", "Basis for the claim, such as an exhaustive manifest parse or a partial scan", "Default of noAssertion when nothing has been declared" ] }, { "id": "dep-graph-q-enumeration-frontier", "text": "Which node scope, relation types and traversal depth does the completeness declaration actually cover?", "kind": "composition", "answer_data": [ "Node or subgraph scope the declaration applies to", "Relation type codes enumerated and those explicitly not enumerated", "Maximum traversal depth reached and whether the frontier was truncated" ] }, { "id": "dep-graph-q-known-unknowns", "text": "Which gaps are declared as known unknowns rather than treated as absent edges?", "kind": "evidence", "answer_data": [ "Enumerated gap records naming the node or edge class that could not be resolved", "Reason for each gap, such as an opaque binary, a closed upstream or an unresolvable reference", "Distinguished no-assertion marker separate from a positive assertion that nothing exists" ] }, { "id": "dep-graph-q-closed-world-licence", "text": "What licenses a closed-world reading so that absence of an edge may be read as absence of dependency?", "kind": "constraint", "answer_data": [ "Explicit closed-world flag scoped to the declared frontier, defaulting to false", "Named authority that may set the flag and the evidence required", "Rule that a negative conclusion outside the declared frontier is invalid regardless of the flag" ] }, { "id": "dep-graph-q-completeness-currency", "text": "How long does a completeness declaration remain valid, and what invalidates it?", "kind": "lifecycle", "answer_data": [ "Declared validity interval with RFC 3339 bounds", "Invalidation triggers such as a new edge assertion inside the scope or a superseded endpoint", "Re-declaration obligation and the owning role" ] } ], "data_elements": [ { "id": "dep-graph-de-completeness-id", "name": "Completeness declaration identifier", "description": "Addressable identifier of the declaration, citable from any negative conclusion.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-014" ] }, { "id": "dep-graph-de-completeness-value", "name": "Completeness value", "description": "Three-valued marker: complete, incomplete or noAssertion.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-014" ] }, { "id": "dep-graph-de-enumeration-frontier", "name": "Enumeration frontier", "description": "Node scope, relation types covered and maximum depth actually enumerated, with a truncation indicator.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-075", "SRC-030" ] }, { "id": "dep-graph-de-known-unknown", "name": "Known unknown record", "description": "Declared gap in enumeration, with the affected node or edge class and the reason it could not be resolved.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-075", "SRC-030" ] }, { "id": "dep-graph-de-closed-world-flag", "name": "Closed-world flag", "description": "Whether absence within the declared frontier may be read as absence in reality; defaults to false.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-014", "SRC-073", "SRC-075" ] } ], "artifacts": [ { "id": "dep-graph-art-completeness-declaration", "name": "Completeness declaration", "description": "A scoped, time-bounded declaration of how exhaustively an edge set was enumerated, naming the frontier, the completeness value, the declared known unknowns and the closed-world flag, signed by the declaring role. Cited by identifier from every projection that makes a negative or reachability claim.", "media_or_form": [ "scoped declaration record, format-neutral", "projection to an SPDX relationship completeness value plus a scope note", "header block attached to a released impact projection" ], "serial": false, "identity_strategy": "Governed identifier issued by the declaring owner package; date-free and stable across re-declaration, with each re-declaration recorded as a new version that supersedes the prior one by explicit pointer.", "source_refs": [ "SRC-014", "SRC-075", "SRC-030" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "dep-graph-derived-projections", "name": "Derived graph projections and result semantics", "description": "Everything computed rather than asserted: the run descriptor that makes a derived result reproducible and falsifiable, and the declared semantics of each result type - paths, cycles and strongly connected groups, reachability, fan-in and fan-out, cut sets and alternative paths.", "rationale": "A graph result is meaningless without its algorithm, parameters, edge filter and input snapshot: implementation documentation for strongly connected components shows results reflect a projected graph at execution time, and ISO/IEC 39075 shows that even 'a path' is ambiguous until a restrictor such as walk, trail, acyclic or simple is fixed. IEC 61025 and IEC 61078 supply the established qualitative vocabulary for cut sets and success paths, but bind those results to a stated method and stated assumptions. Separating this bundle from the fact base enforces the rule that projections are never merged into the asserted edge set and are re-derived rather than patched.", "source_refs": [ "SRC-071", "SRC-072", "SRC-074", "SRC-077", "SRC-078", "SRC-079" ], "layers": [ { "id": "dep-graph-analysis-provenance", "name": "Analysis run and projection provenance", "description": "How a derived result is bound to the algorithm, parameters, edge filter and immutable input snapshot that produced it, and how it becomes stale.", "source_refs": [ "SRC-071", "SRC-074", "SRC-079" ], "findings": [ { "id": "dep-graph-analysis-run", "name": "Declared analysis run over a named snapshot", "description": "A derived result is admissible only as a projection carrying: the algorithm identifier and version, the full parameter set, the edge-selection filter (relation types, licence profile, modality inclusions, exclusions applied, temporal reference), the digest of the immutable input edge set, the run execution time, a determinism class and any supersession pointer. This mirrors how graph analytics actually behave, computing over a projected in-memory graph whose results reflect that projection at execution time. The model records the run; it never executes it, and it holds no claim over the evaluator's own execution logs or audit records.", "source_refs": [ "SRC-071", "SRC-074", "SRC-077", "SRC-079" ], "questions": [ { "id": "dep-graph-q-method-identity", "text": "Which algorithm identifier and version produced this derived result?", "kind": "identity", "answer_data": [ "Registered method identifier with version, distinct per algorithm variant", "Implementation or evaluator reference where the same method has several implementations", "Rule that an algorithm change requires a new method identifier rather than a silent revision" ] }, { "id": "dep-graph-q-run-parameters", "text": "Which parameters, edge filters and modality inclusions defined the analysed subgraph?", "kind": "process", "answer_data": [ "Complete parameter set including seeds, depth bounds and direction", "Edge filter naming relation types, licence profile version and applied exclusions", "Which relation modalities were admitted, in particular whether hypothetical edges were included" ] }, { "id": "dep-graph-q-snapshot-binding", "text": "Against which immutable snapshot of the asserted edge set was the run executed?", "kind": "provenance", "answer_data": [ "Snapshot digest over the canonicalised selected edge set", "Reference to the completeness declarations covering the snapshot scope", "Temporal reference instant the snapshot represents, separate from the run execution time" ] }, { "id": "dep-graph-q-result-determinism", "text": "Is the result reproducible from the recorded snapshot and parameters, and where is it not?", "kind": "quality", "answer_data": [ "Determinism class such as deterministic, tie-break dependent or randomised with seed", "Recorded random seed or tie-break rule where applicable", "Known non-determinism such as arbitrary representative selection within a component" ] }, { "id": "dep-graph-q-projection-supersession", "text": "What makes a stored projection stale, and how is supersession recorded?", "kind": "state", "answer_data": [ "Staleness triggers: input snapshot digest mismatch, licence profile revision, completeness re-declaration", "Supersedes and superseded-by pointers between run descriptors", "Rule that a stale projection may not support a negative or absence conclusion" ] } ], "data_elements": [ { "id": "dep-graph-de-method-id", "name": "Analysis method identifier", "description": "Registered identifier and version of the algorithm that produced the result.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-079" ] }, { "id": "dep-graph-de-method-parameters", "name": "Method parameters", "description": "Complete parameter set including seeds, bounds, direction and tie-break or random seed.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-074", "SRC-079" ] }, { "id": "dep-graph-de-edge-filter", "name": "Edge selection filter", "description": "Relation types, licence profile version, applied exclusions, admitted modalities and temporal reference that defined the analysed subgraph.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-019", "SRC-076" ] }, { "id": "dep-graph-de-snapshot-digest", "name": "Input snapshot digest", "description": "Content digest over the canonicalised selected edge set, giving the projection a falsifiable input identity.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-079" ] }, { "id": "dep-graph-de-run-time", "name": "Run execution time", "description": "When the analysis was executed, recorded separately from edge validity time and from the snapshot reference instant.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-071" ] }, { "id": "dep-graph-de-determinism-class", "name": "Determinism class", "description": "Whether the result is fully deterministic, tie-break dependent or seeded-random.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-079" ] }, { "id": "dep-graph-de-supersedes-ref", "name": "Supersession reference", "description": "Pointer to the run descriptor this projection replaces, or to the one that replaced it.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-071" ] } ], "artifacts": [ { "id": "dep-graph-art-analysis-run-descriptor", "name": "Analysis run descriptor", "description": "The header record that makes every derived result reproducible and challengeable: method identity and version, parameters, edge filter, snapshot digest, cited completeness declarations, run time, determinism class and supersession pointers. Every result set in this bundle is invalid without a resolvable descriptor.", "media_or_form": [ "run descriptor record, format-neutral", "manifest header prepended to any released result set", "provenance-style record projectable to a PROV activity description without importing PROV lifecycle semantics" ], "serial": true, "identity_strategy": "Governed method identifier plus input snapshot digest plus a zero-padded monotonic run ordinal scoped to that method and snapshot; where an external evaluator issues its own authoritative run identifier, that master-system identifier takes precedence and the composite key is retained as a secondary key.", "source_refs": [ "SRC-071", "SRC-074", "SRC-079" ] } ], "inline_only_rationale": null } ] }, { "id": "dep-graph-result-semantics", "name": "Result-type semantics", "description": "The declared meaning of each derived result class: path results and their restrictors, cycles and strongly connected groups, and reachability with the criticality measures built on it.", "source_refs": [ "SRC-072", "SRC-074", "SRC-077", "SRC-078", "SRC-079" ], "findings": [ { "id": "dep-graph-path-semantics", "name": "Path results, path restrictors and alternative paths", "description": "A path result is uninterpretable until its restrictor is declared. ISO/IEC 39075 fixes the distinctions normatively with walk, trail, acyclic and simple restrictors controlling whether nodes or edges may repeat, alongside match modes and path search. A path result must therefore state its restrictor, direction, depth or hop bound and what happened at that bound, and whether it claims all paths, shortest paths, k paths or a single witness. Alternative-path counts are only meaningful with a declared disjointness criterion, which is the success-path dual of the cut-set view in reliability modelling.", "source_refs": [ "SRC-074", "SRC-078", "SRC-079" ], "questions": [ { "id": "dep-graph-q-path-mode", "text": "Which path restrictor governs the result: walk, trail, acyclic or simple?", "kind": "definition", "answer_data": [ "Restrictor code aligned to the GQL path restrictor vocabulary", "Statement of whether repeated nodes and repeated edges are permitted", "Default restrictor when the consumer does not specify one" ] }, { "id": "dep-graph-q-path-bounds", "text": "What depth or hop bound and traversal direction were applied, and what happened at the bound?", "kind": "constraint", "answer_data": [ "Maximum hop or depth bound and traversal direction", "Truncation indicator distinguishing exhausted search from bound-limited search", "Count of frontier nodes left unexpanded at the bound" ] }, { "id": "dep-graph-q-path-selection", "text": "Does the result claim all paths, shortest paths, k paths, or a single witness path?", "kind": "classification", "answer_data": [ "Selection mode code and, for k paths, the value of k", "Cost or weight function used for shortest-path selection, if any", "Explicit statement that a witness path does not imply the absence of others" ] }, { "id": "dep-graph-q-alternative-paths", "text": "How many node-disjoint or edge-disjoint alternative paths exist between the two endpoints?", "kind": "measurement", "answer_data": [ "Disjointness criterion applied (node-disjoint, edge-disjoint or none)", "Count of alternative paths found and whether the search was exhaustive", "Reference to the method used, since alternative-path counting is method-sensitive" ] }, { "id": "dep-graph-q-path-identity", "text": "How is an individual path addressed and compared across runs?", "kind": "identity", "answer_data": [ "Ordered edge-key sequence as the path's natural key", "Digest over that sequence for compact addressing", "Comparison rule when a path is stable but its constituent edges have been superseded" ] } ], "data_elements": [ { "id": "dep-graph-de-path-mode", "name": "Path restrictor", "description": "Declared restrictor: walk, trail, acyclic or simple.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-074" ] }, { "id": "dep-graph-de-path-depth-bound", "name": "Depth or hop bound", "description": "Maximum traversal depth applied, with a truncation indicator.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-074", "SRC-079" ] }, { "id": "dep-graph-de-path-selection", "name": "Path selection mode", "description": "Whether the result claims all, shortest, k-shortest or any single path.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-074" ] }, { "id": "dep-graph-de-path-edge-sequence", "name": "Path edge sequence", "description": "Ordered sequence of edge keys constituting the path, serving as its natural key.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-074", "SRC-013" ] }, { "id": "dep-graph-de-path-disjointness", "name": "Alternative-path disjointness criterion", "description": "Node-disjoint, edge-disjoint or none, governing how alternative paths were counted.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-078" ] } ], "artifacts": [ { "id": "dep-graph-art-path-result-set", "name": "Path result set", "description": "The enumerated paths returned by one analysis run, each with its ordered edge sequence and digest, bound to the run descriptor and carrying the restrictor, bound, selection mode, truncation state and disjointness criterion that define what the set claims.", "media_or_form": [ "result set record, format-neutral", "ordered edge-key sequences with per-path digests", "projection to a GQL path result or a property-graph path object" ], "serial": true, "identity_strategy": "Analysis run descriptor identifier plus a zero-padded ordinal for the result set, with each path addressed by the digest of its ordered edge-key sequence; no date component in any identifier.", "source_refs": [ "SRC-074", "SRC-078" ] } ], "inline_only_rationale": null }, { "id": "dep-graph-cyclicity-and-components", "name": "Cycles, strongly connected groups and closure safety", "description": "Directed dependency graphs are not reliably acyclic. A strongly connected component is a maximal set of nodes with a directed path between every pair, and its presence changes what may be claimed: unbounded transitive closure over a cycle does not terminate, topological ordering is undefined inside a component, and shortest-path depth claims must state their restrictor. This finding records component membership, cycle witnesses, the acyclic condensation where computed, and an explicit closure-safety marker stating whether transitive or ordering claims over the analysed subgraph are sound.", "source_refs": [ "SRC-071", "SRC-072", "SRC-074", "SRC-079" ], "questions": [ { "id": "dep-graph-q-cycle-presence", "text": "Does the analysed subgraph contain directed cycles, and which edges witness them?", "kind": "state", "answer_data": [ "Boolean cyclicity result for the analysed subgraph under the declared edge filter", "One or more witness cycles as ordered edge-key sequences", "Whether cycle enumeration was exhaustive or bounded" ] }, { "id": "dep-graph-q-scc-grouping", "text": "Which nodes form strongly connected groups, and how is each group addressed?", "kind": "relationship", "answer_data": [ "Component assignment mapping each node to a component identifier", "Component identity strategy independent of any arbitrarily chosen representative node", "Component size distribution and the count of non-trivial components" ] }, { "id": "dep-graph-q-closure-safety", "text": "How do detected cycles constrain transitive closure, ordering and depth claims?", "kind": "constraint", "answer_data": [ "Closure-safety marker stating whether unbounded transitive claims are sound", "Mandatory depth bound or component-collapse strategy where cycles are present", "Explicit statement that topological ordering is undefined within a non-trivial component" ] }, { "id": "dep-graph-q-condensation-use", "text": "Is the acyclic condensation of the graph recorded, and how does it relate to the original asserted edges?", "kind": "composition", "answer_data": [ "Reference to the condensation projection and its own run descriptor", "Mapping from each condensation node back to its member node set", "Rule that condensation edges are derived, never asserted, and carry derived modality" ] } ], "data_elements": [ { "id": "dep-graph-de-component-id", "name": "Component identifier", "description": "Identifier of a strongly connected group, assigned so it does not depend on an arbitrary representative node.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-079" ] }, { "id": "dep-graph-de-component-membership", "name": "Component membership", "description": "Mapping of node references to component identifiers for the analysed subgraph.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-079" ] }, { "id": "dep-graph-de-cycle-witness", "name": "Cycle witness", "description": "Ordered edge-key sequence demonstrating a directed cycle.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-074" ] }, { "id": "dep-graph-de-condensation-ref", "name": "Condensation reference", "description": "Reference to the acyclic condensation projection derived from the component assignment.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-079" ] }, { "id": "dep-graph-de-closure-safety-flag", "name": "Closure safety marker", "description": "Whether transitive closure and ordering claims over the analysed subgraph are sound given detected cycles and declared bounds.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-071", "SRC-072" ] } ], "artifacts": [ { "id": "dep-graph-art-component-assignment-set", "name": "Component and cycle result set", "description": "The component assignment produced by one run, with cycle witnesses, component size statistics, the closure-safety marker and an optional condensation reference, bound to its run descriptor and snapshot digest.", "media_or_form": [ "result set record, format-neutral", "node-to-component assignment table", "derived condensation graph projection referenced by identifier" ], "serial": true, "identity_strategy": "Analysis run descriptor identifier plus a zero-padded result ordinal; component identifiers are minted per run as ULIDs and mapped to their member sets, so component identity is never silently reused across snapshots.", "source_refs": [ "SRC-079", "SRC-072" ] } ], "inline_only_rationale": null }, { "id": "dep-graph-reachability-and-criticality", "name": "Reachability, negative claims, fan-in, fan-out and cut sets", "description": "The impact answer itself: the set reachable from a seed under the declared licence, modality and temporal filters, together with the structural measures built on that traversal - fan-in and fan-out degree, minimal cut sets whose removal disconnects a seed from a target, and the count of surviving alternative paths. Fault tree analysis supplies the cut-set vocabulary and the discipline of identifying assumptions and event boundaries explicitly; reliability block diagrams supply the dual success-path view. The controlling rule is asymmetric: a positive reachability claim needs only the traversal record, while any negative claim - not reachable, not impacted, no dependency - additionally requires a resolvable completeness declaration with the closed-world flag covering the queried scope.", "source_refs": [ "SRC-014", "SRC-073", "SRC-075", "SRC-077", "SRC-078" ], "questions": [ { "id": "dep-graph-q-reachability-set", "text": "Which nodes are reachable from the seed under the declared licence, modality and temporal filters?", "kind": "relationship", "answer_data": [ "Reachable node set with, for each node, at least one witness path or hop distance", "The seed set and traversal direction that produced it", "Counts of edges traversed, suppressed by exclusion and unmatched by any licence profile" ] }, { "id": "dep-graph-q-negative-claim-basis", "text": "On what basis may this result state that a node is not reachable or not impacted?", "kind": "validation", "answer_data": [ "Identifier of the completeness declaration covering the queried scope, with its closed-world flag set", "Explicit downgrade to 'not known to be reachable' where the declaration is absent, incomplete or stale", "Record of which known unknowns bound the strength of the claim" ] }, { "id": "dep-graph-q-fan-measures", "text": "What are the fan-in and fan-out degrees of the node, and over which edge selection were they counted?", "kind": "measurement", "answer_data": [ "In-degree and out-degree counts with the edge filter and licence profile they were computed under", "Whether multi-edges, self-loops and suppressed edges were counted or excluded", "Whether the count is over asserted edges only or includes derived edges" ] }, { "id": "dep-graph-q-cut-set", "text": "Which minimal sets of nodes or edges, if removed, disconnect the seed from the target?", "kind": "decision", "answer_data": [ "Enumerated minimal cut sets with their cardinality, and identification of any single points of failure", "Whether enumeration was exhaustive or bounded, and the bound applied", "Method reference and the stated assumptions and event boundaries of the analysis" ] }, { "id": "dep-graph-q-hypothetical-impact", "text": "How is a what-if impact answer over hypothetical or removed edges kept separate from the actual-state answer?", "kind": "exception", "answer_data": [ "Scenario identifier and the edge additions or removals it applies", "Mandatory labelling of the result as hypothetical, including in any downstream export", "Prohibition on citing a hypothetical result as evidence of the actual state" ] } ], "data_elements": [ { "id": "dep-graph-de-reachability-set", "name": "Reachability set", "description": "Nodes reachable from the seed under the declared filters, each with a witness path or hop distance.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-074", "SRC-077" ] }, { "id": "dep-graph-de-negative-claim-flag", "name": "Negative claim marker", "description": "Whether the result asserts non-reachability, and the identifier of the completeness declaration that licenses it.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-014", "SRC-073", "SRC-075" ] }, { "id": "dep-graph-de-fan-in", "name": "Fan-in degree", "description": "Count of licensed incoming edges at a node under the declared edge filter.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-077" ] }, { "id": "dep-graph-de-fan-out", "name": "Fan-out degree", "description": "Count of licensed outgoing edges at a node under the declared edge filter.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-077" ] }, { "id": "dep-graph-de-cut-set", "name": "Cut set", "description": "A minimal set of nodes or edges whose removal disconnects the seed from the target, with cardinality and exhaustiveness marker.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-077", "SRC-078" ] }, { "id": "dep-graph-de-alternative-path-count", "name": "Surviving alternative path count", "description": "Number of disjoint alternative paths remaining between seed and target under the declared disjointness criterion.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-078" ] } ], "artifacts": [ { "id": "dep-graph-art-impact-and-criticality-report", "name": "Impact and criticality result set", "description": "The released impact answer for one run: reachability set with witness paths, suppressed and unmatched edge counts, fan-in and fan-out measures, enumerated cut sets and surviving alternative-path counts, with every negative claim carrying an inline reference to the completeness declaration that licenses it and every hypothetical component labelled as such.", "media_or_form": [ "result set record, format-neutral", "impact report with a mandatory completeness and assumptions header", "criticality measure table keyed by node reference" ], "serial": true, "identity_strategy": "Analysis run descriptor identifier plus a zero-padded result ordinal; node and edge entries are addressed by the endpoint references and edge keys owned by the fact base, never by report-local sequence numbers.", "source_refs": [ "SRC-014", "SRC-077", "SRC-078" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "dep-impact-scenario-frame", "name": "Impact scenario framing and propagation inputs", "description": "Everything that must be fixed before an impact result can exist: what is being analysed, as which versioned scenario, against which baseline, in which analysis mode and over which horizon, and under which propagation assumptions. All of it is input-side and none of it asserts an outcome.", "rationale": "Impact statements are only falsifiable if their inputs are separable and citable. Statutory impact assessment requires a described baseline and its likely evolution without the project, described alternatives, and a stated forecasting method before effects may be reported; scenario-based business impact analysis requires severe but plausible scenarios to be declared. Grouping trigger, scenario, baseline, frame and propagation assumptions in one bundle keeps them versionable and reviewable independently of results, and keeps the dependency graph itself firmly outside as a cited input.", "source_refs": [ "SRC-080", "SRC-083", "SRC-085", "SRC-081" ], "layers": [ { "id": "dep-impact-input-layer", "name": "Trigger and scenario inputs", "description": "Identifies the analysed trigger as a reference to a record owned elsewhere, and fixes the scenario as a versioned, independently citable object carrying its assumptions and its cited dependency-graph snapshot.", "source_refs": [ "SRC-083", "SRC-012", "SRC-081", "SRC-080" ], "findings": [ { "id": "dep-impact-change-event-input", "name": "Change, event and hypothetical trigger input", "description": "States exactly what is being analysed and of what kind: a proposed change not yet made, an event that occurred, a hypothetical stress condition, or a standing condition. The trigger is always carried as a resolvable reference to its owning record plus the impact-specific seed parameters - which entities it acts on and what property of each is altered - so that the analysis never becomes a second master record for the change or the incident.", "source_refs": [ "SRC-083", "SRC-081", "SRC-012", "SRC-080" ], "questions": [ { "id": "dep-impact-q-trigger-kind", "text": "What exactly is the analysed trigger - a proposed change, an occurred event, a hypothetical stress condition or a standing condition - and how is that distinction recorded rather than inferred?", "kind": "definition", "answer_data": [ "Trigger kind code from a bound code list (proposed-change, occurred-event, hypothetical-condition, standing-condition)", "Narrative trigger statement in the scenario header", "Code list identifier and version" ] }, { "id": "dep-impact-q-trigger-identity", "text": "Which authoritative record identifies the trigger, and which identifier resolves it in its owning system?", "kind": "identity", "answer_data": [ "Master-system identifier of the change, incident or advisory record", "Owning system or registry reference", "Identifier scheme name and version", "Resolution status flag when the reference cannot be dereferenced" ] }, { "id": "dep-impact-q-trigger-locus", "text": "Which entities does the trigger act on directly, and which property or capability of each is altered, degraded or lost?", "kind": "relationship", "answer_data": [ "Seed entity references resolved against an asset or configuration-item registry", "Altered property or capability name", "Alteration type code (added, removed, degraded, replaced, unavailable, reconfigured)" ] }, { "id": "dep-impact-q-trigger-magnitude", "text": "What magnitude, duration or severity is assumed for the trigger itself, and is that assumption stipulated, measured or inherited from the owning record?", "kind": "measurement", "answer_data": [ "Assumed magnitude quantity with a referenced unit and scale", "Assumed trigger duration", "Assumption provenance code (stipulated, measured, inherited)" ] } ], "data_elements": [ { "id": "dep-impact-de-trigger-ref", "name": "Trigger record reference", "description": "Resolvable reference to the change, event, advisory or condition record owned by another model, which this scenario analyses.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-083", "SRC-012" ] }, { "id": "dep-impact-de-trigger-kind", "name": "Trigger kind", "description": "Code distinguishing a proposed change from an occurred event, a hypothetical condition and a standing condition; determines whether the analysis is necessarily prospective.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-081", "SRC-083" ] }, { "id": "dep-impact-de-seed-entity-ref", "name": "Seed entity reference", "description": "Entity on which the trigger acts directly and from which traversal begins; resolved against the adopting Dimension's registry, never defined here.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-012", "SRC-083" ] }, { "id": "dep-impact-de-trigger-alteration", "name": "Trigger alteration descriptor", "description": "Per seed entity, the property or capability affected and the alteration type, expressed independently of any downstream consequence.", "value_kind": "object", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-081", "SRC-086" ] }, { "id": "dep-impact-de-trigger-magnitude-assumption", "name": "Trigger magnitude assumption", "description": "Assumed size, severity or duration of the trigger with its provenance code, kept separate from any assessed effect magnitude.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-083", "SRC-081" ] } ], "artifacts": [], "inline_only_rationale": "The trigger is not produced by this model. A proposed change, an incident record or a vulnerability advisory has its own identity, approval state, lifecycle and system of record in a change, event or advisory model. This finding therefore carries only a resolvable reference, a trigger-kind classification and the impact-specific seed parameters as inline fields on the scenario header. Materialising a local trigger artifact would create a second, divergent master record and would import the referenced model's lifecycle and approval semantics across a boundary this model must not cross." }, { "id": "dep-impact-scenario-definition", "name": "Scenario identity, version and declared input set", "description": "Fixes the impact scenario as a versioned object that can be cited, compared and refuted: its identifier and version, the dependency-graph snapshot and snapshot time it was evaluated against, its stated assumptions and parameters, the alternatives it is one of, and whether it is draft, released or superseded.", "source_refs": [ "SRC-012", "SRC-080", "SRC-084", "SRC-083" ], "questions": [ { "id": "dep-impact-q-scenario-identity", "text": "Which identifier and version distinguish this scenario from every other scenario evaluated for the same trigger?", "kind": "identity", "answer_data": [ "Stable scenario identifier following the identity priority order", "Monotonic version label that encodes no date", "Scenario title as a non-identifying label" ] }, { "id": "dep-impact-q-scenario-snapshot", "text": "Against which dependency-graph snapshot, taken at which snapshot time, was this scenario evaluated?", "kind": "provenance", "answer_data": [ "Graph snapshot reference owned by the dependency-assertion area", "Snapshot time in RFC 3339 with an explicit offset", "Snapshot immutability or content-hash attestation" ] }, { "id": "dep-impact-q-scenario-inputs", "text": "Which stated assumptions, parameters and option choices together constitute the scenario's declared input set?", "kind": "composition", "answer_data": [ "Named assumption entries with values and rationale", "Referenced propagation profile version", "Referenced baseline statement version", "Bound code-list identifiers and versions" ] }, { "id": "dep-impact-q-scenario-versioning", "text": "When a scenario input changes, does the scenario mutate in place or is a superseding version issued, and what happens to results already derived from it?", "kind": "lifecycle", "answer_data": [ "Scenario status code (draft, released, superseded, withdrawn)", "Supersession link to predecessor and successor versions", "Derived-result invalidation or re-derivation flag" ] }, { "id": "dep-impact-q-scenario-alternatives", "text": "Which other scenarios are declared as alternatives or comparators for the same trigger, and on what dimension do they differ?", "kind": "relationship", "answer_data": [ "Alternative scenario references", "Differentiating parameter name and value per alternative", "Comparator role code (do-nothing, preferred option, sensitivity variant)" ] } ], "data_elements": [ { "id": "dep-impact-de-scenario-id", "name": "Scenario identifier", "description": "Stable identifier for the scenario, constant across versions and containing no date, status or severity component.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-012" ] }, { "id": "dep-impact-de-scenario-version", "name": "Scenario version", "description": "Monotonic integer or semantic version of the scenario; never restarts and never encodes a date.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-012" ] }, { "id": "dep-impact-de-graph-snapshot-ref", "name": "Dependency-graph snapshot reference", "description": "Citation of the immutable graph snapshot, with its snapshot time, that traversal was performed against; the snapshot is owned by the dependency-assertion area.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-012", "SRC-083" ] }, { "id": "dep-impact-de-scenario-assumption", "name": "Declared scenario assumption", "description": "Named assumption or parameter with value and rationale, disclosed as part of the scenario rather than buried in a method note.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-084", "SRC-081" ] }, { "id": "dep-impact-de-alternative-scenario-ref", "name": "Alternative scenario reference", "description": "Reference to a sibling scenario representing a reasonable alternative or sensitivity variant for the same trigger.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-080", "SRC-085" ] }, { "id": "dep-impact-de-scenario-status", "name": "Scenario status", "description": "Lifecycle state of the scenario record: draft, released, superseded or withdrawn; release freezes the version.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-012" ] } ], "artifacts": [ { "id": "dep-impact-art-scenario-spec", "name": "Impact scenario specification", "description": "The released, versioned statement of one scenario: trigger reference and kind, seed entities, cited graph snapshot, referenced baseline and propagation profile versions, declared assumptions, horizon and alternatives. It is the citable object every downstream result binds to.", "media_or_form": [ "Versioned structured record, projection-neutral", "Human-readable narrative section for assumptions and rationale" ], "serial": true, "identity_strategy": "Identified by the master-system scenario identifier issued by the adopting Dimension's system of record for impact assessment; failing that by a governed identifier or IRI from a registry the Dimension has bound; failing both by a UUID or ULID minted by the Dimension and then published so that it becomes resolvable. The version is a separate monotonic component and never part of identity; no date, title or severity may be used as an identifier.", "source_refs": [ "SRC-012", "SRC-080", "SRC-084" ] } ], "inline_only_rationale": null } ] }, { "id": "dep-impact-frame-layer", "name": "Analysis frame: baseline, mode, time and scope", "description": "Establishes the comparison basis and the temporal and scope frame within which any asserted effect is meaningful, and separates prospective analysis from retrospective observation before any result is produced.", "source_refs": [ "SRC-080", "SRC-085", "SRC-084", "SRC-007" ], "findings": [ { "id": "dep-impact-counterfactual-baseline", "name": "Counterfactual baseline and comparison basis", "description": "Declares what the scenario is compared against: the current state, a projected likely evolution without the trigger, or an explicit counterfactual alternative - and whether effects are reported as differences from that baseline, as absolute end states, or both. An impact assertion without a declared baseline is not falsifiable, so 'no baseline declared' is itself a recorded, disclosable value rather than an absence.", "source_refs": [ "SRC-080", "SRC-085", "SRC-084" ], "questions": [ { "id": "dep-impact-q-baseline-basis", "text": "Against which baseline state is the scenario's effect measured, and is that baseline a static observed state or a projected evolution without the trigger?", "kind": "definition", "answer_data": [ "Baseline kind code (static-observed, projected-evolution, counterfactual-alternative, none-declared)", "Baseline state description or reference", "Projection method name where the baseline evolves" ] }, { "id": "dep-impact-q-baseline-source", "text": "Which observation, register or model produced the baseline values, and at what time were those values observed or projected?", "kind": "provenance", "answer_data": [ "Baseline source reference", "Baseline observation or projection time in RFC 3339 with an explicit offset", "Baseline author or system agent reference" ] }, { "id": "dep-impact-q-effect-expression", "text": "Is a reported effect expressed as a difference from baseline, as an absolute end state, or as both, and is that choice uniform across the result set?", "kind": "measurement", "answer_data": [ "Effect expression mode code (delta, absolute, both)", "Uniformity flag with per-member override where mixed", "Referenced scale for the expressed value" ] }, { "id": "dep-impact-q-baseline-revision", "text": "What happens to results already published when the baseline is revised or found to be wrong?", "kind": "lifecycle", "answer_data": [ "Baseline version and supersession link", "Re-derivation or invalidation rule for dependent results", "Erratum record reference" ] }, { "id": "dep-impact-q-baseline-absent", "text": "Under what conditions may an assessment be issued with no declared baseline, and how is that limitation surfaced to a consumer?", "kind": "exception", "answer_data": [ "Permitted no-baseline condition codes", "Mandatory limitation text in the disclosure artifact", "Downgraded claim status forced by the absence" ] } ], "data_elements": [ { "id": "dep-impact-de-baseline-ref", "name": "Baseline statement reference", "description": "Citation of the versioned baseline statement the scenario is measured against.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-080", "SRC-085" ] }, { "id": "dep-impact-de-baseline-kind", "name": "Baseline kind", "description": "Whether the baseline is a static observed state, a projected evolution without the trigger, an explicit counterfactual alternative, or explicitly none-declared.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-080" ] }, { "id": "dep-impact-de-baseline-observation-time", "name": "Baseline observation or projection time", "description": "When the baseline values were observed or projected, recorded separately from analysis time and trigger time.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-007", "SRC-086" ] }, { "id": "dep-impact-de-effect-expression-mode", "name": "Effect expression mode", "description": "Whether asserted effects are deltas from baseline, absolute end states or both.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-080", "SRC-085" ] }, { "id": "dep-impact-de-baseline-revision-ref", "name": "Baseline revision link", "description": "Link from a baseline version to its predecessor or successor, used to determine which dependent results must be re-derived.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-012", "SRC-080" ] } ], "artifacts": [ { "id": "dep-impact-art-baseline-statement", "name": "Baseline and comparison-basis statement", "description": "The versioned description of the state against which effects are measured, including its source, observation or projection time, projection method where the baseline evolves, and any declared limitation such as a missing or partial baseline.", "media_or_form": [ "Versioned structured record, projection-neutral", "Human-readable narrative description of the baseline state and its likely evolution" ], "serial": true, "identity_strategy": "Identified by the master-system baseline identifier where the Dimension operates a baseline or state-snapshot system of record; otherwise by a governed identifier from a bound registry; otherwise by a Dimension-minted UUID or ULID. Version is a separate monotonic component; observation date is metadata and never an identifier.", "source_refs": [ "SRC-080", "SRC-085", "SRC-084" ] } ], "inline_only_rationale": null }, { "id": "dep-impact-analysis-mode-and-time", "name": "Analysis mode, time separation and effect horizon", "description": "Separates prospective analysis from retrospective observation and from reconciliation of the two; records analysis time, trigger time, expected effect time and observation or ingestion time as distinct values; and bounds the horizon over which effects are in scope, including short, medium and long-term banding, permanence and reversion time, plus the organisational, contractual and geographic scope of the analysis.", "source_refs": [ "SRC-007", "SRC-080", "SRC-084", "SRC-033", "SRC-086" ], "questions": [ { "id": "dep-impact-q-analysis-mode", "text": "Is this record a prospective analysis, a retrospective observation or a reconciliation of the two, and how is that mode declared rather than left to be inferred from timestamps?", "kind": "classification", "answer_data": [ "Analysis mode code (prospective, retrospective, reconciliation)", "Rule forbidding inference of mode from timestamp ordering", "Mode-specific mandatory field set" ] }, { "id": "dep-impact-q-time-separation", "text": "Are the analysis time, the trigger time, the expected or observed effect time and the observation or ingestion time recorded as four separate values?", "kind": "temporal", "answer_data": [ "Analysis time in RFC 3339 with an explicit offset", "Trigger occurrence or scheduled time", "Effect onset time, expected or observed", "Observation or ingestion time recorded by the receiving system" ] }, { "id": "dep-impact-q-horizon-bands", "text": "Over what horizon are effects in scope, and how does this Dimension define its short-, medium- and long-term bands?", "kind": "constraint", "answer_data": [ "Horizon start and end, or a duration from trigger time", "Named horizon bands with their boundaries as declared by the Dimension", "Statement that effects beyond the horizon are out of scope rather than absent" ] }, { "id": "dep-impact-q-effect-permanence", "text": "Is each expected effect classified as temporary or permanent, and is a recovery or reversion time recorded where it is temporary?", "kind": "state", "answer_data": [ "Permanence code (temporary, permanent, unknown)", "Expected recovery or reversion time or duration", "Reversibility condition text" ] }, { "id": "dep-impact-q-analysis-scope", "text": "Which organisational, contractual or geographic scope bounds this analysis, and what is explicitly outside it?", "kind": "spatial", "answer_data": [ "Organisational or legal-entity scope descriptor", "Contractual or supplier scope descriptor", "Coarse geographic scope descriptor with a note that precise geometry is delegated", "Explicit out-of-scope statement" ] } ], "data_elements": [ { "id": "dep-impact-de-analysis-mode", "name": "Analysis mode", "description": "Declares whether the record is a prospective analysis, a retrospective observation or a reconciliation; determines which fields are mandatory and which claim statuses are permitted.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-086", "SRC-081" ] }, { "id": "dep-impact-de-analysis-time", "name": "Analysis time", "description": "When the assessment was computed or authored, distinct from trigger, effect and ingestion times.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-007", "SRC-001" ] }, { "id": "dep-impact-de-trigger-time", "name": "Trigger occurrence or scheduled time", "description": "When the trigger occurred, or is scheduled to occur for a prospective change; absent for a purely hypothetical condition.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-001" ] }, { "id": "dep-impact-de-effect-horizon", "name": "Effect horizon", "description": "The bounded interval or duration from the trigger within which effects are considered; expressible as an interval with beginning and end.", "value_kind": "duration", "cardinality": "1", "required": true, "source_refs": [ "SRC-033", "SRC-080", "SRC-084" ] }, { "id": "dep-impact-de-horizon-band", "name": "Horizon band", "description": "Dimension-declared short, medium or long-term band into which an effect falls; no cited source fixes the boundaries universally.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-084", "SRC-080" ] }, { "id": "dep-impact-de-effect-permanence", "name": "Effect permanence", "description": "Whether an expected effect is temporary, permanent or of unknown permanence, with any recovery or reversion time.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-080" ] }, { "id": "dep-impact-de-analysis-scope", "name": "Analysis scope descriptor", "description": "Coarse organisational, contractual and geographic bounds of the analysis, with an explicit statement of what falls outside; precise geometry is delegated to a geospatial model.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-083", "SRC-080" ] } ], "artifacts": [], "inline_only_rationale": "Analysis mode, the four separated time values, horizon bands, permanence and scope bounds are typed scalar fields of the scenario and result headers, not separately produced deliverables. Promoting them to their own artifact would create a second place where the analysis timeline can drift from the scenario specification and the trace record that already carry them, and would invite a mode or horizon to be revised without a corresponding scenario version. The substantive documents that carry these values are the scenario specification and the impact trace record, both declared in adjacent findings; interval and Allen-relation expression is an optional external alignment rather than a locally stored object." } ] }, { "id": "dep-impact-propagation-layer", "name": "Propagation assumptions", "description": "Declares, before any traversal is run, how effect is assumed to move across dependency edges - including where it is asserted not to move at all - so that the phrase 'indirect effect' has a defined and checkable meaning.", "source_refs": [ "SRC-012", "SRC-082", "SRC-080", "SRC-081" ], "findings": [ { "id": "dep-impact-propagation-assumptions", "name": "Propagation rules, traversal limits and non-propagating dependencies", "description": "The reusable, versioned rule set governing traversal: which declared edge types propagate effect and in which direction, which are asserted non-propagating, the depth limit and stop conditions, which steps are conditional on a stated predicate, and how cycles, redundancy, failover and aggregation edges are handled. Direct versus indirect effect is defined here in traversal terms and explicitly distinguished from domain notions of secondary or cumulative effect.", "source_refs": [ "SRC-012", "SRC-082", "SRC-080", "SRC-081" ], "questions": [ { "id": "dep-impact-q-edge-propagation", "text": "Which declared dependency edge types are treated as propagating for this scenario, and which are declared non-propagating with what justification?", "kind": "classification", "answer_data": [ "Propagating edge type codes selected from the dependency-assertion vocabulary", "Non-propagating edge type codes with a justification code per exclusion", "Bound edge-type code list identifier and version" ] }, { "id": "dep-impact-q-traversal-limits", "text": "In which direction is traversal performed, and at what depth or under which stop condition does it terminate?", "kind": "constraint", "answer_data": [ "Traversal direction code (upstream, downstream, both)", "Maximum depth as an integer, or an explicit unbounded flag", "Stop condition predicates such as trust boundary, ownership change or attenuation threshold" ] }, { "id": "dep-impact-q-direct-indirect", "text": "How is a direct effect distinguished from an indirect effect, and does that distinction rest on traversal distance or on a domain-causal claim?", "kind": "definition", "answer_data": [ "Definition basis code (traversal-distance, domain-causal, both-declared)", "Distance threshold at which an effect becomes indirect", "Explicit statement that the traversal sense does not equal the statutory sense of indirect, secondary or cumulative" ] }, { "id": "dep-impact-q-conditional-steps", "text": "Which propagation steps are conditional, and on which predicate, configuration or state does each condition depend?", "kind": "requirement", "answer_data": [ "Conditional step identifier and the edge it qualifies", "Predicate expression or narrative condition", "Evaluation status code (condition-holds, condition-fails, condition-unevaluated)" ] }, { "id": "dep-impact-q-cycle-handling", "text": "How are cycles, redundancy, failover and aggregation edges handled so that they neither inflate nor silently suppress the affected set?", "kind": "process", "answer_data": [ "Cycle handling rule code (visit-once, bounded-revisit, reject)", "Redundancy and failover treatment rule with the assumed availability of the alternate path", "Aggregation rule stating whether a node reached by several paths is counted once with all paths retained" ] } ], "data_elements": [ { "id": "dep-impact-de-propagation-profile-ref", "name": "Propagation profile reference", "description": "Citation of the versioned traversal rule set applied by this scenario; profiles are reusable across scenarios.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-012", "SRC-082" ] }, { "id": "dep-impact-de-propagating-edge-type", "name": "Propagating edge type", "description": "Edge type code, drawn from the dependency-assertion vocabulary, across which effect is assumed to travel in this scenario.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-012" ] }, { "id": "dep-impact-de-non-propagating-edge-type", "name": "Non-propagating edge type", "description": "Edge type code explicitly asserted not to carry effect in this scenario, with a justification code; preserves the negative assertion instead of leaving it implicit.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-082", "SRC-012" ] }, { "id": "dep-impact-de-traversal-direction", "name": "Traversal direction", "description": "Whether traversal follows dependency edges upstream, downstream or in both directions from the seed entities.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-012" ] }, { "id": "dep-impact-de-traversal-depth-limit", "name": "Traversal depth limit", "description": "Maximum edge count from a seed entity at which traversal stops; an explicit unbounded flag is permitted but must be declared.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-012", "SRC-081" ] }, { "id": "dep-impact-de-stop-condition", "name": "Traversal stop condition", "description": "Predicate other than depth that terminates traversal along a branch, such as an ownership or trust boundary or a magnitude attenuation threshold.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-081", "SRC-083" ] }, { "id": "dep-impact-de-conditional-predicate", "name": "Conditional propagation predicate", "description": "Condition under which a specific propagation step holds, together with whether the condition was evaluated, held or failed.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-082", "SRC-012" ] }, { "id": "dep-impact-de-cycle-handling-rule", "name": "Cycle and multiplicity handling rule", "description": "Rule governing revisits, redundancy and failover paths, and multi-path arrival at one node, so that set size is reproducible.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-012", "SRC-080" ] } ], "artifacts": [ { "id": "dep-impact-art-propagation-profile", "name": "Propagation profile", "description": "A versioned, reusable traversal rule set naming propagating and non-propagating edge types, direction, depth and stop conditions, conditional predicates and cycle handling, together with the declared basis for calling an effect direct or indirect.", "media_or_form": [ "Versioned structured rule set, projection-neutral", "Human-readable rationale for each propagation and non-propagation assertion" ], "serial": true, "identity_strategy": "Identified by the master-system profile identifier where the Dimension maintains a profile registry; otherwise by a governed identifier from a bound registry; otherwise by a Dimension-minted UUID or ULID. Profiles are versioned monotonically and a profile name, edge-type list or effective date may not serve as identity.", "source_refs": [ "SRC-012", "SRC-082", "SRC-080" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "dep-impact-result-assurance", "name": "Impact results, traceability and epistemic status", "description": "The output side: which entities the scenario reaches and with what explicitly recorded status, how each effect is characterised, which paths and exclusions produced the result, and what claim status, uncertainty and limitations must accompany it before it may be published or consumed.", "rationale": "A result is only usable if a reviewer can reconstruct it and if the reader can tell what kind of statement it is. Vulnerability exchange practice establishes that a negative determination is a first-class published statement carrying a justification, not an omission. Risk assessment guidance requires assumptions, constraints and confidence to be documented alongside results, statutory impact assessment requires disclosure of forecasting methods, difficulties and main uncertainties, and exposure assessment practice keeps exposure formally distinct from effect. Grouping results with their traceability and epistemic qualification prevents an exposure inference from being read as a causal finding or an authorisation.", "source_refs": [ "SRC-082", "SRC-081", "SRC-080", "SRC-086", "SRC-001" ], "layers": [ { "id": "dep-impact-outcome-layer", "name": "Affected set and effect characterisation", "description": "Enumerates the entities the scenario reaches with an explicit per-entity status and justification, and characterises each asserted effect by kind, polarity, magnitude, ordering and declared accumulation.", "source_refs": [ "SRC-082", "SRC-012", "SRC-080", "SRC-081", "SRC-086" ], "findings": [ { "id": "dep-impact-affected-set-status", "name": "Affected-set membership and per-entity status", "description": "The enumerated set of entities reached by the scenario, each carrying an explicit status - affected, not affected, unknown or under investigation, conditionally affected, or reached but not propagating - with a justification code and determination time. Absence from the set never means 'not affected'; negative, unknown and conditional determinations are published as members so that a shorter set cannot masquerade as a smaller impact.", "source_refs": [ "SRC-082", "SRC-012", "SRC-081", "SRC-083", "SRC-086" ], "questions": [ { "id": "dep-impact-q-member-identity", "text": "Which entities are members of the affected set, and by which registry identifier is each one resolved?", "kind": "identity", "answer_data": [ "Affected entity reference resolved against the asset or configuration-item registry", "Identifier scheme and version", "Unresolvable-reference marker where the registry no longer resolves the entity" ] }, { "id": "dep-impact-q-member-status", "text": "What status does each member carry, and is a not-affected determination recorded explicitly rather than by absence from the set?", "kind": "state", "answer_data": [ "Status code (affected, not-affected, under-investigation, conditionally-affected, reached-not-propagating)", "Rule that absence is not equivalent to not-affected", "Status determination time in RFC 3339 with an explicit offset" ] }, { "id": "dep-impact-q-negative-justification", "text": "What justification supports a not-affected or reached-but-not-propagating determination for a given member?", "kind": "evidence", "answer_data": [ "Justification code from the bound vocabulary", "Narrative impact statement where no justification code applies", "Reference to the propagation profile rule or conditional predicate relied on" ] }, { "id": "dep-impact-q-exposure-vs-effect", "text": "How is 'exposed through a dependency' distinguished from 'assessed as affected' for the same member?", "kind": "classification", "answer_data": [ "Exposure flag set by traversal reachability alone", "Separate assessed-effect flag set only by an assessor determination", "Rule forbidding automatic promotion of exposure to effect" ] }, { "id": "dep-impact-q-unknown-carryforward", "text": "How are members whose status is unknown or still under investigation carried forward across scenario versions instead of being dropped?", "kind": "exception", "answer_data": [ "Carry-forward rule for under-investigation members", "Re-determination due time or review trigger", "Count of suppressed or unresolved members reported with every filtered read" ] } ], "data_elements": [ { "id": "dep-impact-de-affected-entity-ref", "name": "Affected-set member reference", "description": "Reference to an entity reached by traversal, resolved against the adopting Dimension's registry; the registry, not this model, owns the entity's identity and lifecycle.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-012", "SRC-083" ] }, { "id": "dep-impact-de-affected-status", "name": "Affected status", "description": "Explicit per-member status covering affected, not-affected, under-investigation, conditionally-affected and reached-not-propagating; unknown codes must be treated as unknown, never as not-affected.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-082", "SRC-012" ] }, { "id": "dep-impact-de-status-justification", "name": "Status justification", "description": "Coded reason supporting a negative or non-propagating determination, mirroring the requirement that a not-affected statement carry a justification or an explanatory impact statement.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-082", "SRC-012" ] }, { "id": "dep-impact-de-status-narrative", "name": "Status impact statement", "description": "Narrative explanation required when no justification code adequately explains a negative determination.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-082" ] }, { "id": "dep-impact-de-exposure-flag", "name": "Dependency exposure flag", "description": "Records that a member was reached by traversal, held separately from any assessed effect so that reachability is never published as harm.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-086", "SRC-081" ] }, { "id": "dep-impact-de-status-determination-time", "name": "Status determination time", "description": "When the current status was determined, retained alongside prior determinations rather than overwritten.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-007", "SRC-082" ] } ], "artifacts": [ { "id": "dep-impact-art-affected-set", "name": "Affected-set register", "description": "The versioned result set listing every reached entity with its status, justification, exposure flag and determination time, bound to exactly one scenario version and one graph snapshot. Negative, unknown and conditional members are retained as first-class entries.", "media_or_form": [ "Versioned tabular or keyed result set, projection-neutral", "Per-member narrative impact statements where required" ], "serial": true, "identity_strategy": "Identified by the master-system assessment-result identifier from the Dimension's impact-assessment system of record; otherwise by a governed identifier from a bound registry such as an advisory document tracking identifier when the trigger is a published vulnerability; otherwise by a Dimension-minted UUID or ULID. Version is monotonic and separate from identity, and no determination date may be used as an identifier.", "source_refs": [ "SRC-082", "SRC-012", "SRC-081" ] } ], "inline_only_rationale": null }, { "id": "dep-impact-effect-characterization", "name": "Effect kind, polarity, magnitude, ordering and accumulation", "description": "Characterises each asserted effect on an affected member: what kind of effect on which property or capability, whether it is negative, neutral or beneficial, its magnitude on a referenced scale with a referenced unit, whether it is a first-order consequence of the trigger or arises only from another asserted effect, and whether it is declared to accumulate with effects from other triggers or scenarios.", "source_refs": [ "SRC-080", "SRC-081", "SRC-086", "SRC-083" ], "questions": [ { "id": "dep-impact-q-effect-nature", "text": "What kind of effect is asserted on this member, and on which of its properties or capabilities does it fall?", "kind": "definition", "answer_data": [ "Effect kind code (availability, capacity, correctness, cost, compliance, safety, service continuity)", "Affected property or capability name", "Narrative effect description" ] }, { "id": "dep-impact-q-effect-polarity", "text": "Is the asserted effect negative, neutral or beneficial, and can a neutral or beneficial effect be represented at all in this result set?", "kind": "classification", "answer_data": [ "Polarity code (negative, neutral, positive, mixed)", "Statement that positive and neutral effects are representable and not filtered out", "Rationale where only adverse effects are recorded" ] }, { "id": "dep-impact-q-effect-scale", "text": "On what scale and in what unit is effect magnitude expressed, and is that scale ordinal or quantitative?", "kind": "measurement", "answer_data": [ "Referenced scale identifier and version from a measurement model", "Scale type code (ordinal, interval, ratio, qualitative-band)", "Magnitude value with unit reference", "Qualitative criterion text where no quantitative measure exists" ] }, { "id": "dep-impact-q-effect-order", "text": "Which effects are first-order consequences of the trigger and which arise only from another asserted effect?", "kind": "relationship", "answer_data": [ "Effect order code (first-order, downstream)", "Reference to the antecedent effect for a downstream effect", "Traversal distance at which the effect was asserted" ] }, { "id": "dep-impact-q-effect-accumulation", "text": "Does this effect accumulate with effects from other triggers or scenarios, and is that accumulation declared rather than computed here?", "kind": "composition", "answer_data": [ "References to effects or scenarios with which accumulation is declared", "Accumulation basis code (same-entity, same-capability, same-horizon)", "Explicit statement that no aggregation arithmetic is performed by this model" ] } ], "data_elements": [ { "id": "dep-impact-de-effect-kind", "name": "Effect kind", "description": "Coded nature of the asserted effect and the property or capability it falls on.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-080", "SRC-081" ] }, { "id": "dep-impact-de-effect-polarity", "name": "Effect polarity", "description": "Whether the effect is negative, neutral, positive or mixed; deliberately broader than an adverse-harm-only framing.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-080" ] }, { "id": "dep-impact-de-effect-magnitude", "name": "Effect magnitude", "description": "Magnitude of the asserted effect as a quantity or ordinal band, always paired with a referenced scale and unit defined outside this model.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-081", "SRC-083" ] }, { "id": "dep-impact-de-effect-scale-ref", "name": "Effect scale reference", "description": "Citation of the severity or magnitude scale and its version, owned by a measurement model; comparability across Dimensions is not guaranteed by this model.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-081", "SRC-086" ] }, { "id": "dep-impact-de-effect-order", "name": "Effect order", "description": "Whether the effect is a first-order consequence of the trigger or arises only from another asserted effect, with a reference to that antecedent.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-080", "SRC-012" ] }, { "id": "dep-impact-de-cumulative-with-ref", "name": "Declared accumulation link", "description": "Reference to another effect or scenario with which this effect is declared to accumulate; the declaration is recorded, no arithmetic is performed.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-080", "SRC-085" ] } ], "artifacts": [], "inline_only_rationale": "Effect characterisation is a set of typed attributes attached to each entry of the affected-set register, which is already declared as the artifact in the adjacent finding. Emitting a separate effect document would split one row of a single result set across two artifacts with independent version histories, allowing a magnitude to be revised without a corresponding change to the status it qualifies. The scales, units and severity vocabularies themselves are referenced from a measurement model rather than defined or stored here, so nothing in this finding is locally authored content that would justify its own serial artifact." } ] }, { "id": "dep-impact-assurance-layer", "name": "Traceability, disclosure and epistemic status", "description": "Makes a published result reviewable and correctly readable: the paths and exclusions that produced it, the completeness of the traversal, and the claim status, uncertainty and limitations without which it must not be released or consumed.", "source_refs": [ "SRC-001", "SRC-080", "SRC-081", "SRC-086", "SRC-082" ], "findings": [ { "id": "dep-impact-path-trace-and-exclusions", "name": "Traced paths, excluded edges and traversal completeness", "description": "For each asserted member, the ordered sequence of dependency edges connecting the trigger to it, together with the edges, nodes and subgraphs excluded from traversal with a reason code, and a completeness code stating whether the traversal was exhaustive over the cited snapshot, truncated by a declared limit, limited by missing data, or sampled. This is what allows a reviewer to re-execute and refute the result.", "source_refs": [ "SRC-001", "SRC-080", "SRC-012", "SRC-085" ], "questions": [ { "id": "dep-impact-q-path-sequence", "text": "Which ordered sequence of dependency edges connects the trigger to each asserted affected member?", "kind": "provenance", "answer_data": [ "Ordered list of edge references with their edge types", "Path length and the seed entity it originates from", "All alternative paths retained where a member is reached more than once" ] }, { "id": "dep-impact-q-excluded-edges", "text": "Which edges, nodes or subgraphs were excluded from traversal, and under which exclusion reason code?", "kind": "constraint", "answer_data": [ "Excluded edge or node references", "Exclusion reason code (declared non-propagating, depth limit, stop condition, condition failed, data missing, access restricted, out of analysis scope)", "Count of exclusions by reason" ] }, { "id": "dep-impact-q-traversal-completeness", "text": "Was the traversal exhaustive over the cited snapshot, truncated by a declared limit, partial because of missing data, or sampled?", "kind": "quality", "answer_data": [ "Completeness code (exhaustive, depth-truncated, data-limited, sampled, access-limited)", "Description of unreachable or unmodelled regions of the graph", "Known data deficiencies in the cited snapshot" ] }, { "id": "dep-impact-q-path-retraction", "text": "How is a recorded path treated when an underlying dependency assertion is later retracted, retyped or corrected in the source graph?", "kind": "lifecycle", "answer_data": [ "Unresolved-edge marker retained on the historical path", "Rule that the historical trace is never silently re-derived", "Trigger condition for issuing a superseding result version" ] }, { "id": "dep-impact-q-reexecution", "text": "Can a consumer re-execute the traversal from the cited snapshot, profile and code-list versions and obtain the identical result?", "kind": "validation", "answer_data": [ "Cited snapshot, profile and code-list versions with content hashes", "Deterministic ordering and canonicalisation rule used before hashing", "Reproduction outcome record, including an unverifiable marker when a citation cannot be resolved" ] } ], "data_elements": [ { "id": "dep-impact-de-impact-path", "name": "Impact path", "description": "Ordered edge sequence from a seed entity to an asserted member; all distinct paths to the same member are retained.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001", "SRC-012" ] }, { "id": "dep-impact-de-path-edge-ref", "name": "Path edge reference", "description": "Reference to one dependency edge in the cited snapshot, consumed from the dependency-assertion area and never redefined here.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-012", "SRC-001" ] }, { "id": "dep-impact-de-excluded-edge-ref", "name": "Excluded edge or node reference", "description": "Reference to an edge, node or subgraph deliberately or unavoidably excluded from traversal.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-080", "SRC-012" ] }, { "id": "dep-impact-de-exclusion-reason", "name": "Exclusion reason", "description": "Coded reason for each exclusion, so that an absent branch is distinguishable from an assessed-negative branch.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-080", "SRC-082" ] }, { "id": "dep-impact-de-traversal-completeness", "name": "Traversal completeness", "description": "Whether traversal was exhaustive, depth-truncated, data-limited, sampled or access-limited over the cited snapshot.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-080", "SRC-085" ] }, { "id": "dep-impact-de-unresolved-edge-marker", "name": "Unresolved edge marker", "description": "Flag retained on a historical path when a cited edge no longer resolves, preventing silent re-derivation of past results.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-012" ] } ], "artifacts": [ { "id": "dep-impact-art-trace-record", "name": "Impact trace and exclusion record", "description": "The versioned traceability record for one result: every path from trigger to member, every excluded edge with its reason, the completeness code, unreachable regions, and the cited snapshot, profile and code-list versions with hashes needed to re-execute.", "media_or_form": [ "Versioned path and exclusion listing, projection-neutral", "Structured citation block of inputs with content hashes", "Human-readable note on unreachable or unmodelled regions" ], "serial": true, "identity_strategy": "Identified by the master-system trace identifier issued alongside the assessment result by the Dimension's system of record; otherwise by a governed identifier from a bound registry; otherwise by a Dimension-minted UUID or ULID. The trace carries the same stable identifier across versions with a separate monotonic version; run timestamps are metadata and never identity.", "source_refs": [ "SRC-001", "SRC-080", "SRC-012" ] } ], "inline_only_rationale": null }, { "id": "dep-impact-uncertainty-and-claim-status", "name": "Claim status, outcome uncertainty and limitation disclosure", "description": "Qualifies every asserted outcome with its epistemic standing: whether it is a dependency-derived exposure inference, a modelled prediction, an observed outcome or an attributed cause; the likelihood or confidence qualifier on a declared scale and who assigned it; the evidence required before an attributed-cause claim may be made at all; the accountable assessor and the mandate under which the assessment was issued; and the limitations that a consumer must read with the result. It also states, as a publication condition, that no impact result is an approval, an instruction or a notification.", "source_refs": [ "SRC-081", "SRC-080", "SRC-086", "SRC-001", "SRC-084" ], "questions": [ { "id": "dep-impact-q-claim-status", "text": "What claim status does each asserted outcome carry - exposure inference, modelled prediction, observed outcome or attributed cause?", "kind": "classification", "answer_data": [ "Claim status code (exposure-inference, modelled-prediction, observed-outcome, attributed-cause)", "Rule that traversal reachability alone may only yield exposure-inference", "Permitted claim statuses per analysis mode" ] }, { "id": "dep-impact-q-confidence-scale", "text": "Which likelihood or confidence qualifier is attached, on which declared scale, and which agent assigned it?", "kind": "quality", "answer_data": [ "Likelihood qualifier with the bound scale identifier and version", "Confidence qualifier with its evidence and agreement basis", "Assigning agent reference and role", "Statement that no calibrated likelihood vocabulary is prescribed by this model" ] }, { "id": "dep-impact-q-causal-evidence", "text": "What evidence must be cited before an outcome may be published with attributed-cause status, and what is recorded when that evidence is absent?", "kind": "evidence", "answer_data": [ "References to the cited causal evidence and its method", "Minimum evidence condition set by the adopting Dimension", "Automatic downgrade to modelled-prediction or exposure-inference where evidence is absent" ] }, { "id": "dep-impact-q-assessment-authority", "text": "Which agent or role is accountable for this assessment, and under what mandate was it issued?", "kind": "authority", "answer_data": [ "Accountable assessor agent and role reference", "Issuing mandate or terms-of-reference reference", "Sign-off record on the limitation disclosure" ] }, { "id": "dep-impact-q-consumer-reuse", "text": "How may a downstream consumer reuse this result without reading it as an approval, an instruction or a notification?", "kind": "interoperability", "answer_data": [ "Explicit non-authorisation statement carried with every released result", "Named consuming models and the decision each of them owns", "Mandatory accompanying fields (claim status, completeness code, limitation disclosure) that a projection may not strip" ] } ], "data_elements": [ { "id": "dep-impact-de-claim-status", "name": "Claim status", "description": "Epistemic standing of an asserted outcome, separating dependency-derived exposure from modelled prediction, observed outcome and attributed cause.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-086", "SRC-001", "SRC-081" ] }, { "id": "dep-impact-de-likelihood-qualifier", "name": "Likelihood qualifier", "description": "Likelihood of the asserted outcome on a Dimension-bound scale; no universal calibrated vocabulary is prescribed by this model.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-081" ] }, { "id": "dep-impact-de-confidence-qualifier", "name": "Confidence qualifier", "description": "Confidence in the determination, with the evidence basis and degree of agreement it rests on.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-081", "SRC-086" ] }, { "id": "dep-impact-de-uncertainty-scale-ref", "name": "Uncertainty scale reference", "description": "Citation of the bound likelihood or confidence scale and its version, so that qualifiers are interpretable across Dimensions.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-081", "SRC-084" ] }, { "id": "dep-impact-de-assessor-agent-ref", "name": "Accountable assessor", "description": "Agent and role accountable for the assessment and for signing the limitation disclosure.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-082", "SRC-001" ] }, { "id": "dep-impact-de-limitation-disclosure", "name": "Limitation and uncertainty disclosure", "description": "Mandatory statement of forecasting method, difficulties encountered, data deficiencies, unmodelled mechanisms and main uncertainties accompanying the result.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-080", "SRC-081", "SRC-085" ] }, { "id": "dep-impact-de-causal-evidence-ref", "name": "Causal evidence reference", "description": "Citation supporting an attributed-cause claim; required for that status and absent for exposure inferences by construction.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-086", "SRC-001" ] }, { "id": "dep-impact-de-non-authorisation-note", "name": "Non-authorisation statement", "description": "Fixed statement carried with every released result that it confers no approval, instruction, notification or enforcement, naming the models that own those decisions.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-083", "SRC-081" ] } ], "artifacts": [ { "id": "dep-impact-art-disclosure", "name": "Assessment limitation and uncertainty disclosure", "description": "The signed, versioned statement accompanying a released result: claim status distribution, likelihood and confidence qualifiers with their bound scales, forecasting method, difficulties and data deficiencies, unmodelled mechanisms, main uncertainties, accountable assessor and mandate, and the non-authorisation statement.", "media_or_form": [ "Human-readable narrative disclosure section", "Versioned structured record of qualifiers, scales and citations" ], "serial": true, "identity_strategy": "Identified by the master-system disclosure identifier issued with the assessment result; otherwise by a governed identifier from a bound registry; otherwise by a Dimension-minted UUID or ULID. Errata are new monotonic versions under the same stable identifier that cite the corrected version; the issue date is metadata and never identity.", "source_refs": [ "SRC-080", "SRC-081", "SRC-086", "SRC-085" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "dep-res-criticality-impact", "name": "Criticality and impact estimation", "description": "Judgements about how important a dependency is and what its loss would cost, each bound to a named scheme, a declared loss scenario and an explicit qualification of likelihood and confidence.", "rationale": "Criticality analysis is a structured prioritisation of systems and components by their importance to organizational goals and the impact of their failure (NIST IR 8179), while NIST SP 800-30 Rev. 1 keeps likelihood, impact and resulting risk as separate determinations. Grouping assignment, scale binding, impact projection and estimate qualification in one bundle keeps every estimate traceable to a scheme, a scenario and an evidence basis, and keeps the risk conclusion outside the model.", "source_refs": [ "SRC-087", "SRC-088", "SRC-090" ], "layers": [ { "id": "dep-res-criticality-basis", "name": "Criticality basis and scale binding", "description": "What a criticality value means: the subject and purpose it relates, the authority that set it, and the published scheme and version under which the value is interpreted.", "source_refs": [ "SRC-087", "SRC-090", "SRC-091" ], "findings": [ { "id": "dep-res-criticality-assignment", "name": "Criticality assignment to a dependency", "description": "A criticality value asserted for a depended-on element as seen from one named dependent purpose, valid for a stated operating state and time window, with the deciding authority recorded. Criticality is relational, not intrinsic: the same element may carry different values for different purposes.", "source_refs": [ "SRC-087", "SRC-089", "SRC-090" ], "questions": [ { "id": "dep-res-q-assignment-subject", "text": "Which depended-on element and which dependent purpose does this criticality assignment bind together?", "kind": "identity", "answer_data": [ "Reference to the dependency edge in the dependency-fact core", "Reference to the dependent mission, service or function", "Assignment identifier" ] }, { "id": "dep-res-q-assignment-level", "text": "What criticality level is asserted, and under which named scheme and version is that level defined?", "kind": "classification", "answer_data": [ "Criticality level code as published by the scheme", "Scheme reference and version", "Raw scheme-native value or vector" ] }, { "id": "dep-res-q-assignment-authority", "text": "Which role or body determined the level, by what method, and where is that decision recorded?", "kind": "authority", "answer_data": [ "Deciding role or committee reference", "Determination method reference", "Approval or decision record reference", "Decision timestamp" ] }, { "id": "dep-res-q-assignment-validity", "text": "For which operating state and validity window does the assignment hold?", "kind": "temporal", "answer_data": [ "Operating state or condition code (normal, degraded, surge, seasonal)", "valid_from and valid_to timestamps", "Review-due timestamp" ] }, { "id": "dep-res-q-assignment-inheritance", "text": "Does the assigned level propagate to elements the subject itself depends on, and under which inheritance rule?", "kind": "relationship", "answer_data": [ "Inheritance rule code (none, inherit-highest, decay-by-order)", "Maximum propagation depth", "Explicit override flag and reason" ] } ], "data_elements": [ { "id": "dep-res-de-assignment-id", "name": "Criticality assignment identifier", "description": "Stable identifier of the assignment record, distinct from the identifier of the dependency edge it qualifies.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-087" ] }, { "id": "dep-res-de-assignment-subject-ref", "name": "Qualified dependency reference", "description": "Reference to the typed dependency edge owned by the dependency-fact core that this assignment qualifies.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-087", "SRC-097" ] }, { "id": "dep-res-de-assignment-purpose-ref", "name": "Dependent purpose reference", "description": "The mission, business process, service or national critical function from whose viewpoint criticality is judged.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-088", "SRC-093" ] }, { "id": "dep-res-de-assignment-level", "name": "Scheme-qualified criticality level", "description": "The asserted level expressed as a code drawn from the bound scheme, never as a free-standing number.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-090", "SRC-091" ] }, { "id": "dep-res-de-assignment-validity", "name": "Validity window and operating state", "description": "Operating state plus valid-from/valid-to timestamps that bound the assertion in time.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-087", "SRC-039" ] } ], "artifacts": [], "inline_only_rationale": "A criticality assignment is a structured assertion made of references, a scheme-qualified code, an authority pointer and a validity window. It produces no medium of its own: the decision paperwork lives in the deciding body's record system and is cited, and the analysis that supports the level is captured by the impact-assessment and dependability-model artifacts declared in other findings. Materialising an artifact here would duplicate those records and invite divergence between the stored code and the cited document." }, { "id": "dep-res-scale-scheme-binding", "name": "Scale scheme binding", "description": "The declaration that a stored criticality, severity or likelihood value belongs to a specific published scheme version, with its publisher, value space, notation and supersession status, so no single scoring doctrine is embedded as canonical.", "source_refs": [ "SRC-090", "SRC-091", "SRC-092", "SRC-095" ], "questions": [ { "id": "dep-res-q-scheme-identity", "text": "Which published scheme, version and notation produced the stored value?", "kind": "identity", "answer_data": [ "Scheme identifier and version string", "Notation form (numeric band, vector string, decision-tree outcome, ordinal rank)", "Metric group or decision points supplied" ] }, { "id": "dep-res-q-scheme-publisher", "text": "Who publishes and maintains the scheme, and at which authoritative location is its definition retrievable?", "kind": "provenance", "answer_data": [ "Publisher organisation reference", "Authoritative specification URL or registry entry", "Publication and last-update timestamps" ] }, { "id": "dep-res-q-scheme-mapping", "text": "May values from two different schemes be compared, and is any declared mapping between them marked lossy?", "kind": "interoperability", "answer_data": [ "Permitted comparison flag per scheme pair", "Mapping definition reference", "Lossiness marker and known distortion notes" ] }, { "id": "dep-res-q-scheme-supersession", "text": "What becomes of stored values when the bound scheme version is superseded or withdrawn?", "kind": "lifecycle", "answer_data": [ "Scheme version status (current, superseded, withdrawn)", "Re-scoring obligation flag", "Frozen-value retention rule" ] }, { "id": "dep-res-q-scheme-inputs", "text": "Which scheme inputs are mandatory and which are optional or environment-specific?", "kind": "constraint", "answer_data": [ "Mandatory input list", "Optional or environmental input list", "Completeness verdict for the stored value" ] } ], "data_elements": [ { "id": "dep-res-de-scheme-ref", "name": "Scheme reference", "description": "Versioned reference to the published scheme under which a value is interpreted.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-091", "SRC-092" ] }, { "id": "dep-res-de-scheme-value-space", "name": "Declared value space", "description": "The permitted value set or range of the scheme, including whether values are ordinal, interval or categorical.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-091", "SRC-095" ] }, { "id": "dep-res-de-scheme-notation", "name": "Native notation string", "description": "The scheme's own notation for the recorded value, such as a vector string or a decision-tree path.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-091", "SRC-092" ] }, { "id": "dep-res-de-scheme-status", "name": "Scheme version status", "description": "Whether the bound scheme version is current, superseded or withdrawn at the time of reading.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-091" ] } ], "artifacts": [ { "id": "dep-res-art-scheme-definition", "name": "Published scale scheme definition", "description": "The externally published definition of a rating scheme version that stored values are bound to, such as a scoring specification, a decision-tree definition or a criticality rubric.", "media_or_form": [ "Specification document", "Decision-tree definition file", "Vector-string grammar or calculator definition", "Published ranking rubric or worksheet template" ], "serial": false, "identity_strategy": "Use the publisher's own scheme identifier and version as the authoritative master-system identifier (for example a named specification version); otherwise the governed specification URI or registry entry; otherwise a UUID minted by the adopting Dimension with the retrieval URL and content digest recorded.", "source_refs": [ "SRC-091", "SRC-092", "SRC-095" ] } ], "inline_only_rationale": null } ] }, { "id": "dep-res-impact-projection", "name": "Downstream impact projection", "description": "What a loss of the subject would do to dependents: consequence severity per category and the extent, order and boundaries of propagation.", "source_refs": [ "SRC-088", "SRC-039", "SRC-093" ], "findings": [ { "id": "dep-res-impact-estimate", "name": "Downstream impact estimate", "description": "An estimate of the consequence to a named dependent if the subject is lost or degraded, recorded per consequence category and per assumed loss scenario, with sensitivity to disruption duration. It is an input to a host risk or continuity record and is never itself a risk determination.", "source_refs": [ "SRC-088", "SRC-039", "SRC-096" ], "questions": [ { "id": "dep-res-q-impact-scenario", "text": "Which loss scenario does the estimate assume: total loss, partial degradation, delay, or corruption of the depended-on element?", "kind": "definition", "answer_data": [ "Loss scenario code", "Assumed degradation profile", "Scenario exclusions and assumptions" ] }, { "id": "dep-res-q-impact-categories", "text": "Which consequence categories are estimated, and what severity value is recorded for each?", "kind": "measurement", "answer_data": [ "Consequence category codes (operational, financial, safety, legal, individuals affected, mission)", "Per-category severity value and its bound scheme", "Aggregation rule if a single headline value is stored" ] }, { "id": "dep-res-q-impact-duration", "text": "How does the estimated consequence change as the disruption persists?", "kind": "temporal", "answer_data": [ "Severity value per duration band", "Referenced maximum tolerable downtime or impact tolerance value and its owner", "Non-linearity or step-change notes" ] }, { "id": "dep-res-q-impact-evidence", "text": "What evidence underpins the estimated severity and how was it obtained?", "kind": "evidence", "answer_data": [ "Assessment method reference (workshop, historical loss data, simulation, contractual penalty)", "Supporting assessment record reference", "Quantitative unit, currency or population count where used" ] }, { "id": "dep-res-q-impact-consumer", "text": "Which host record consumes this estimate, and who owns the decision made from it?", "kind": "ownership", "answer_data": [ "Consuming risk, continuity or supervisory record reference", "Owning system identifier", "Accountable owner role in the host system" ] } ], "data_elements": [ { "id": "dep-res-de-impact-scenario", "name": "Assumed loss scenario", "description": "The disruption assumption under which the estimate is valid; changing it invalidates the estimate.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-088" ] }, { "id": "dep-res-de-impact-severity", "name": "Per-category severity value", "description": "Scheme-qualified severity recorded for each consequence category considered.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-088", "SRC-095" ] }, { "id": "dep-res-de-impact-quantified", "name": "Quantified consequence measure", "description": "Optional quantitative expression of consequence with an explicit unit, such as monetary loss, service-hours lost or population affected.", "value_kind": "quantity", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-088", "SRC-039" ] }, { "id": "dep-res-de-impact-duration-profile", "name": "Duration sensitivity profile", "description": "Severity values indexed by elapsed-outage bands, referencing externally owned tolerance thresholds.", "value_kind": "collection", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-039", "SRC-096" ] }, { "id": "dep-res-de-impact-consumer-ref", "name": "Consuming host record reference", "description": "Pointer to the risk, continuity or supervisory record that takes this estimate as input.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-088", "SRC-096" ] } ], "artifacts": [ { "id": "dep-res-art-impact-assessment-record", "name": "Impact assessment record", "description": "The document or dataset produced by the assessment activity that supports the stored severity values, such as a business impact analysis extract, an assessment worksheet or a signed determination.", "media_or_form": [ "Assessment report", "Business impact analysis worksheet or extract", "Structured assessment dataset", "Signed determination memorandum" ], "serial": false, "identity_strategy": "Use the assessment platform's document identifier as the authoritative master-system identifier; otherwise a governed document IRI; otherwise a UUID or ULID minted by the adopting Dimension, always stored with a content digest and retrieval location.", "source_refs": [ "SRC-088", "SRC-039" ] } ], "inline_only_rationale": null }, { "id": "dep-res-blast-radius", "name": "Affected set and propagation extent", "description": "A snapshot of which dependents are reached if the subject fails, at what propagation order, across which boundaries and with what timing. It is a derived view over a referenced dependency-graph snapshot, recorded with its traversal rule and assumptions so it can be reproduced or falsified.", "source_refs": [ "SRC-087", "SRC-093", "SRC-097" ], "questions": [ { "id": "dep-res-q-radius-members", "text": "Which dependents are reached by a failure of the subject, and at what propagation order is each reached?", "kind": "relationship", "answer_data": [ "Affected element references with propagation order", "Path witness for each member", "Count of directly versus indirectly affected elements" ] }, { "id": "dep-res-q-radius-boundaries", "text": "Which organisational, jurisdictional, network or facility boundaries does the propagation cross?", "kind": "spatial", "answer_data": [ "Boundary type and crossing point", "Jurisdiction or region codes reached", "Cross-sector or cross-tenant flags" ] }, { "id": "dep-res-q-radius-derivation", "text": "Which graph snapshot, traversal rule and depth limit produced this affected set?", "kind": "provenance", "answer_data": [ "Dependency graph snapshot reference and snapshot time", "Traversal rule identifier and version", "Depth limit and cycle-handling rule" ] }, { "id": "dep-res-q-radius-timing", "text": "How quickly does the effect reach each tier of the affected set?", "kind": "temporal", "answer_data": [ "Time-to-impact per propagation order", "Buffering, queueing or cache assumptions that delay propagation", "Timestamp of the derivation" ] }, { "id": "dep-res-q-radius-exclusions", "text": "Which reachable paths were deliberately excluded from the affected set, and on what stated ground?", "kind": "exception", "answer_data": [ "Excluded path reference", "Exclusion reason code (isolated, out of scope, blocked by declared substitute)", "Approver of the exclusion" ] } ], "data_elements": [ { "id": "dep-res-de-radius-snapshot-id", "name": "Affected-set snapshot identifier", "description": "Identifier of one derivation run, since the affected set changes whenever the graph or traversal rule changes.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-087" ] }, { "id": "dep-res-de-radius-graph-ref", "name": "Source graph snapshot reference", "description": "Reference to the dependency-graph snapshot owned by the dependency-fact core over which the traversal ran.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-097" ] }, { "id": "dep-res-de-radius-members", "name": "Affected element set", "description": "Collection of reached elements with propagation order and path witness.", "value_kind": "collection", "cardinality": "1", "required": true, "source_refs": [ "SRC-093" ] }, { "id": "dep-res-de-radius-boundary-crossings", "name": "Boundary crossings", "description": "Boundaries traversed by the propagation, used to signal cross-organisation or cross-sector consequence.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-093", "SRC-094" ] }, { "id": "dep-res-de-radius-time-to-impact", "name": "Time to impact", "description": "Elapsed time before a given propagation order is affected, expressed as a duration.", "value_kind": "duration", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-039" ] } ], "artifacts": [], "inline_only_rationale": "An affected set is a reproducible derivation, not a document: it is fully determined by the cited graph snapshot, the traversal rule version and the depth and exclusion parameters recorded alongside it. Storing it as inline reference data keeps it regenerable and prevents a stale rendered diagram from being mistaken for the current propagation extent. Any published visualisation is a projection produced by the interface layer, and the term 'blast radius' itself has no normative definition, so no artifact class can be claimed as canonical." } ] }, { "id": "dep-res-estimate-quality", "name": "Likelihood and estimate qualification", "description": "The epistemic layer over every criticality and impact value: how likely the assumed disruption is, how confident the assessor is, what evidence supports that confidence and what uncertainty remains.", "source_refs": [ "SRC-088", "SRC-089", "SRC-090" ], "findings": [ { "id": "dep-res-estimate-qualification", "name": "Likelihood, confidence and residual uncertainty", "description": "Qualification of an estimate: the likelihood or frequency assigned to the assumed disruption over a stated horizon under a named scheme, together with asserted confidence, its evidential basis, the residual uncertainty that remains and the conditions that invalidate the estimate. Likelihood (about the world) and confidence (about the assessment) are recorded separately and never collapsed.", "source_refs": [ "SRC-088", "SRC-089", "SRC-095" ], "questions": [ { "id": "dep-res-q-quality-likelihood", "text": "What likelihood or failure frequency is assigned to the assumed disruption, over which horizon and under which likelihood scheme?", "kind": "measurement", "answer_data": [ "Likelihood value with its bound scheme and version", "Time horizon or exposure period", "Basis type (historical frequency, reliability model, expert judgement)" ] }, { "id": "dep-res-q-quality-confidence", "text": "What confidence is asserted in the estimate, and is it derived from evidence quality, assessor agreement or a stated model?", "kind": "quality", "answer_data": [ "Confidence level under a named confidence scheme", "Confidence derivation basis code", "Degree of agreement among contributing assessors" ] }, { "id": "dep-res-q-quality-residual", "text": "What residual uncertainty, unmodelled factor or known unknown remains after the estimate is made?", "kind": "evidence", "answer_data": [ "Residual uncertainty statement", "Unmodelled factor list", "Sensitivity notes identifying which input dominates the result" ] }, { "id": "dep-res-q-quality-invalidation", "text": "Which change in the underlying facts marks the estimate stale and triggers reassessment?", "kind": "validation", "answer_data": [ "Invalidation trigger conditions (edge change, scheme supersession, substitute withdrawal, realised incident)", "Maximum age before mandatory review", "Current freshness state" ] }, { "id": "dep-res-q-quality-authorship", "text": "Who produced the estimate, and were independent reviewers or dissenting judgements recorded?", "kind": "provenance", "answer_data": [ "Assessor identity and role", "Reviewer identities and review outcome", "Recorded dissent or minority position" ] } ], "data_elements": [ { "id": "dep-res-de-quality-likelihood", "name": "Scheme-qualified likelihood value", "description": "Likelihood or frequency of the assumed disruption, stored with its scheme reference and horizon.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-088" ] }, { "id": "dep-res-de-quality-horizon", "name": "Likelihood horizon", "description": "Exposure period over which the likelihood value applies, without which the value is uninterpretable.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-088" ] }, { "id": "dep-res-de-quality-confidence", "name": "Confidence level", "description": "Asserted confidence in the estimate under a named confidence scheme, kept distinct from likelihood.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-088", "SRC-090" ] }, { "id": "dep-res-de-quality-residual-note", "name": "Residual uncertainty statement", "description": "Narrative record of what the estimate does not capture, including unmodelled factors and dominant sensitivities.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-089" ] }, { "id": "dep-res-de-quality-freshness", "name": "Estimate freshness state", "description": "Whether the estimate is current, due for review or stale because a declared invalidation trigger fired.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-088", "SRC-089" ] } ], "artifacts": [], "inline_only_rationale": "Qualification data are attributes of an estimate rather than things in their own right: they must travel inside the same record as the value they qualify, or a consumer can read a severity without its confidence and horizon. The evidence they cite is already materialised by the impact-assessment record, the dependability model and the substitution verification record, each of which is referenced here rather than copied, so declaring a separate artifact would fragment a single assertion across two objects." } ] } ] }, { "id": "dep-res-resilience-posture", "name": "Resilience posture of the dependency", "description": "The conditions that soften or sharpen a dependency: declared substitutes and their limits, redundancy and its effective independence, single points of failure, concentration exposure, and references to externally owned mitigations.", "rationale": "Cyber resiliency is the capability to anticipate, withstand, recover from and adapt to adverse conditions (NIST SP 800-160 Vol. 2 Rev. 1), and dependability analysis models redundancy structures and their limits (IEC 61078:2016). DORA makes substitutability, exit strategies and concentration risk binding concerns. These posture facts qualify an impact estimate but must be recorded separately from it, because a substitute that exists on paper and one that has been exercised produce very different residual exposure.", "source_refs": [ "SRC-089", "SRC-094", "SRC-078" ], "layers": [ { "id": "dep-res-substitution-redundancy", "name": "Substitution, redundancy and correlated failure", "description": "Declared alternatives and redundant structures behind a dependency, their capacity and qualification limits, and the shared conditions that can defeat them together.", "source_refs": [ "SRC-089", "SRC-094", "SRC-078" ], "findings": [ { "id": "dep-res-substitute-option", "name": "Declared substitute or alternate", "description": "An alternative that can carry the dependent's need if the subject is unavailable, recorded with equivalence class, invocation preconditions, capacity and duration limits, switchover cost and the evidence that it has been verified. Declaration is not capability: unverified substitutes are marked as such.", "source_refs": [ "SRC-089", "SRC-039", "SRC-094" ], "questions": [ { "id": "dep-res-q-substitute-identity", "text": "Which alternative element can carry the need, and is it a full, partial or degraded-mode equivalent?", "kind": "identity", "answer_data": [ "Substitute element reference", "Equivalence class code (full, partial, degraded mode, manual workaround)", "Functions not covered by the substitute" ] }, { "id": "dep-res-q-substitute-preconditions", "text": "Under which declared preconditions is the substitution considered available and valid?", "kind": "constraint", "answer_data": [ "Precondition list (contract in force, data replicated, licence available, staff trained)", "Named condition owner for each precondition", "Current precondition satisfaction state" ] }, { "id": "dep-res-q-substitute-capacity", "text": "What capacity, throughput or duration ceiling limits the substitute, and what share of demand can it absorb?", "kind": "measurement", "answer_data": [ "Capacity ceiling with unit", "Absorbable demand share", "Maximum sustainable period in substitute mode" ] }, { "id": "dep-res-q-substitute-switchover", "text": "How long does switchover take, and what degradation or data loss is accepted while the substitute is in effect?", "kind": "temporal", "answer_data": [ "Switchover duration estimate", "Accepted degradation description", "Data-loss window and its referenced recovery-point objective owner" ] }, { "id": "dep-res-q-substitute-verification", "text": "When was the substitute last exercised or otherwise verified, and with what recorded result?", "kind": "evidence", "answer_data": [ "Last verification event time", "Verification method (live failover, tabletop exercise, contractual attestation)", "Result and defects found" ] } ], "data_elements": [ { "id": "dep-res-de-substitute-ref", "name": "Substitute element reference", "description": "Reference to the element, supplier or manual procedure proposed as an alternative.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-094" ] }, { "id": "dep-res-de-substitute-equivalence", "name": "Equivalence class", "description": "How completely the substitute replaces the subject, including declared functional gaps.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-089" ] }, { "id": "dep-res-de-substitute-capacity-limit", "name": "Capacity limit", "description": "Quantified ceiling on what the substitute can carry, with an explicit unit and any time bound.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-078" ] }, { "id": "dep-res-de-substitute-switchover-time", "name": "Switchover duration", "description": "Expected elapsed time to bring the substitute into effect, used in time-to-impact reasoning.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-039" ] }, { "id": "dep-res-de-substitute-verification-state", "name": "Verification state", "description": "Whether the substitute is unverified, attested, tested or proven in a real event, with the last verification time.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-089", "SRC-094" ] } ], "artifacts": [ { "id": "dep-res-art-substitution-verification-record", "name": "Substitution verification record", "description": "Evidence produced by one verification of a declared substitute, such as a failover test report, an exercise record or a contractual exit-plan attestation.", "media_or_form": [ "Failover or switchover test report", "Continuity exercise record or drill log", "Contractual exit-plan or transition-period attestation", "Structured test-run dataset" ], "serial": true, "identity_strategy": "Use the identifier issued by the exercising or testing system of record as the authoritative master-system identifier; otherwise a governed IRI for the exercise programme instance; otherwise a ULID minted by the adopting Dimension. Each verification run is a distinct instance and is never identified by its date alone.", "source_refs": [ "SRC-089", "SRC-094", "SRC-096" ] } ], "inline_only_rationale": null }, { "id": "dep-res-redundancy-correlation", "name": "Redundancy configuration and correlated failure", "description": "The redundant structure standing behind a dependency, expressed as a required-out-of-total configuration with its mode, together with the shared resources, suppliers, locations or designs that reduce effective independence and can defeat the redundancy at once.", "source_refs": [ "SRC-095", "SRC-078", "SRC-089" ], "questions": [ { "id": "dep-res-q-redundancy-structure", "text": "What redundancy configuration is declared, expressed as which structure and which required-out-of-total quantity?", "kind": "composition", "answer_data": [ "Structure code (series, parallel, k-of-n, active-standby)", "Required and total element counts", "Member element references" ] }, { "id": "dep-res-q-redundancy-sharing", "text": "Which resources, suppliers, sites, code bases or time sources are shared across the redundant members?", "kind": "relationship", "answer_data": [ "Shared resource references by type", "Sharing depth (same rack, same site, same provider, same software build)", "Diversity claim and its basis" ] }, { "id": "dep-res-q-redundancy-common-cause", "text": "Which common-cause or correlated failure conditions would defeat all redundant members simultaneously?", "kind": "constraint", "answer_data": [ "Common-cause condition list (power, cooling, region, certificate expiry, shared defect)", "Estimated correlation strength or beta-factor style parameter", "Scheme reference for the correlation measure" ] }, { "id": "dep-res-q-redundancy-degradation", "text": "Is the redundancy load-sharing, so that losing one member degrades capacity rather than preserving it?", "kind": "state", "answer_data": [ "Load-sharing flag", "Capacity retained after loss of one member", "Degraded-mode service description" ] }, { "id": "dep-res-q-redundancy-method", "text": "Which dependability analysis method produced or supports the configuration, and what assumptions did it declare?", "kind": "evidence", "answer_data": [ "Analysis method reference (reliability block diagram, fault tree, failure modes and criticality analysis)", "Model version and analyst", "Stated assumptions and acknowledged limitations" ] } ], "data_elements": [ { "id": "dep-res-de-redundancy-structure", "name": "Redundancy structure", "description": "Structural form of the redundancy together with required and total member counts.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-078" ] }, { "id": "dep-res-de-redundancy-members", "name": "Redundant member references", "description": "The elements that together provide the redundancy, referenced rather than duplicated.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-078" ] }, { "id": "dep-res-de-common-cause-conditions", "name": "Common-cause conditions", "description": "Conditions shared by the members that can cause simultaneous failure, each with a type and description.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-095", "SRC-078" ] }, { "id": "dep-res-de-effective-independence", "name": "Effective independence assessment", "description": "Judgement of how independent the members really are after shared conditions are accounted for, with its scheme reference.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-078" ] }, { "id": "dep-res-de-retained-capacity", "name": "Retained capacity on single loss", "description": "Capacity still available after one member is lost, expressed with an explicit unit or share.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-078" ] } ], "artifacts": [ { "id": "dep-res-art-dependability-model", "name": "Dependability analysis model", "description": "The analysis artefact that supports a redundancy or independence claim, such as a reliability block diagram, a fault tree or a failure modes, effects and criticality analysis worksheet.", "media_or_form": [ "Reliability block diagram model file or drawing", "Fault tree model", "Failure modes, effects and criticality analysis worksheet", "Simulation input and result dataset" ], "serial": false, "identity_strategy": "Use the engineering or dependability tool's model identifier as the authoritative master-system identifier; otherwise a governed model IRI held by the owning engineering function; otherwise a UUID minted by the adopting Dimension, recorded with model version, method standard reference and content digest.", "source_refs": [ "SRC-095", "SRC-078" ] } ], "inline_only_rationale": null } ] }, { "id": "dep-res-concentration-treatment", "name": "Single points of failure, concentration and treatment linkage", "description": "Determinations that follow from the posture facts - where no viable alternative exists and where too much converges on one element - and the outward references to mitigations that modify them.", "source_refs": [ "SRC-094", "SRC-078", "SRC-038" ], "findings": [ { "id": "dep-res-spof-concentration", "name": "Single point of failure and concentration exposure", "description": "The derived determination that a subject is a single point of failure for a named dependent, and the measured convergence of many dependents on one element, supplier, jurisdiction or facility. Both are derivations with a recorded rule version and trace, contestable and reversible, not standing labels.", "source_refs": [ "SRC-094", "SRC-078", "SRC-087" ], "questions": [ { "id": "dep-res-q-spof-determination", "text": "Is the subject a single point of failure for the named dependent, and from which recorded facts was that concluded?", "kind": "decision", "answer_data": [ "Determination verdict and derivation rule version", "Input records used (redundancy configuration, substitute options, capacity limits)", "Determination timestamp and derivation trace reference" ] }, { "id": "dep-res-q-spof-convergence", "text": "How many distinct dependents converge on this element, and what share of them carry a high criticality level?", "kind": "measurement", "answer_data": [ "Distinct dependent count", "Share of dependents at or above a named criticality level", "Counting rule and deduplication basis" ] }, { "id": "dep-res-q-spof-level", "text": "At which level does the concentration exist: element, product, supplier, jurisdiction or shared facility?", "kind": "classification", "answer_data": [ "Concentration level code", "Concentrating entity reference", "Cross-level roll-up notes" ] }, { "id": "dep-res-q-spof-clearance", "text": "Which change of state would remove the single-point-of-failure determination?", "kind": "state", "answer_data": [ "Clearance condition list", "Currently blocking condition", "Expected clearance owner in the host system" ] }, { "id": "dep-res-q-spof-contest", "text": "Which determinations are contested or overridden, by whom and on what stated ground?", "kind": "exception", "answer_data": [ "Contest or override record reference", "Overriding role and justification", "Effective period of the override" ] } ], "data_elements": [ { "id": "dep-res-de-spof-verdict", "name": "Single-point-of-failure verdict", "description": "Derived boolean-style verdict for a subject and dependent pair, valid only with its rule version and timestamp.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-078" ] }, { "id": "dep-res-de-spof-rule-version", "name": "Derivation rule version", "description": "Version of the rule that produced the verdict, so that historic determinations remain interpretable.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-087" ] }, { "id": "dep-res-de-concentration-count", "name": "Dependent convergence count", "description": "Number of distinct dependents relying on the concentrating entity under a declared counting rule.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-094" ] }, { "id": "dep-res-de-concentration-level", "name": "Concentration level", "description": "Level at which convergence is measured, such as element, supplier, jurisdiction or facility.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-094", "SRC-038" ] }, { "id": "dep-res-de-spof-override", "name": "Determination override", "description": "Recorded contest or override of a derived determination, with authority, ground and effective period.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-087" ] } ], "artifacts": [], "inline_only_rationale": "These are derivations over records this model already holds - redundancy configuration, substitute options and capacity limits - plus a rule version and a trace. They must be recomputed whenever an input changes, so freezing them into an artifact would create a document that outlives its inputs and invites reliance on a stale determination. The supporting analysis is already materialised by the dependability model artifact and is cited, and any published concentration report is an interface projection owned by the reporting process, not a record of this model." }, { "id": "dep-res-mitigation-reference", "name": "Mitigation and treatment reference", "description": "Outward pointers from a criticality or resilience record to externally owned mitigations, controls, continuity plans and treatment decisions, together with the credited effect on the local estimate and the residual value after crediting. The reference carries no ownership of the mitigation's approval, execution, testing or audit trail.", "source_refs": [ "SRC-089", "SRC-096", "SRC-038" ], "questions": [ { "id": "dep-res-q-mitigation-target", "text": "Which external mitigation, control or continuity record is referenced, and in which owning system does it live?", "kind": "identity", "answer_data": [ "Mitigation record identifier or IRI", "Owning system identifier and record type", "Resolution status of the reference" ] }, { "id": "dep-res-q-mitigation-effect", "text": "Which local estimate does the referenced mitigation modify, and is the stored value recorded before or after crediting it?", "kind": "relationship", "answer_data": [ "Modified estimate reference", "Pre-mitigation and post-mitigation value pair", "Crediting rule applied" ] }, { "id": "dep-res-q-mitigation-residual", "text": "What residual criticality or impact remains once the mitigation is credited?", "kind": "measurement", "answer_data": [ "Residual value with its bound scheme", "Residual gap description", "Whether the residual is accepted elsewhere and by which record" ] }, { "id": "dep-res-q-mitigation-inforce", "text": "What evidence shows the mitigation was in force at the moment the estimate was asserted?", "kind": "evidence", "answer_data": [ "Evidence reference from the owning system", "In-force period with explicit timestamps", "Verification staleness marker" ] }, { "id": "dep-res-q-mitigation-ownership", "text": "Who owns approval, execution and effectiveness testing of the referenced mitigation?", "kind": "ownership", "answer_data": [ "Accountable owner role in the owning system", "Owning model or system reference", "Explicit statement that this model performs none of these" ] } ], "data_elements": [ { "id": "dep-res-de-mitigation-ref", "name": "External mitigation reference", "description": "Resolvable pointer to a mitigation, control, plan or treatment record held by another system.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-089", "SRC-096" ] }, { "id": "dep-res-de-mitigation-credited-effect", "name": "Credited effect", "description": "The declared modification the mitigation makes to a named local estimate, with the crediting rule used.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-088", "SRC-089" ] }, { "id": "dep-res-de-mitigation-residual", "name": "Residual value after crediting", "description": "Scheme-qualified criticality or impact value remaining once the mitigation is credited.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-088" ] }, { "id": "dep-res-de-mitigation-inforce-window", "name": "In-force window", "description": "Period during which the owning system attests the mitigation was effective, used to date-bound the credit.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-096" ] } ], "artifacts": [], "inline_only_rationale": "This finding is deliberately nothing but reference data. The mitigation itself, its approval record, its test evidence and its audit trail are artifacts of the owning control, continuity or supply-chain system; reproducing any of them here would duplicate a governed record, create a second version that can drift, and quietly claim ownership of enforcement and audit semantics that the boundary notes place outside this model. Only the pointer, the credited effect and the residual value are held locally." } ] } ] }, { "id": "dep-govr-accountability-bundle", "name": "Accountability and Role Assignment", "description": "The generic governance role archetypes that may attach to a typed dependency or downstream-impact assertion, their accountability boundaries, the constraints that keep incompatible duties apart, and the way an archetype is bound to a specific agent for a bounded scope, term, purpose and jurisdiction.", "rationale": "Authoritative practice consistently separates the party that asserts a fact, the party accountable for the endpoint the fact concerns, the party that reviews it and the party that accepts residual risk. SPDX requires every assertion element to carry createdBy attribution; PROV-O supplies the qualified-attribution and delegation pattern; the Verifiable Credentials model separates issuer from verifier; RFC 8126 separates the designated expert from the change controller; NIST SP 800-37 Rev. 2 names authorizing official, owner and steward as distinct roles; and NIST SP 800-161 Rev. 1 requires those roles to be defined across organizational boundaries including suppliers and integrators. Without this bundle a dependency assertion is unattributable and its governance is unfalsifiable.", "source_refs": [ "SRC-001", "SRC-098", "SRC-100", "SRC-102", "SRC-105", "SRC-038", "SRC-106" ], "layers": [ { "id": "dep-govr-role-archetypes-layer", "name": "Role Archetypes and Accountability Boundaries", "description": "Definition of the reusable, polity-neutral role archetypes for dependency and impact governance, the endpoint-stewardship split that arises because a dependency has two ends under potentially different owners, and the declarative separation-of-duties constraints that limit which archetypes one agent may hold at once.", "source_refs": [ "SRC-102", "SRC-105", "SRC-038", "SRC-106" ], "findings": [ { "id": "dep-govr-role-archetype-catalog", "name": "Governance role archetype catalogue", "description": "A governed, extensible catalogue of the seven generic archetypes an agent may occupy with respect to a dependency or impact assertion - issuer, endpoint steward, reviewer, approver, observer, analyst and exception authority - each with a definition, the governance acts it may originate, and the acts it is explicitly not accountable for. Archetypes are abstract role concepts in the PROV-O sense; the adopting Dimension maps them to its own job titles, committees and delegated bodies without this model prescribing an organizational form.", "source_refs": [ "SRC-001", "SRC-100", "SRC-102", "SRC-105", "SRC-038" ], "questions": [ { "id": "dep-govr-q-archetype-definition", "text": "What exactly does each governance role archetype mean for a dependency or impact assertion, and which governance acts is it competent to originate?", "kind": "definition", "answer_data": [ "Archetype code and canonical label", "Normative definition text", "Enumerated competent governance acts (assert, annotate, review, approve, reject, except, observe)", "Enumerated explicitly-excluded acts", "Citation to the grounding source for the archetype" ] }, { "id": "dep-govr-q-archetype-boundary", "text": "Where does one archetype's accountability stop and the next archetype's begin, so that no act is unowned and no act is doubly owned?", "kind": "authority", "answer_data": [ "Accountability boundary statement per archetype", "Handover point between adjacent archetypes", "Escalation target when an act falls outside every declared archetype", "Flag for acts deliberately left to a referenced model" ] }, { "id": "dep-govr-q-archetype-extension", "text": "How may an adopting Dimension add a locally required archetype without breaking interoperability of the generic set?", "kind": "classification", "answer_data": [ "Extension namespace for local archetype codes", "Required parent archetype (specialisation link)", "Registration policy applied to the local extension", "Deprecation status of superseded local codes" ] }, { "id": "dep-govr-q-archetype-mapping", "text": "How does a given archetype map onto external role vocabularies so that governance data remains exchangeable?", "kind": "interoperability", "answer_data": [ "Mapping target vocabulary identifier (for example a PROV role IRI or an ODRL party function)", "Mapping relation strength (exact, broader, narrower, related)", "Known semantic mismatch note", "Mapping provenance and reviewer" ] } ], "data_elements": [ { "id": "dep-govr-de-archetype-code", "name": "Role archetype code", "description": "Stable code identifying one generic governance role archetype in the catalogue.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-102", "SRC-105" ] }, { "id": "dep-govr-de-archetype-competent-acts", "name": "Competent governance acts", "description": "Enumerated set of governance acts the archetype may originate for a dependency or impact assertion.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-100", "SRC-102" ] }, { "id": "dep-govr-de-archetype-excluded-acts", "name": "Excluded acts and referral target", "description": "Acts the archetype must not perform locally, each paired with the referenced model or external body that owns them.", "value_kind": "collection", "cardinality": "0..n", "required": true, "source_refs": [ "SRC-103", "SRC-104" ] }, { "id": "dep-govr-de-archetype-parent", "name": "Parent archetype reference", "description": "Reference to the generic archetype that a Dimension-local archetype specialises.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-102" ] }, { "id": "dep-govr-de-archetype-external-mapping", "name": "External role vocabulary mapping", "description": "Alignment from an archetype code to an external role or party-function identifier, with mapping strength.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-101" ] } ], "artifacts": [ { "id": "dep-govr-artifact-archetype-register", "name": "Dependency governance role archetype register", "description": "The governed code list of role archetypes with definitions, competent and excluded acts, parent links, external mappings and registration status. Published as a versioned controlled vocabulary independent of any serialisation.", "media_or_form": [ "controlled vocabulary / code list", "tabular register", "concept scheme" ], "serial": false, "identity_strategy": "Each entry is identified by its stable archetype code within the register namespace, resolvable as a governed IRI; the register itself carries the adopting Dimension's master-system identifier for the vocabulary. Superseded codes are retained with a deprecated status rather than removed.", "source_refs": [ "SRC-102", "SRC-001" ] } ], "inline_only_rationale": null }, { "id": "dep-govr-endpoint-stewardship", "name": "Endpoint stewardship and cross-boundary accountability", "description": "A dependency assertion has at least two ends, and the source and target may sit under different owners, organizations or contracts. This finding models the endpoint-steward binding for each end of the assertion, the case where the counterparty end is outside the adopting Dimension's control, and the resulting accountability asymmetry: an issuer may assert a dependency on an endpoint it does not steward, but cannot bind that endpoint's steward to any obligation.", "source_refs": [ "SRC-013", "SRC-105", "SRC-038", "SRC-015" ], "questions": [ { "id": "dep-govr-q-endpoint-owner", "text": "Which agent is the accountable steward of each end of this dependency, and is that end inside or outside the adopting Dimension's control boundary?", "kind": "ownership", "answer_data": [ "Endpoint role (source or target)", "Steward agent reference", "Control-boundary classification (internal, contracted external, uncontracted external, unknown)", "Contract or agreement reference where the end is external", "Evidence that the steward accepted the stewardship" ] }, { "id": "dep-govr-q-endpoint-consent", "text": "Has the counterparty steward acknowledged the asserted dependency, and what is the governance status when it has not?", "kind": "relationship", "answer_data": [ "Acknowledgement state (acknowledged, disputed, unacknowledged, not sought)", "Acknowledgement timestamp and acknowledging agent", "Unilateral-assertion flag", "Note that unacknowledged assertions create no obligation on the counterparty" ] }, { "id": "dep-govr-q-endpoint-composition", "text": "When an endpoint is itself a composite, at which level is stewardship asserted and how does it decompose?", "kind": "composition", "answer_data": [ "Asserted stewardship granularity (system, component, dataset, service, other)", "Parent endpoint reference", "Inherited-versus-explicit stewardship flag", "Decomposition depth limit declared by the adopting Dimension" ] }, { "id": "dep-govr-q-endpoint-gap", "text": "What happens when no steward can be identified for an endpoint that a critical impact path traverses?", "kind": "exception", "answer_data": [ "Unstewarded-endpoint marker", "Interim accountable agent reference", "Escalation target and due date", "Link to any exception grant covering the gap" ] } ], "data_elements": [ { "id": "dep-govr-de-endpoint-steward-binding", "name": "Endpoint steward binding", "description": "Association of one end of a dependency assertion with the agent accountable for that endpoint.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-105", "SRC-038" ] }, { "id": "dep-govr-de-control-boundary-class", "name": "Control-boundary classification", "description": "Whether the endpoint lies inside the adopting Dimension, under contract, outside any agreement, or is unknown.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-038" ] }, { "id": "dep-govr-de-counterparty-acknowledgement", "name": "Counterparty acknowledgement state", "description": "Whether the steward of the far endpoint has acknowledged, disputed or not responded to the assertion.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013", "SRC-038" ] }, { "id": "dep-govr-de-unstewarded-marker", "name": "Unstewarded endpoint marker", "description": "Flag with escalation reference indicating that no accountable steward has been identified for an endpoint.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-105" ] } ], "artifacts": [], "inline_only_rationale": "Endpoint stewardship is expressed entirely as reference data: a pair of pointers from an existing dependency assertion to agent identifiers that are minted and maintained in the referenced party/agent identity model, qualified by a control-boundary code and an acknowledgement state. Materialising a separate stewardship artifact would duplicate the authoritative party register and the core assertion's own from/to endpoints, creating two divergent copies of the same relationship. The correct projection is inline qualification of the assertion, so this finding declares no artifact of its own." }, { "id": "dep-govr-segregation-of-duties", "name": "Segregation-of-duties declarations for dependency governance", "description": "Declarative statements of which archetype combinations one agent must not hold simultaneously for the same assertion, which acts require two distinct persons, and where self-review or self-approval is prohibited. These are constraint declarations supplied as attributes to an external decision point; this model records the rule and any recorded conflict observation, and never blocks an operation itself.", "source_refs": [ "SRC-106", "SRC-103", "SRC-104", "SRC-102" ], "questions": [ { "id": "dep-govr-q-sod-incompatible-pairs", "text": "Which pairs or sets of role archetypes are declared incompatible for the same agent on the same dependency or impact assertion?", "kind": "constraint", "answer_data": [ "Incompatible archetype set", "Separation mode (static, dynamic, history-based)", "Scope of incompatibility (same assertion, same endpoint, same programme)", "Declaring authority and effective period" ] }, { "id": "dep-govr-q-sod-two-person", "text": "Which governance acts require two distinct natural persons, and how is distinctness determined?", "kind": "validation", "answer_data": [ "Act codes requiring a two-person condition", "Distinctness test (distinct agent identifier, distinct legal person, distinct reporting line)", "Minimum number of concurring agents", "Handling of software-agent participants" ] }, { "id": "dep-govr-q-sod-conflict-observation", "text": "When a duty conflict is observed on an existing assignment, what is recorded and who must act on it?", "kind": "decision", "answer_data": [ "Conflict observation record with detected archetype set", "Observation timestamp and observing agent or tool", "Accountable remediation agent", "Referral note stating that blocking or revoking access is executed by the referenced access model", "Link to any compensating exception grant" ] }, { "id": "dep-govr-q-sod-privilege-aggregation", "text": "How is cumulative privilege across delegated bindings assessed so that separation is not defeated by aggregation over time?", "kind": "security", "answer_data": [ "Aggregation window definition", "Set of bindings considered (direct and delegated)", "History-based separation rule reference", "Assessment outcome and assessing agent" ] } ], "data_elements": [ { "id": "dep-govr-de-incompatible-duty-set", "name": "Incompatible duty set", "description": "A named set of archetype codes declared not simultaneously holdable by one agent within a stated scope.", "value_kind": "collection", "cardinality": "0..n", "required": true, "source_refs": [ "SRC-106" ] }, { "id": "dep-govr-de-separation-mode", "name": "Separation mode", "description": "Whether the separation is static, dynamic at access time, or history-based over a defined window.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-106" ] }, { "id": "dep-govr-de-two-person-requirement", "name": "Two-person condition", "description": "Requirement that a named governance act be performed by two distinct persons, with the distinctness test applied.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-106" ] }, { "id": "dep-govr-de-conflict-observation", "name": "Duty conflict observation", "description": "Recorded observation that a binding set violates a declared incompatible duty set, with observation time and observer.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-103", "SRC-106" ] } ], "artifacts": [ { "id": "dep-govr-artifact-duty-conflict-matrix", "name": "Incompatible-duty matrix", "description": "The declarative matrix of archetype combinations, separation modes, two-person conditions and scopes, published as governed constraint data that an external policy decision point can consume as attributes. It states rules and does not evaluate them.", "media_or_form": [ "constraint matrix", "policy attribute set", "tabular register" ], "serial": false, "identity_strategy": "Identified by the adopting Dimension's master-system identifier for the governance ruleset, plus a monotonically increasing ruleset version; individual rows are identified by the ordered archetype-code tuple and scope code.", "source_refs": [ "SRC-106", "SRC-103" ] } ], "inline_only_rationale": null } ] }, { "id": "dep-govr-binding-qualifiers-layer", "name": "Role Binding, Delegation and Mandatory Qualifiers", "description": "How an abstract archetype becomes a concrete, time-bounded accountability of a named agent, including delegation chains and acting-on-behalf-of relationships, and the purpose and jurisdiction qualifiers that every governance act must carry so that the record is interpretable outside its originating context.", "source_refs": [ "SRC-001", "SRC-100", "SRC-101", "SRC-107" ], "findings": [ { "id": "dep-govr-role-binding-and-delegation", "name": "Role binding, term and delegation chain", "description": "The qualified attribution that binds one archetype to one agent for a stated scope of dependency or impact assertions over a stated validity period, together with the delegation chain when an agent acts on behalf of another and the succession rule when a binding lapses. Modelled on the PROV-O qualified-attribution pattern and the validFrom/validUntil plus status pattern of verifiable credentials.", "source_refs": [ "SRC-001", "SRC-100", "SRC-098", "SRC-007" ], "questions": [ { "id": "dep-govr-q-binding-identity", "text": "How is a single role binding identified and distinguished from every other binding of the same agent and archetype?", "kind": "identity", "answer_data": [ "Binding identifier resolved by the identity priority rule", "Bound agent reference", "Archetype code", "Scope expression (assertion set, endpoint set or domain)", "Binding version or sequence number" ] }, { "id": "dep-govr-q-binding-lifecycle", "text": "What states may a role binding occupy between proposal and termination, and what triggers each transition?", "kind": "lifecycle", "answer_data": [ "State code (proposed, active, suspended, lapsed, revoked, superseded)", "Transition trigger and triggering agent", "Successor binding reference", "Reason code for suspension or revocation" ] }, { "id": "dep-govr-q-binding-delegation", "text": "When an agent acts on behalf of another for a governance act, how is the delegation chain recorded and bounded?", "kind": "provenance", "answer_data": [ "Delegating agent reference", "Delegate agent reference", "Delegation depth and maximum permitted depth", "Acts included in and excluded from the delegation", "Delegation validity period" ] }, { "id": "dep-govr-q-binding-term", "text": "Over which validity period is the binding effective, and how are effective time and record time distinguished?", "kind": "temporal", "answer_data": [ "Valid-from timestamp", "Valid-until timestamp or open-ended marker", "Record creation timestamp", "Observation or ingestion timestamp where it differs from the effective time", "Time zone offset carried explicitly" ] } ], "data_elements": [ { "id": "dep-govr-de-binding-id", "name": "Role binding identifier", "description": "Identifier of a single archetype-to-agent binding within a stated scope.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-100" ] }, { "id": "dep-govr-de-binding-scope", "name": "Binding scope expression", "description": "The set of dependency or impact assertions, endpoints or domains over which the binding is effective.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001" ] }, { "id": "dep-govr-de-binding-validity", "name": "Binding validity period", "description": "Valid-from and optional valid-until instants for the binding, with explicit offsets.", "value_kind": "timestamp", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-100", "SRC-007" ] }, { "id": "dep-govr-de-binding-state", "name": "Binding state", "description": "Current lifecycle state of the binding with reason code and transition provenance.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-100", "SRC-102" ] }, { "id": "dep-govr-de-delegation-chain", "name": "Delegation chain", "description": "Ordered acted-on-behalf-of links from the performing agent to the ultimately accountable agent, with depth bound.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] } ], "artifacts": [], "inline_only_rationale": "A role binding is a qualified attribution: a structured inline statement that links an already-identified agent, an archetype code from the register, a scope expression and a validity period to a dependency or impact assertion. Its authoritative constituents live elsewhere - agents in the party/agent identity model, archetype codes in the archetype register artifact, scope in the core assertion structure - so a standalone binding artifact would be a derived join with no independent authority and a high risk of drifting from its sources. Representing it inline keeps exactly one authoritative copy and makes the binding travel with the assertion it qualifies." }, { "id": "dep-govr-purpose-jurisdiction-qualifiers", "name": "Purpose and jurisdiction qualifiers on governance acts", "description": "Every governance act recorded by this model must declare the purpose for which it was performed and the jurisdiction or territorial scope under which it is claimed to be valid. Both are carried as references into externally governed code lists - a purpose vocabulary and a jurisdiction registry - so that the model can require the qualifier without asserting any doctrine about what a jurisdiction is or which law prevails.", "source_refs": [ "SRC-101", "SRC-107", "SRC-038" ], "questions": [ { "id": "dep-govr-q-purpose-required", "text": "For what declared purpose was this governance act performed, and from which governed vocabulary is that purpose drawn?", "kind": "requirement", "answer_data": [ "Purpose code and source vocabulary identifier", "Free-text purpose narrative where the code list is insufficient", "Purpose declared at act time rather than inferred later", "Reference to the compatibility assessment held in the referenced privacy model where the act touches personal data" ] }, { "id": "dep-govr-q-jurisdiction-qualifier", "text": "Which jurisdiction or territorial scope is claimed for this act, and how are multiple or conflicting claims represented?", "kind": "spatial", "answer_data": [ "Jurisdiction code and registry reference", "Territorial scope type (entity seat, data location, endpoint location, contractual forum)", "Ordered list where several jurisdictions are claimed", "Conflict marker with no local resolution rule" ] }, { "id": "dep-govr-q-personal-data-in-binding", "text": "Does the governance record contain personal data about the bound agent, and what minimisation applies?", "kind": "privacy", "answer_data": [ "Personal-data present flag", "Categories of personal data carried (identifier, role, contact reference)", "Minimisation decision and its rationale", "Reference to the controller determination held in the referenced privacy model" ] }, { "id": "dep-govr-q-qualifier-access-effect", "text": "How do purpose and jurisdiction qualifiers reach the systems that decide who may read the governance record?", "kind": "access", "answer_data": [ "Qualifier attributes exposed for external decision points", "Attribute naming and namespace", "Statement that this model supplies attributes and renders no decision", "Reference to the access and policy model that consumes them" ] } ], "data_elements": [ { "id": "dep-govr-de-purpose-code", "name": "Governance purpose code", "description": "Reference into an external purpose vocabulary stating why a governance act was performed.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-101", "SRC-107" ] }, { "id": "dep-govr-de-jurisdiction-ref", "name": "Jurisdiction qualifier reference", "description": "Reference into an external jurisdiction registry describing the territorial scope claimed for the act.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-101", "SRC-107" ] }, { "id": "dep-govr-de-jurisdiction-conflict-flag", "name": "Jurisdiction conflict marker", "description": "Marker that two or more claimed jurisdictions conflict, with no local resolution asserted.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-101" ] }, { "id": "dep-govr-de-personal-data-flag", "name": "Personal-data presence flag", "description": "Whether the governance record carries personal data, with the categories present.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-107" ] } ], "artifacts": [], "inline_only_rationale": "Purpose and jurisdiction are mandatory qualifiers attached to each governance act, not documents in their own right. The vocabularies they point at are owned by external registries - a purpose code list and a jurisdiction registry - and reproducing either locally would create an unauthoritative copy and would drag polity doctrine into a model that must stay neutral. The model therefore carries only the coded reference, the scope type and a conflict marker as inline reference data on the act it qualifies." } ] } ] }, { "id": "dep-govr-assurance-bundle", "name": "Assurance, Exception and Record Governance", "description": "The governance acts that change the standing of a dependency or impact assertion after it has been issued: review and approval decisions, handling of contested or unresolvable assertions, time-bounded exception grants by a named authority, and the declarative record-governance markers that route the resulting records to the correct retention, hold and access regimes owned elsewhere.", "rationale": "Registration governance in RFC 8126 shows that an assertion's standing depends on a reviewer decision, a change controller's authority and an appeals path for contested cases; NIST SP 800-37 Rev. 2 shows that an approval is an explicit acceptance of residual risk by a named authorizing official, tracked with a plan of action and milestones; SPDX distinguishes an assertion of no relationship from an absence of assertion, giving contested and unknown states first-class treatment; and NARA guidance plus GDPR storage limitation show that retention and legal-hold execution belong to a records authority rather than the originating system. This bundle records outcomes and referrals, never enforcement.", "source_refs": [ "SRC-013", "SRC-099", "SRC-102", "SRC-105", "SRC-107", "SRC-108" ], "layers": [ { "id": "dep-govr-review-approval-layer", "name": "Review, Approval and Contested Assertions", "description": "The decision records that move a dependency or impact assertion from issued to reviewed to approved or rejected, and the parallel track for assertions whose truth or scope is disputed by a steward, an analyst or a counterparty.", "source_refs": [ "SRC-013", "SRC-099", "SRC-102", "SRC-105" ], "findings": [ { "id": "dep-govr-review-approval-decision", "name": "Review and approval decision record", "description": "A separately attributed decision record stating that a named reviewer examined a dependency or impact assertion and that a named approver accepted or rejected it, with the decision outcome, its stated basis, the effective time of the decision and the conditions attached. Reviewer and approver are distinct archetypes: review establishes technical adequacy, approval constitutes acceptance of the residual consequence.", "source_refs": [ "SRC-099", "SRC-102", "SRC-105", "SRC-100" ], "questions": [ { "id": "dep-govr-q-review-process-steps", "text": "What sequence of review and approval steps is required before a dependency or impact assertion is treated as governed, and what is the timeliness expectation for each?", "kind": "process", "answer_data": [ "Ordered step list with the archetype competent for each", "Response-time expectation per step", "Conditions under which a step may be skipped", "Recusal rule where the reviewer has a declared conflict of interest" ] }, { "id": "dep-govr-q-review-state", "text": "What governance standing does an assertion hold at any moment, and how is that standing represented when review has expired or been withdrawn?", "kind": "state", "answer_data": [ "Standing code (issued, in review, approved, rejected, withdrawn, lapsed, superseded)", "Standing effective timestamp", "Superseding decision reference", "Whether a lapsed approval reverts the assertion to in-review or to issued" ] }, { "id": "dep-govr-q-review-basis", "text": "On what stated basis was the decision reached, and what supporting material is cited without being reproduced?", "kind": "evidence", "answer_data": [ "Decision basis narrative", "References to cited analyses, tests or attestations held elsewhere", "Statement of what was not examined", "Confidence or completeness qualifier attached to the reviewed assertion" ] }, { "id": "dep-govr-q-review-quality", "text": "How is the adequacy of the review itself judged, and what makes a decision record defective?", "kind": "quality", "answer_data": [ "Minimum required fields for a valid decision record", "Defect codes (missing basis, missing approver, expired binding, conflicted reviewer)", "Re-review trigger conditions", "Reviewer of the review where a second-line check applies" ] } ], "data_elements": [ { "id": "dep-govr-de-decision-id", "name": "Decision record identifier", "description": "Identifier of one review or approval decision on a dependency or impact assertion.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-099", "SRC-105" ] }, { "id": "dep-govr-de-decision-outcome", "name": "Decision outcome", "description": "Coded outcome of the governance act (approved, approved with conditions, rejected, returned for rework, withdrawn).", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-102", "SRC-105" ] }, { "id": "dep-govr-de-decision-effective-time", "name": "Decision effective time", "description": "Instant from which the decision takes effect, recorded separately from the instant the record was captured.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-007", "SRC-098" ] }, { "id": "dep-govr-de-decision-conditions", "name": "Attached conditions", "description": "Conditions the approver attached to an approval, each with an owner and a due date, tracked in the referenced risk or change model.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-105" ] }, { "id": "dep-govr-de-recusal-note", "name": "Recusal or conflict note", "description": "Record that a reviewer or approver recused themselves, with the declared conflict and the substitute agent.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-102", "SRC-106" ] } ], "artifacts": [ { "id": "dep-govr-artifact-decision-record", "name": "Dependency governance decision record", "description": "An immutable, separately attributed record of one review or approval act on a named dependency or impact assertion, carrying outcome, basis, effective time, conditions, the acting agents and their bindings, and the purpose and jurisdiction qualifiers. Corrections are issued as superseding records rather than edits.", "media_or_form": [ "structured decision record", "signed statement", "narrative decision memorandum" ], "serial": true, "identity_strategy": "Primary identity is the adopting Dimension's master-system identifier from its governance or workflow system of record; where none exists, a governed IRI in the Dimension's decision namespace; failing both, a UUID or ULID minted at creation. Serial position is a monotonic sequence within the subject assertion, never derived from the decision date.", "source_refs": [ "SRC-099", "SRC-105", "SRC-102" ] } ], "inline_only_rationale": null }, { "id": "dep-govr-contested-assertion", "name": "Contested, unknown and no-assertion handling", "description": "Treatment of dependency or impact assertions whose existence, direction, scope or severity is disputed. Distinguishes a positive assertion that no dependency exists from an absence of any assertion, records the contesting party and grounds, holds the assertion in a contested state without silently deleting it, and names the authority competent to resolve - including an escalation path when the contest crosses an organizational boundary.", "source_refs": [ "SRC-013", "SRC-102", "SRC-099", "SRC-038" ], "questions": [ { "id": "dep-govr-q-contest-event", "text": "What event opened the contest, who raised it, and against which specific element of the assertion?", "kind": "event", "answer_data": [ "Contest opening timestamp and raising agent", "Contested element (existence, direction, endpoint, type, scope, severity, timing)", "Contest ground narrative", "Counter-assertion reference where one is offered" ] }, { "id": "dep-govr-q-contest-noassertion", "text": "How is a positive statement that no dependency exists distinguished from the absence of any statement, and from an unresolved contest?", "kind": "classification", "answer_data": [ "Assertion stance code (asserted, asserted-none, no-assertion, contested)", "Stance provenance and asserting agent", "Reason the stance could not be strengthened", "Downstream handling rule for each stance" ] }, { "id": "dep-govr-q-contest-resolution-authority", "text": "Which authority is competent to resolve this contest, and what is the escalation path when the parties sit under different owners?", "kind": "decision", "answer_data": [ "Competent resolving authority reference", "Escalation tier and next tier", "Cross-boundary escalation route (contract governance, joint forum, external adjudicator)", "Statement that unresolved cross-boundary contests remain open rather than defaulting to either party" ] }, { "id": "dep-govr-q-contest-duration", "text": "How long may a contest remain open, and what is recorded when it exceeds that period?", "kind": "temporal", "answer_data": [ "Contest opened and target-resolution timestamps", "Age threshold and breach marker", "Interim treatment of the assertion while contested", "Resolution or lapse timestamp and resolving agent" ] } ], "data_elements": [ { "id": "dep-govr-de-contest-id", "name": "Contest record identifier", "description": "Identifier of one open or closed contest against a dependency or impact assertion.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-102" ] }, { "id": "dep-govr-de-assertion-stance", "name": "Assertion stance code", "description": "Coded stance distinguishing asserted, asserted-none, no-assertion and contested, following the SPDX distinction between a none element and a no-assertion element.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-013" ] }, { "id": "dep-govr-de-contested-element", "name": "Contested element", "description": "The specific aspect of the assertion under dispute.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-013", "SRC-099" ] }, { "id": "dep-govr-de-resolving-authority", "name": "Competent resolving authority", "description": "Reference to the agent or forum competent to close the contest, with escalation tier.", "value_kind": "reference", "cardinality": "0..1", "required": true, "source_refs": [ "SRC-102", "SRC-038" ] }, { "id": "dep-govr-de-contest-interim-treatment", "name": "Interim treatment code", "description": "How the assertion is to be treated by consumers while the contest is open.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-013", "SRC-102" ] } ], "artifacts": [ { "id": "dep-govr-artifact-contest-record", "name": "Contested assertion record", "description": "A record of one contest: what is disputed, by whom, on what ground, any counter-assertion, the competent resolving authority, the interim treatment and the eventual resolution. Retained after closure so that the history of disputed dependency claims is reconstructable.", "media_or_form": [ "structured dispute record", "counter-assertion statement", "narrative dossier" ], "serial": true, "identity_strategy": "Primary identity is the master-system identifier from the adopting Dimension's case or issue system of record; otherwise a governed IRI in the Dimension's contest namespace; otherwise a UUID or ULID. Serial position is a monotonic sequence within the contested assertion and carries no date component.", "source_refs": [ "SRC-102", "SRC-013" ] } ], "inline_only_rationale": null } ] }, { "id": "dep-govr-exception-authority-layer", "name": "Exception Authority and Time-Bounded Waivers", "description": "The narrow, explicitly bounded power to accept a documented deviation from the governance rules of this model - for example proceeding on an unacknowledged external dependency, or approving despite an observed duty conflict - vested in a named authority for a bounded period under stated conditions.", "source_refs": [ "SRC-105", "SRC-102", "SRC-106" ], "findings": [ { "id": "dep-govr-exception-grant", "name": "Exception grant and accountable exception authority", "description": "A record that a named exception authority, acting within a declared scope of competence, granted a time-bounded waiver of a specific governance requirement for a specific dependency or impact assertion, with the compensating conditions, the expiry and the named agent accountable for the residual consequence. Modelled on the authorization decision as an explicit, time-bounded acceptance of residual risk rather than a silent rule suppression.", "source_refs": [ "SRC-105", "SRC-102", "SRC-106", "SRC-104" ], "questions": [ { "id": "dep-govr-q-exception-authority-competence", "text": "Which authority is competent to grant this exception, and what is the ceiling on that competence?", "kind": "authority", "answer_data": [ "Exception authority agent reference and binding", "Competence ceiling expressed as requirement classes, impact severity or endpoint criticality", "Requirements that may never be excepted", "Escalation target where the request exceeds the ceiling" ] }, { "id": "dep-govr-q-exception-scope", "text": "Precisely which governance requirement is waived, for which assertions, and what remains in force?", "kind": "exception", "answer_data": [ "Waived requirement identifier", "Assertion or endpoint scope of the waiver", "Requirements explicitly not waived", "Compensating conditions with owners" ] }, { "id": "dep-govr-q-exception-expiry", "text": "When does the exception expire, and what is the recorded consequence of expiry without renewal?", "kind": "temporal", "answer_data": [ "Granted-from and expires-at timestamps with explicit offsets", "Maximum permitted duration by exception class", "Renewal decision reference", "Post-expiry standing of the affected assertion" ] }, { "id": "dep-govr-q-exception-constraint", "text": "What constraints prevent an exception from becoming a permanent substitute for compliance?", "kind": "constraint", "answer_data": [ "Maximum consecutive renewal count", "Prohibition on self-granted exceptions", "Requirement for a remediation reference in the referenced risk or change model", "Periodic review obligation and its owner" ] } ], "data_elements": [ { "id": "dep-govr-de-exception-id", "name": "Exception grant identifier", "description": "Identifier of one exception or waiver grant.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-105" ] }, { "id": "dep-govr-de-waived-requirement", "name": "Waived requirement reference", "description": "Reference to the specific governance requirement of this model that is waived.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-102", "SRC-106" ] }, { "id": "dep-govr-de-exception-window", "name": "Exception validity window", "description": "Granted-from and expires-at instants bounding the waiver, with explicit offsets.", "value_kind": "timestamp", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-007", "SRC-105" ] }, { "id": "dep-govr-de-compensating-condition", "name": "Compensating condition", "description": "A condition imposed as the price of the exception, with an accountable owner and a due date tracked externally.", "value_kind": "collection", "cardinality": "0..n", "required": true, "source_refs": [ "SRC-105" ] }, { "id": "dep-govr-de-residual-accountable-agent", "name": "Residual accountable agent", "description": "The agent accepting accountability for the consequence of the waived requirement.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-105", "SRC-038" ] } ], "artifacts": [ { "id": "dep-govr-artifact-exception-grant", "name": "Exception grant record", "description": "The signed, time-bounded record of a waiver: waived requirement, scope, compensating conditions, validity window, granting authority with its binding, residual accountable agent, and the purpose and jurisdiction qualifiers. Renewals are new records referencing the prior grant, never edits to it.", "media_or_form": [ "structured waiver record", "signed authorization statement", "narrative justification memorandum" ], "serial": true, "identity_strategy": "Primary identity is the master-system identifier from the adopting Dimension's governance, risk and compliance system of record; otherwise a governed IRI in the Dimension's exception namespace; otherwise a UUID or ULID. Serial position is a monotonic renewal sequence within the waived requirement and scope, with no date-derived component.", "source_refs": [ "SRC-105", "SRC-102" ] } ], "inline_only_rationale": null } ] }, { "id": "dep-govr-record-governance-layer", "name": "Record-Governance Referral Markers", "description": "The declarative markers this model places on its own governance records - sensitivity and access classification, retention-class reference and legal-hold marker - that let the owning access, privacy and records models apply the correct regime without this model deciding, enforcing or executing anything.", "source_refs": [ "SRC-103", "SRC-107", "SRC-108", "SRC-104" ], "findings": [ { "id": "dep-govr-record-governance-referral", "name": "Sensitivity, access, retention and legal-hold referral markers", "description": "Governance records about dependencies are frequently sensitive: they name accountable individuals, expose organizational weak points and identify unacknowledged external reliance. This finding declares the markers carried on each governance record - a sensitivity and access classification supplied as attributes to the external decision point, a retention-class reference into the records model, and a legal-hold marker with its provenance - together with the explicit statement that classification is not authorization, that this model is not an audit store, and that suspension of disposition is executed and adjudicated elsewhere.", "source_refs": [ "SRC-103", "SRC-104", "SRC-107", "SRC-108" ], "questions": [ { "id": "dep-govr-q-record-sensitivity", "text": "How sensitive is this governance record, and on what basis was that classification assigned?", "kind": "privacy", "answer_data": [ "Sensitivity classification code and scheme reference", "Basis for the classification (personal data present, commercial confidence, security exposure of an unacknowledged dependency)", "Classifying agent and classification timestamp", "Reclassification trigger and review date" ] }, { "id": "dep-govr-q-record-access-attributes", "text": "Which attributes does this model expose so that an external decision point can decide who may read the record, and what does it deliberately not decide?", "kind": "access", "answer_data": [ "Exposed attribute set and namespace", "Statement that no permit or deny decision is rendered locally", "Reference to the access and policy model that owns decision and enforcement", "Handling of obligations or advice returned by the external decision point, which are discharged by the enforcement point and not here" ] }, { "id": "dep-govr-q-record-retention-class", "text": "Which retention class applies to this governance record, and who owns the disposition decision and its execution?", "kind": "retention", "answer_data": [ "Retention class reference into the records model", "Retention trigger event (decision effective time, exception expiry, contest closure)", "Statement that disposition approval and execution belong to the records authority", "Reference to the adopting Dimension's records officer or equivalent" ] }, { "id": "dep-govr-q-record-legal-hold", "text": "Is this governance record under a legal or investigative hold, and what does the marker permit and forbid locally?", "kind": "evidence", "answer_data": [ "Hold marker with hold identifier and issuing authority reference", "Hold applied and released timestamps", "Statement that the marker suspends local disposition proposals only", "Statement that the legal determination and any unauthorized-disposition reporting are owned by the records and legal functions" ] }, { "id": "dep-govr-q-record-audit-boundary", "text": "How is the boundary maintained between a governance record held here and the audit trail held in the referenced audit model?", "kind": "interoperability", "answer_data": [ "Correlation identifier shared with the audit model", "List of events this model emits versus events it stores", "Statement that log integrity, tamper-evidence and audit retention are external", "Reconciliation procedure when the two diverge" ] } ], "data_elements": [ { "id": "dep-govr-de-sensitivity-class", "name": "Sensitivity classification", "description": "Coded sensitivity of the governance record with a reference to the classification scheme used.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-104", "SRC-107" ] }, { "id": "dep-govr-de-access-attribute-set", "name": "Exposed access attribute set", "description": "The attributes published for consumption by an external policy decision point; contains no decision outcome.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-103" ] }, { "id": "dep-govr-de-retention-class-ref", "name": "Retention class reference", "description": "Reference into the records retention model naming the schedule that governs this record.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-107", "SRC-108" ] }, { "id": "dep-govr-de-legal-hold-marker", "name": "Legal hold marker", "description": "Flag with hold identifier, issuing authority reference and applied or released timestamps, suspending local disposition proposals.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-108" ] }, { "id": "dep-govr-de-audit-correlation-id", "name": "Audit correlation identifier", "description": "Shared identifier allowing the referenced audit model to correlate its trail entries with this governance record.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-104" ] } ], "artifacts": [], "inline_only_rationale": "These markers are qualifiers on records that already exist as artifacts elsewhere in this model - decision records, contest records and exception grants - and their authoritative content is owned by other models: the classification scheme by the adopting Dimension's information-classification policy, the retention class by the records model, the hold by the legal function, and the audit trail by the audit model. Creating a separate marker artifact would either duplicate those authoritative registers or imply that this model holds a disposition or hold register of its own, which would breach the ownership boundary the model is built to respect. The markers are therefore purely inline reference data carried on the governed record." } ] } ] }, { "id": "dep-govp-record-contract", "name": "Format-Neutral Record Contract", "description": "The abstract-record layer of the Dependency / Impact mixin: how a dependency edge or impact assessment is identified, placed in a namespace and tenant partition, reduced to a deterministic canonical form and digest, and projected into any concrete serialization with disclosed loss.", "rationale": "Dependency and impact assertions are exchanged across SBOM formats, graph stores, document databases and human-readable documents. Unless identity, canonical form and projection loss are fixed at the abstract-record level, digests, comparisons and signatures diverge per format. RFC 8785 and RDFC-1.0 each provide deterministic canonicalization only within their own data model, so the contract must be stated once above both.", "source_refs": [ "SRC-109", "SRC-110", "SRC-114", "SRC-013", "SRC-015", "SRC-116" ], "layers": [ { "id": "dep-govp-identity-namespace", "name": "Identity and Namespace Governance", "description": "Rules for minting, binding and resolving identifiers for dependency-edge and impact-assessment records, and for partitioning them by namespace, tenant and adopting Dimension.", "source_refs": [ "SRC-114", "SRC-013", "SRC-116" ], "findings": [ { "id": "dep-govp-record-identity", "name": "Record identity and identifier priority", "description": "A dependency edge and an impact assessment are each first-class records requiring a stable identifier that is independent of the endpoints they relate. Identity is bound in strict priority: an authoritative master-system identifier where one exists; otherwise a governed global identifier or IRI issued under a delegated namespace authority; otherwise a UUID (UUIDv7 preferred) or ULID minted by the adopting Dimension. Endpoint references are separate fields, never a substitute for edge identity, and no date, version tag or content digest may serve as the identifier.", "source_refs": [ "SRC-114", "SRC-013", "SRC-116" ], "questions": [ { "id": "dep-govp-q-identity-primary", "text": "Which identifier is authoritative for this dependency or impact record, and which system assigned it?", "kind": "identity", "answer_data": [ "Primary identifier value and its identifier scheme", "Assigning system or authority reference", "Priority tier satisfied: master-system, governed global IRI/URN, or locally minted UUID/ULID" ] }, { "id": "dep-govp-q-identity-authority", "text": "What authority delegated the namespace under which this identifier was assigned, and what persistence commitment applies?", "kind": "authority", "answer_data": [ "Namespace authority reference", "Persistence and non-reassignment commitment statement", "Delegation evidence reference" ] }, { "id": "dep-govp-q-identity-endpoint-binding", "text": "How are the source and target endpoints of the edge referenced without collapsing them into the edge identifier?", "kind": "constraint", "answer_data": [ "Source endpoint reference and its identifier scheme", "Target endpoint reference(s) and identifier scheme", "Endpoint resolution status and unresolved-reference flag" ] }, { "id": "dep-govp-q-identity-alias-mapping", "text": "Which alternate or legacy identifiers map to this record, and are any of them known to be non-unique?", "kind": "interoperability", "answer_data": [ "Alias identifier list with scheme and issuing system", "Uniqueness assertion per alias", "Mapping confidence and reconciliation method" ] } ], "data_elements": [ { "id": "dep-govp-de-record-id", "name": "Record identifier", "description": "The single authoritative identifier for this dependency-edge or impact-assessment record, opaque and free of date-like components.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-114", "SRC-116" ] }, { "id": "dep-govp-de-id-scheme", "name": "Identifier scheme and priority tier", "description": "Coded scheme (master-system key, URN, HTTP IRI, UUIDv7, ULID) and the identity-priority tier that scheme satisfies.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-114", "SRC-116" ] }, { "id": "dep-govp-de-endpoint-ref", "name": "Endpoint reference", "description": "Reference to a related element, carrying role (source or target), identifier scheme and resolution status; modelled after the from/to structure of a first-class relationship.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-013" ] }, { "id": "dep-govp-de-alias-id", "name": "Alias identifier", "description": "A non-authoritative identifier for the same record in another system, with issuing system and uniqueness assertion.", "value_kind": "identifier", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-013", "SRC-116" ] } ], "artifacts": [], "inline_only_rationale": "Identity is expressed as inline fields on the dependency or impact record itself. Materialising a separate identifier document would create a second, competing source of truth and would invite the anti-pattern of a locally operated identifier registry, which this model explicitly excludes. Alias mappings are also inline references; where a real identifier registry exists it is an external system referenced by URN or IRI, not an artifact produced here." }, { "id": "dep-govp-namespace-tenancy", "name": "Namespace, tenancy and adopting-Dimension partitioning", "description": "Every governed record belongs to exactly one namespace partition owned by one adopting Dimension, expressed as a URN namespace identifier or an HTTP base IRI with a documented assignment authority. Tenancy is a partition of the identifier and canonicalization space, not an access-control mechanism: cross-tenant references are permitted only as explicit external references with their own namespace prefix, and identifier collision across tenants is prevented by namespace, never by hoping for UUID uniqueness alone.", "source_refs": [ "SRC-015", "SRC-116", "SRC-118" ], "questions": [ { "id": "dep-govp-q-ns-owner", "text": "Which adopting Dimension owns this namespace partition, and who is the accountable owner package?", "kind": "ownership", "answer_data": [ "Adopting Dimension identifier", "Owner package reference and accountable role", "Effective date of ownership assignment" ] }, { "id": "dep-govp-q-ns-form", "text": "Is the namespace expressed as a URN namespace identifier or an HTTP base IRI, and what string form do namespace-specific parts take?", "kind": "classification", "answer_data": [ "Namespace form code (URN NID or HTTP base IRI)", "Namespace-specific string pattern", "Reserved segment list and prohibited prefixes" ] }, { "id": "dep-govp-q-ns-cross-tenant", "text": "Under what conditions may a record in one tenant partition reference a record in another?", "kind": "constraint", "answer_data": [ "Cross-partition reference permission rule", "Required namespace prefix on foreign references", "Dangling-reference handling policy" ] }, { "id": "dep-govp-q-ns-resolution-separation", "text": "How are resolution and service parameters kept out of the persistent identifier itself?", "kind": "access", "answer_data": [ "Resolution endpoint reference held separately from the identifier", "Rule excluding resolution, query and fragment parameters from identifier equality", "Identifier equality comparison procedure" ] } ], "data_elements": [ { "id": "dep-govp-de-namespace", "name": "Namespace identifier", "description": "URN namespace identifier or HTTP base IRI under which record identifiers in this partition are assigned.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-116" ] }, { "id": "dep-govp-de-tenant-partition", "name": "Tenant partition key", "description": "Key identifying the adopting-Dimension partition that owns the record; used for identifier scoping and projection routing, not for authorization.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-116", "SRC-118" ] }, { "id": "dep-govp-de-owner-package", "name": "Owner package reference", "description": "Reference to the accountable owner package within the adopting Dimension, with the role responsible for namespace stewardship.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-118" ] }, { "id": "dep-govp-de-foreign-ref-policy", "name": "Cross-partition reference rule", "description": "Coded rule stating whether foreign-partition references are prohibited, permitted as opaque external references, or permitted with resolution.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-015", "SRC-116" ] } ], "artifacts": [ { "id": "dep-govp-art-namespace-manifest", "name": "Namespace and tenancy registration manifest", "description": "Declarative statement binding a namespace identifier to an adopting Dimension, an owner package, the assignment authority, the persistence commitment, reserved segments and the cross-partition reference rule. It declares a binding; it does not allocate identifiers or resolve them.", "media_or_form": [ "structured record in any serialization (document, table row, graph node)", "human-readable rendering for review" ], "serial": false, "identity_strategy": "Identified by the namespace identifier it declares, qualified by manifest version; superseded manifests are retained and linked as previous versions rather than overwritten.", "source_refs": [ "SRC-116", "SRC-118" ] } ], "inline_only_rationale": null } ] }, { "id": "dep-govp-canonicalization", "name": "Canonicalization, Serialization and Projection Loss", "description": "Rules producing a deterministic canonical form and digest for a dependency or impact record in each supported shape, and the mandatory disclosure of what a given projection cannot carry.", "source_refs": [ "SRC-109", "SRC-110", "SRC-113", "SRC-115" ], "findings": [ { "id": "dep-govp-canonical-form", "name": "Canonical form, digest and artifact integrity", "description": "Canonicalization is defined per shape family, not per file format. Tree-shaped projections canonicalize under the JSON Canonicalization Scheme, which sorts properties lexicographically, removes whitespace, serializes numbers by ECMAScript rules and forbids duplicate keys. Graph-shaped projections canonicalize under RDFC-1.0, which assigns deterministic blank-node labels. A record's digest is computed over the canonical byte stream of a named shape, and the shape name is always carried with the digest. Because the two algorithms operate on different data models and JCS performs no Unicode normalization, digest equality across shape families is not asserted.", "source_refs": [ "SRC-109", "SRC-110", "SRC-117" ], "questions": [ { "id": "dep-govp-q-canon-shape", "text": "Which canonicalization profile applies to this record, and over which shape family was it computed?", "kind": "definition", "answer_data": [ "Canonicalization profile identifier and version", "Shape family code (tree or graph)", "Named algorithm reference and its version" ] }, { "id": "dep-govp-q-canon-numeric", "text": "How are impact scores and other numeric values represented so that canonicalization does not silently change their precision?", "kind": "constraint", "answer_data": [ "Numeric representation rule, including the string-encoding requirement beyond double precision", "Declared precision and unit for each quantitative field", "Rejected-value handling for non-finite numbers" ] }, { "id": "dep-govp-q-canon-digest", "text": "What digest algorithm and encoding bind this record's canonical form, and how is the binding verified?", "kind": "evidence", "answer_data": [ "Digest algorithm name and output encoding", "Digest value and the canonical form it covers", "Verification procedure and last successful verification reference" ] }, { "id": "dep-govp-q-canon-text-equality", "text": "How are string comparisons handled when the canonicalization algorithm does not normalize Unicode?", "kind": "quality", "answer_data": [ "Declared Unicode normalization form applied before canonicalization, or an explicit statement that none is applied", "Text equality comparison rule", "Known false-difference risk statement" ] } ], "data_elements": [ { "id": "dep-govp-de-canon-profile", "name": "Canonicalization profile reference", "description": "Identifier and version of the canonicalization profile applied, naming the algorithm and the shape family it covers.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-109", "SRC-110" ] }, { "id": "dep-govp-de-content-digest", "name": "Content digest", "description": "Digest over the canonical byte stream, carrying algorithm name, encoding and the canonicalization profile it was computed under.", "value_kind": "text", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-109", "SRC-117" ] }, { "id": "dep-govp-de-numeric-encoding", "name": "Numeric encoding declaration", "description": "Per-field declaration of whether a numeric value is carried as a JSON number within IEEE 754 double range or as a string to preserve precision.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-109" ] }, { "id": "dep-govp-de-normalization-form", "name": "Text normalization declaration", "description": "Declared Unicode normalization applied before canonicalization, or an explicit none, since the canonicalization scheme itself preserves strings as is.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-109" ] } ], "artifacts": [ { "id": "dep-govp-art-canon-profile", "name": "Canonicalization profile declaration", "description": "Versioned declaration naming, for each supported shape family, the canonicalization algorithm, digest algorithm and encoding, numeric and text handling rules, and the explicit statement that cross-shape digest equality is not claimed.", "media_or_form": [ "structured record in any serialization", "specification-style human-readable rendering" ], "serial": false, "identity_strategy": "Identified by profile identifier plus semantic version; each published version is immutable and digest-bound, and supersession is expressed by a previous-version link.", "source_refs": [ "SRC-109", "SRC-110" ] }, { "id": "dep-govp-art-integrity-manifest", "name": "Record integrity manifest", "description": "Digest-bearing manifest listing the canonical digests of a set of dependency or impact records at a stated point in time, usable as the subject list of an external attestation without this model performing any verification service.", "media_or_form": [ "structured record in any serialization", "detached digest listing" ], "serial": true, "identity_strategy": "Identified by a minted record identifier; ordered by the manifest's own generation timestamp, never by embedding a date in the identifier.", "source_refs": [ "SRC-117" ] } ], "inline_only_rationale": null }, { "id": "dep-govp-projection-loss", "name": "Projection profiles and loss disclosure", "description": "Every concrete serialization or store is a projection of the abstract record and must be governed by a projection profile that states which elements survive, which are transformed and which are dropped. Known lossy cases are normative examples rather than exhaustive: merge-patch-style documents cannot distinguish a null value from a deletion, arrays are replaced wholesale, absence semantics such as an explicit no-relationship assertion versus a no-assertion statement do not survive into formats lacking that distinction, and stores that normalize timestamps to UTC discard the recorded offset. A projection that cannot carry an element must disclose the loss rather than silently degrade.", "source_refs": [ "SRC-112", "SRC-113", "SRC-013", "SRC-115", "SRC-015" ], "questions": [ { "id": "dep-govp-q-proj-target", "text": "Which projection target does this profile describe, and which shape family and canonicalization profile does it use?", "kind": "interoperability", "answer_data": [ "Projection target identifier (format, store or interface family)", "Shape family and canonicalization profile reference", "Profile version and effective date" ] }, { "id": "dep-govp-q-proj-loss-inventory", "text": "Which elements of the abstract record are dropped, coerced or restructured by this projection?", "kind": "evidence", "answer_data": [ "Per-element disposition: carried, transformed, or dropped", "Transformation description and reversibility flag", "Residual-information statement for irreversible transformations" ] }, { "id": "dep-govp-q-proj-roundtrip", "text": "Is a round trip through this projection lossless, and what test demonstrates the answer?", "kind": "quality", "answer_data": [ "Round-trip classification (lossless, lossy-disclosed, unknown)", "Round-trip test reference and last result", "Digest comparison outcome before and after projection" ] }, { "id": "dep-govp-q-proj-absence", "text": "How does this projection represent an explicit assertion that no dependency exists versus an absence of any assertion?", "kind": "exception", "answer_data": [ "Representation of explicit no-relationship assertion", "Representation of no-assertion or unknown", "Statement of collapse where the projection cannot distinguish the two" ] }, { "id": "dep-govp-q-proj-selection", "text": "How is a partial projection addressed and named so that consumers can tell which subtree or subgraph they received?", "kind": "composition", "answer_data": [ "Node-selection expression and its expression language", "Normalized path or canonical location of each returned node", "Completeness flag for the returned selection" ] } ], "data_elements": [ { "id": "dep-govp-de-projection-target", "name": "Projection target", "description": "Coded identifier for the serialization, store or interface family a profile describes; explicitly non-canonical.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-115", "SRC-015" ] }, { "id": "dep-govp-de-loss-entry", "name": "Loss disclosure entry", "description": "Per-element record of disposition (carried, transformed, dropped), reversibility and any residual information, forming the disclosure inventory.", "value_kind": "object", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-112", "SRC-013" ] }, { "id": "dep-govp-de-roundtrip-status", "name": "Round-trip status", "description": "Classification of the projection as lossless, lossy with disclosure, or untested, with a reference to the evidencing test run.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-110", "SRC-112" ] }, { "id": "dep-govp-de-selection-expression", "name": "Node selection expression", "description": "Expression identifying which nodes a partial projection returned, together with the normalized path form of each returned node.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-115" ] } ], "artifacts": [ { "id": "dep-govp-art-projection-profile", "name": "Projection profile and loss disclosure statement", "description": "Versioned, per-target statement of the mapping from abstract record to a concrete projection, its complete loss inventory, round-trip status and the representation chosen for absence semantics.", "media_or_form": [ "structured record in any serialization", "tabular mapping rendering", "human-readable conformance annex" ], "serial": false, "identity_strategy": "Identified by projection-target code plus profile version; each published version is immutable and digest-bound to the canonicalization profile it depends on.", "source_refs": [ "SRC-112", "SRC-013", "SRC-115" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "dep-govp-service-contract", "name": "Service-Layer Operating Contract", "description": "The operating half of the governance contract: change control and clocks, validation and conformance, provenance and custody, and the interface-neutral query, mutation, retention and delegation surface.", "rationale": "Dependency and impact records are consumed by criticality and supply-chain risk processes where a stale, unattributed or unvalidated edge produces a wrong downstream conclusion. Standards exist for each mechanism - patch grammars, timestamps, shape validation, provenance attribution and build attestation - but none governs a dependency mixin end to end, so the operating contract must bind them together while explicitly delegating evaluation, enforcement, audit and erasure execution outward.", "source_refs": [ "SRC-111", "SRC-112", "SRC-113", "SRC-049", "SRC-001", "SRC-117", "SRC-038", "SRC-118" ], "layers": [ { "id": "dep-govp-change-control", "name": "Version, Patch and Clock Discipline", "description": "How a dependency or impact record changes over time: version identity and compatibility classes, the patch grammars permitted, and the separation of asserted event time, edge validity and observation time.", "source_refs": [ "SRC-111", "SRC-112", "SRC-113", "SRC-013", "SRC-118" ], "findings": [ { "id": "dep-govp-version-patch", "name": "Version identity, patch grammar and compatibility classes", "description": "A record version is an immutable, digest-bound state linked to its predecessor by a previous-version relation, forming an auditable chain. Mutations are expressed as patch documents: an operation-sequence grammar with pointer targets, test preconditions and all-or-nothing application is the default; merge-patch grammar is permitted only for object-shaped subtrees that contain no explicit nulls and require no partial array edits; graph-shaped records use a canonicalized add/remove quad set. Every patch carries the expected pre-state digest and the resulting post-state digest, and declares a compatibility class: additive, corrective, or restrictive (breaking).", "source_refs": [ "SRC-111", "SRC-112", "SRC-110", "SRC-118" ], "questions": [ { "id": "dep-govp-q-ver-chain", "text": "Which version of this record does the current state supersede, and how is the chain verified?", "kind": "lifecycle", "answer_data": [ "Previous-version reference and its digest", "Current version identifier and digest", "Chain verification result and gap flag" ] }, { "id": "dep-govp-q-ver-patch-grammar", "text": "Which patch grammar was used for this change, and why was it admissible for the affected subtree?", "kind": "process", "answer_data": [ "Patch grammar code and specification reference", "Admissibility justification against the null-value and array constraints", "Operation list or quad-difference summary" ] }, { "id": "dep-govp-q-ver-precondition", "text": "What precondition guarded this patch against applying to an unexpected state?", "kind": "constraint", "answer_data": [ "Expected pre-state digest or test-operation assertions", "Atomicity outcome (applied in full, or rejected without partial effect)", "Conflict-detection result" ] }, { "id": "dep-govp-q-ver-compatibility", "text": "What compatibility class does this change carry for downstream consumers of the affected dependency edge?", "kind": "decision", "answer_data": [ "Compatibility class (additive, corrective, restrictive)", "Rationale and affected element list", "Consumer notification requirement flag" ] } ], "data_elements": [ { "id": "dep-govp-de-version-id", "name": "Version identifier", "description": "Identifier of an immutable record state, distinct from the record identifier and free of date-like components.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-118" ] }, { "id": "dep-govp-de-previous-version", "name": "Previous-version reference", "description": "Reference to the immediately superseded version, forming the lineage chain a catalogue or consumer can traverse.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-118", "SRC-001" ] }, { "id": "dep-govp-de-patch-grammar", "name": "Patch grammar code", "description": "Which change grammar the patch uses: operation-sequence, merge-patch, or canonicalized quad difference.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-111", "SRC-112", "SRC-110" ] }, { "id": "dep-govp-de-pre-post-digest", "name": "Pre-state and post-state digest pair", "description": "Digests of the record's canonical form before and after the patch, used as the patch precondition and result binding.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-109", "SRC-111" ] }, { "id": "dep-govp-de-compatibility-class", "name": "Compatibility class", "description": "Declared effect of the change on downstream consumers: additive, corrective, or restrictive/breaking.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-111", "SRC-118" ] } ], "artifacts": [ { "id": "dep-govp-art-change-set", "name": "Change set (patch document)", "description": "A single proposed or applied change to one or more records, carrying the patch grammar, the operation sequence or quad difference, pre-state and post-state digests, compatibility class and the requesting agent reference. A change set is a proposal until a separate mutation operation commits it.", "media_or_form": [ "structured patch record in any serialization", "operation sequence or quad-difference listing" ], "serial": true, "identity_strategy": "Identified by a minted UUIDv7 or master-system change identifier; ordering derives from the recorded submission timestamp and the pre-state digest, never from a date embedded in the identifier.", "source_refs": [ "SRC-111", "SRC-112" ] } ], "inline_only_rationale": null }, { "id": "dep-govp-clock-discipline", "name": "Clock discipline and temporal validity", "description": "All time values are recorded as internet timestamps with seconds and an explicit offset or the Z designator. Three time axes are kept distinct and are never collapsed: the asserted event time at which the dependency or impact fact holds or held; the validity interval of the edge itself, expressed as a start and optional end; and the observation or ingestion time at which the record was captured by this model. Where the true local offset is unknown but the instant is known in UTC, the unknown-offset convention is used rather than falsely asserting Z. Leap-second values are accepted on input and their normalization must be disclosed.", "source_refs": [ "SRC-113", "SRC-013", "SRC-001", "SRC-118" ], "questions": [ { "id": "dep-govp-q-clock-axes", "text": "For this record, what are the asserted event time, the edge validity interval and the observation or ingestion time?", "kind": "temporal", "answer_data": [ "Asserted event timestamp with offset", "Validity start and optional validity end", "Observation or ingestion timestamp with offset" ] }, { "id": "dep-govp-q-clock-source", "text": "Which clock source produced each timestamp, and what is its known accuracy or skew?", "kind": "provenance", "answer_data": [ "Clock source reference per timestamp", "Stated accuracy, skew bound or synchronization method", "Trust qualifier for externally supplied timestamps" ] }, { "id": "dep-govp-q-clock-offset-fidelity", "text": "Was any recorded offset normalized or discarded on storage, and where is that disclosed?", "kind": "constraint", "answer_data": [ "Original offset as received", "Normalization applied and the store or projection that applied it", "Loss disclosure reference in the relevant projection profile" ] }, { "id": "dep-govp-q-clock-open-interval", "text": "How is an open-ended or not-yet-known end of a dependency's validity distinguished from an asserted permanent dependency?", "kind": "exception", "answer_data": [ "Open-interval marker semantics", "Explicit no-end assertion versus unknown-end assertion", "Review-due indication for open intervals" ] } ], "data_elements": [ { "id": "dep-govp-de-event-time", "name": "Asserted event time", "description": "Timestamp at which the asserted dependency or impact fact is claimed to hold, with seconds and an explicit offset or Z.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-113" ] }, { "id": "dep-govp-de-validity-interval", "name": "Edge validity interval", "description": "Start and optional end of the period during which the dependency relationship is asserted to hold, mirroring first-class relationship start and end times.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-113", "SRC-013" ] }, { "id": "dep-govp-de-observation-time", "name": "Observation or ingestion time", "description": "Timestamp at which this model captured or last confirmed the assertion; always distinct from event time and always required on a governed record.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-113", "SRC-118" ] }, { "id": "dep-govp-de-clock-source", "name": "Clock source and skew declaration", "description": "Reference to the clock or system that produced a timestamp, with its stated accuracy or synchronization method.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-113", "SRC-001" ] } ], "artifacts": [], "inline_only_rationale": "Time values are attributes of the record and of the relationship they qualify; there is no coherent standalone temporal document. Emitting a separate time artifact would create a second place where event time and observation time could disagree, which is precisely the failure this finding exists to prevent. Clock-source metadata is likewise a reference to an external time service, not an artifact this model produces." } ] }, { "id": "dep-govp-assurance", "name": "Validation, Conformance and Provenance Assurance", "description": "How a dependency or impact record is checked against declared constraints, how a conformance claim is made falsifiable, and how the assertion is attributed to a responsible agent and supporting evidence.", "source_refs": [ "SRC-049", "SRC-001", "SRC-015", "SRC-117", "SRC-038" ], "findings": [ { "id": "dep-govp-validation-conformance", "name": "Validation profile, severity and conformance claim", "description": "Validation is performed against a named shapes or schema graph at a stated version; the outcome is a report stating overall conformance plus individual results, each carrying the focus node, the path, the value, the source constraint and a severity of informational, warning or violation, with violation as the default. Conformance is claimed only against a named profile and a named validation run: a record with no violations under profile A is not thereby conformant to profile B. This model owns the request for validation and the retention of its report; it does not own the validation engine, and it never converts a validation outcome into an authorization or enforcement decision.", "source_refs": [ "SRC-049", "SRC-015" ], "questions": [ { "id": "dep-govp-q-val-profile", "text": "Against which named validation profile and version was this record checked?", "kind": "validation", "answer_data": [ "Validation profile identifier and version", "Shapes or schema graph reference and its digest", "Target selection rule used to pick focus nodes" ] }, { "id": "dep-govp-q-val-outcome", "text": "What is the conformance outcome, and which individual results were produced?", "kind": "requirement", "answer_data": [ "Overall conformance boolean", "Result list with focus node, path, value, source constraint and message", "Severity distribution across results" ] }, { "id": "dep-govp-q-val-severity-handling", "text": "How does the adopting Dimension treat warnings and informational results that do not block conformance?", "kind": "quality", "answer_data": [ "Severity-to-handling mapping", "Accepted-deviation register reference", "Remediation due indication" ] }, { "id": "dep-govp-q-val-engine-boundary", "text": "Which external engine executed the validation, and what stops its outcome from being treated as an authorization decision?", "kind": "authority", "answer_data": [ "Validating engine reference and version", "Statement that execution and enforcement are external to this model", "Consumer obligation note for downstream decisioning" ] } ], "data_elements": [ { "id": "dep-govp-de-validation-profile", "name": "Validation profile reference", "description": "Identifier, version and digest of the shapes or schema graph against which a record is validated.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-049" ] }, { "id": "dep-govp-de-conformance-flag", "name": "Conformance flag", "description": "Boolean stating whether the record conformed under the named profile in the named run; meaningless without both references.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-049" ] }, { "id": "dep-govp-de-validation-result", "name": "Validation result entry", "description": "One finding from a validation run: focus node, result path, offending value, source constraint, message and severity.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-049" ] }, { "id": "dep-govp-de-severity", "name": "Result severity", "description": "Coded severity of a validation result: informational, warning or violation, with violation as the default when unstated.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-049" ] } ], "artifacts": [ { "id": "dep-govp-art-validation-report", "name": "Validation report", "description": "Immutable outcome of one validation run over one or more records, stating overall conformance, the profile and engine used, and the individual results with their severities. Retained as evidence; it is not a decision and confers no permission.", "media_or_form": [ "structured report record in any serialization", "graph-shaped report for semantic projections", "human-readable summary rendering" ], "serial": true, "identity_strategy": "Identified by a minted UUIDv7 run identifier bound to the digests of the validated records and the profile; ordering derives from the run's recorded completion timestamp.", "source_refs": [ "SRC-049", "SRC-015" ] } ], "inline_only_rationale": null }, { "id": "dep-govp-provenance-custody", "name": "Provenance, attribution and custody of assertions", "description": "Every dependency edge and impact assessment is an assertion by some agent, derived from some evidence, produced by some activity. Provenance records which agent the assertion is attributed to, which activity generated it, which prior record it was derived or revised from, and which evidence supports it, including references and digests of external supply-chain evidence such as build attestations or bills of materials. Custody records the chain of responsible parties as the record moves between systems. Evidence is referenced by identifier and digest; this model does not verify signatures, evaluate trust or operate an attestation service.", "source_refs": [ "SRC-001", "SRC-117", "SRC-015", "SRC-038" ], "questions": [ { "id": "dep-govp-q-prov-attribution", "text": "To which agent is this dependency or impact assertion attributed, and in what role?", "kind": "provenance", "answer_data": [ "Responsible agent reference and agent type", "Role in the assertion (asserter, curator, importer, delegate)", "Attribution qualifier such as confidence or on-behalf-of relation" ] }, { "id": "dep-govp-q-prov-derivation", "text": "From which prior record or source was this assertion derived or revised, and by what activity?", "kind": "lifecycle", "answer_data": [ "Source record or dataset reference with digest", "Derivation or revision relation type", "Generating activity reference with start and end times" ] }, { "id": "dep-govp-q-prov-evidence", "text": "What external evidence supports this dependency edge, and how is it addressed immutably?", "kind": "evidence", "answer_data": [ "Evidence artifact reference (bill of materials, build attestation, scan output, human attestation)", "Evidence digest with algorithm", "Evidence type and stated coverage or completeness" ] }, { "id": "dep-govp-q-prov-custody", "text": "Which parties have held custody of this record since assertion, and where did responsibility transfer?", "kind": "ownership", "answer_data": [ "Custody chain entries with holder, start and end times", "Transfer reason and receiving-party acknowledgement reference", "Current custodian reference" ] }, { "id": "dep-govp-q-prov-verification-boundary", "text": "What verification of the supporting evidence has this model performed, and what has it deliberately not performed?", "kind": "security", "answer_data": [ "Digest-match check outcome, where performed", "Explicit statement that signature verification and trust evaluation are external", "Reference to the external verifier relied upon, if any" ] } ], "data_elements": [ { "id": "dep-govp-de-responsible-agent", "name": "Responsible agent reference", "description": "Agent to whom the assertion is attributed, with agent type and role, following the attribution pattern for entities and activities.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001" ] }, { "id": "dep-govp-de-derivation-ref", "name": "Derivation or revision reference", "description": "Reference to the prior entity from which this record was derived or of which it is a revision, with the relation type.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "dep-govp-de-evidence-ref", "name": "Evidence reference with digest", "description": "Immutable reference to supporting external evidence, carrying subject digest and algorithm so the evidence can be re-identified without being re-fetched.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-117", "SRC-015" ] }, { "id": "dep-govp-de-custody-entry", "name": "Custody chain entry", "description": "One holder of responsibility for the record over a time interval, with transfer reason and acknowledgement reference.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-038" ] }, { "id": "dep-govp-de-assertion-confidence", "name": "Assertion confidence qualifier", "description": "Qualifier expressing how strongly the asserting agent stands behind the edge, distinguishing observed, inferred and declared assertions.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-038" ] } ], "artifacts": [ { "id": "dep-govp-art-provenance-record", "name": "Provenance and custody record", "description": "Structured statement binding a dependency or impact record to its responsible agent, generating activity, derivation lineage, supporting evidence references with digests, and custody chain. It records claims; it performs no verification and grants no trust.", "media_or_form": [ "structured provenance record in any serialization", "graph-shaped provenance for semantic projections", "attestation-style statement referencing subject digests" ], "serial": true, "identity_strategy": "Identified by a minted UUIDv7 bound to the subject record digest and the generating activity reference; ordered by the activity's recorded end time.", "source_refs": [ "SRC-001", "SRC-117" ] } ], "inline_only_rationale": null } ] }, { "id": "dep-govp-operating-surface", "name": "Operating Surface and Delegated Boundaries", "description": "The interface-neutral declaration of what can be read, created, changed, projected and retired, and the explicit delegation of retention execution, access decisions and audit-trail ownership outside this model.", "source_refs": [ "SRC-111", "SRC-115", "SRC-038", "SRC-118" ], "findings": [ { "id": "dep-govp-operations-delegation", "name": "Query, mutation and delegated retention, access and audit boundaries", "description": "The operating surface is declared as capabilities, not endpoints: which selection expressions are supported and in what expression language, whether results are complete or truncated, which mutation operations are accepted and under what preconditions, and which projections are offered. Retirement of a record produces a tombstone that preserves the identifier, final digest, disposition reason and the policy reference authorising disposition, so that dangling references resolve to an explicit retired state rather than silently disappearing. Execution of erasure in downstream stores, the access decision itself, and the audit trail are owned by the adopting Dimension and the referenced retention, authorization and audit models; this model records the request, the reference and the outcome received, and never decides, enforces or stores the audit trail.", "source_refs": [ "SRC-111", "SRC-115", "SRC-038", "SRC-118" ], "questions": [ { "id": "dep-govp-q-ops-capability", "text": "Which query and mutation capabilities does this deployment declare, in which expression language, and with what completeness guarantee?", "kind": "process", "answer_data": [ "Supported selection expression language and version", "Supported mutation operations and their preconditions", "Result completeness flag and truncation rule" ] }, { "id": "dep-govp-q-ops-retention", "text": "What retention class applies to this record, which policy governs its disposition, and which party executes the disposition?", "kind": "retention", "answer_data": [ "Retention class and minimum retention period", "Governing retention policy reference held by the adopting Dimension", "Executing party reference and confirmation-of-execution record reference" ] }, { "id": "dep-govp-q-ops-tombstone", "text": "What does a retired dependency record leave behind so that inbound references remain resolvable?", "kind": "state", "answer_data": [ "Tombstone identifier equal to the retired record identifier", "Final content digest and last valid version reference", "Disposition reason, disposition timestamp and successor reference if any" ] }, { "id": "dep-govp-q-ops-access-delegation", "text": "Which external authority decides who may read or change a record, and what does this model contribute to that decision?", "kind": "access", "answer_data": [ "Policy reference and decision-point identifier held externally", "Decision inputs this model exposes (sensitivity label, tenant partition, owner package)", "Explicit statement that no decision or enforcement occurs here" ] }, { "id": "dep-govp-q-ops-audit-emission", "text": "Which governed operations must emit an audit event, and which model owns the resulting trail?", "kind": "interoperability", "answer_data": [ "List of auditable operations", "Minimum event fields to emit (operation, record identifier, version digests, actor reference, observation timestamp)", "Owning audit model or adopting-Dimension system reference" ] } ], "data_elements": [ { "id": "dep-govp-de-capability-entry", "name": "Capability declaration entry", "description": "One declared operation on the surface: kind (read, create, update, retire, project), its expression language or grammar, and its preconditions.", "value_kind": "object", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-111", "SRC-115" ] }, { "id": "dep-govp-de-retention-class", "name": "Retention class and policy reference", "description": "Coded retention class for the record plus a reference to the externally owned retention policy that governs disposition.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-038", "SRC-118" ] }, { "id": "dep-govp-de-tombstone", "name": "Tombstone state", "description": "Post-retirement state carrying the retired identifier, final digest, disposition reason, disposition timestamp and optional successor reference.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-038", "SRC-118" ] }, { "id": "dep-govp-de-sensitivity-label", "name": "Sensitivity label", "description": "Decision input describing the confidentiality class of the dependency assertion, supplied to an external decision point and never evaluated here.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-038" ] }, { "id": "dep-govp-de-audit-emission-spec", "name": "Audit emission requirement", "description": "Declaration of which operations must emit an audit event, the minimum fields, and the external system that owns the resulting trail.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-038" ] } ], "artifacts": [ { "id": "dep-govp-art-capability-descriptor", "name": "Operating-surface capability descriptor", "description": "Interface-neutral declaration of supported query, mutation, projection and retirement capabilities, their expression languages, preconditions and completeness guarantees, plus the references to the external policy, retention and audit systems this deployment delegates to.", "media_or_form": [ "structured capability record in any serialization", "human-readable service description" ], "serial": false, "identity_strategy": "Identified by deployment identifier plus descriptor version; each version is immutable and digest-bound, superseded by previous-version links rather than in-place edits.", "source_refs": [ "SRC-115", "SRC-118" ] }, { "id": "dep-govp-art-tombstone-record", "name": "Tombstone and disposition request record", "description": "Record produced when a dependency or impact record is retired: it preserves the identifier and final digest, states the disposition reason and governing policy reference, and carries the disposition request issued to the executing party together with any confirmation reference received back.", "media_or_form": [ "structured record in any serialization", "minimal reference stub for projections that cannot carry full state" ], "serial": true, "identity_strategy": "Reuses the retired record's identifier as its subject and is itself identified by a minted UUIDv7 disposition identifier; ordered by disposition timestamp, never by a date embedded in the identifier.", "source_refs": [ "SRC-038", "SRC-118" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "dep-mut-bundle-command-surface", "name": "Command surface and admission contract", "description": "What mutation commands exist for a dependency or impact statement, which transitions each one is allowed to make, who may issue them under which authority, and what must be supplied and true before a command is admitted.", "rationale": "A dependency statement is an assertion with a publication lifecycle (draft, active, retired) whose relationships are first-class records with their own creation metadata; before any change semantics can be specified, the permitted command set, the authority that gates promotion and the admission preconditions must be fixed, otherwise every downstream guarantee about history and effects is unenforceable.", "source_refs": [ "SRC-013", "SRC-125", "SRC-127", "SRC-103" ], "layers": [ { "id": "dep-mut-layer-command-catalogue", "name": "Command catalogue and authority gates", "description": "The closed set of mutation commands, the state transitions each produces, and the review and approval gates that control promotion from a draft assertion to an active one.", "source_refs": [ "SRC-125", "SRC-127", "SRC-103" ], "findings": [ { "id": "dep-mut-find-command-inventory", "name": "Command inventory and permitted state transitions", "description": "Enumerates the mutation commands defined for a dependency or impact statement (declare, validate, review, approve, activate, revise, correct, supersede, retire, observation-update), the lifecycle state each produces on the subject statement, which state-and-command pairs are legal, and how content-affecting commands are distinguished from workflow-only ones. The state spine is a specialization of the draft/active/retired/unknown publication vocabulary; refinement states such as in-review and approved are adopting-Dimension additions and are marked as such rather than claimed as standard.", "source_refs": [ "SRC-127", "SRC-125", "SRC-013" ], "questions": [ { "id": "dep-mut-q-command-set", "text": "Which mutation commands are defined for a dependency or impact statement, and which lifecycle state does each one produce?", "kind": "lifecycle", "answer_data": [ "Closed list of command type codes", "Resulting state code per command", "Marker for commands that produce no state change" ] }, { "id": "dep-mut-q-transition-matrix", "text": "Which state-and-command pairs are permitted, and which transitions must be rejected as invalid rather than silently ignored?", "kind": "state", "answer_data": [ "Transition triples of from-state, command type and to-state", "Rejection outcome code for an illegal transition", "Terminal states from which no further content change is allowed" ] }, { "id": "dep-mut-q-content-vs-workflow", "text": "How is a command that changes asserted meaning distinguished from one that only moves workflow state?", "kind": "classification", "answer_data": [ "Version-producing flag per command", "Content-affecting versus workflow-affecting classification", "List of fields whose change forces a new version" ] }, { "id": "dep-mut-q-agent-eligible-commands", "text": "Which commands may be issued by an automated agent without human review, and which require a human authority?", "kind": "authority", "answer_data": [ "Permitted actor class per command", "Observation-managed flag on the statement", "Reference to the authority model that resolves actor competence" ] } ], "data_elements": [ { "id": "dep-mut-de-command-type", "name": "Command type", "description": "Canonical verb identifying the mutation command being invoked, drawn from the closed catalogue published with the contract version.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-125", "SRC-127" ] }, { "id": "dep-mut-de-statement-state", "name": "Statement lifecycle state", "description": "Current lifecycle state of the dependency or impact statement, specializing draft, active, retired and unknown with any adopting-Dimension refinement states.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-127" ] }, { "id": "dep-mut-de-transition-rule", "name": "Permitted transition rule", "description": "Declared triple of originating state, command type and resulting state, together with the outcome code emitted when the pair is not permitted.", "value_kind": "object", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-127", "SRC-126" ] }, { "id": "dep-mut-de-version-producing-flag", "name": "Version-producing flag", "description": "Whether invoking this command creates a new immutable version of the statement rather than only recording workflow progress.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-124", "SRC-001" ] } ], "artifacts": [], "inline_only_rationale": "The command catalogue and its transition matrix are declarative contract data published with the model specification, not per-instance records. They are read as configuration by any conforming implementation; every instance-level trace of a transition is carried by the command record, approval record and version history entry declared in other findings, so minting a separate artifact here would duplicate identity and invite drift between the specification and its instances." }, { "id": "dep-mut-find-authority-gate", "name": "Review, approval and activation authority gate", "description": "The contract for the review, approve and activate commands: what a review disposition may say, which authority reference an approval must carry, when the approver must differ from the declarer, and how an emergency bypass is recorded. The disposition recorded here is a judgement about the fitness of the dependency statement, deliberately separate from any access-control decision, which is referenced from the authorization model and never rendered here.", "source_refs": [ "SRC-125", "SRC-103", "SRC-127", "SRC-001" ], "questions": [ { "id": "dep-mut-q-review-disposition", "text": "What disposition values may a review record carry, and which of them permit the statement to proceed to approval?", "kind": "decision", "answer_data": [ "Review workflow status code", "Disposition code such as persuasive or not-persuasive", "Flag stating whether the disposition unblocks approval" ] }, { "id": "dep-mut-q-approval-authority", "text": "Which authority reference must an approval record carry, and how is the approver's competence over this statement established?", "kind": "authority", "answer_data": [ "Approver party reference", "Authority or role reference under which approval is given", "Reference to the external authorization decision consulted", "Scope expression stating which statements the authority covers" ] }, { "id": "dep-mut-q-separation-of-duties", "text": "Under what conditions must the approver differ from the declarer, and how is that separation evidenced?", "kind": "constraint", "answer_data": [ "Separation-of-duties requirement flag", "Declarer party reference compared with approver party reference", "Outcome code emitted when the constraint is violated" ] }, { "id": "dep-mut-q-break-glass-approval", "text": "How is an emergency or break-glass approval recorded so that retrospective review is guaranteed?", "kind": "exception", "answer_data": [ "Exception code and justification text", "Granting authority reference", "Retrospective review due marker", "Timestamp of the exception grant" ] } ], "data_elements": [ { "id": "dep-mut-de-review-disposition", "name": "Review disposition", "description": "Judgement recorded by a reviewer about the dependency statement, using a disposition vocabulary aligned with artifact assessment dispositions.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-125" ] }, { "id": "dep-mut-de-approver-authority-ref", "name": "Approver authority reference", "description": "Reference to the role, mandate or delegation under which the approving party acted, resolved in the party or authority model rather than defined here.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-103" ] }, { "id": "dep-mut-de-authorization-decision-ref", "name": "Authorization decision reference", "description": "Pointer to the decision rendered by an external policy decision point for this command, including the decision value and the policy identifier it was rendered against.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-103" ] }, { "id": "dep-mut-de-exception-grant", "name": "Gate exception grant", "description": "Record of a bypass of the normal review or approval gate, carrying an exception code, justification, granting authority and a retrospective-review obligation marker.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-125", "SRC-103" ] } ], "artifacts": [ { "id": "dep-mut-art-approval-record", "name": "Review and approval decision record", "description": "A separable record asserting a review or approval judgement about a named version of a dependency or impact statement, carrying disposition, approver party and authority references, the consulted authorization decision reference, any exception grant, and the decision timestamp. It is separable precisely because its attribution and management rights differ from those of the statement it judges.", "media_or_form": [ "structured decision record", "signed attestation", "workflow assessment entry" ], "serial": true, "identity_strategy": "Use the authoritative master-system decision identifier issued by the governing workflow or registry; if none exists, a governed IRI minted in the adopting Dimension's namespace; otherwise a ULID. The record always cites the exact statement version token it judges, and a decision date is never used as identity.", "source_refs": [ "SRC-125", "SRC-124", "SRC-103" ] } ], "inline_only_rationale": null } ] }, { "id": "dep-mut-layer-admission-contract", "name": "Admission contract: envelope and validation", "description": "What every state-changing command must carry to be admitted, and how the validate command reports whether a statement and a proposed change satisfy the invariants owned elsewhere.", "source_refs": [ "SRC-119", "SRC-001", "SRC-126", "SRC-007" ], "findings": [ { "id": "dep-mut-find-command-envelope", "name": "Command envelope and admission preconditions", "description": "The interface-neutral envelope that accompanies every mutation command: command identity, acting agent and submitting software, subject statement binding, authorization decision reference, audit hook reference, required inputs per command type, and the timestamps that must be captured. Endpoint references named in a declare command must resolve, but resolving them is a read against the endpoint's owning model; the command never creates or alters an endpoint record.", "source_refs": [ "SRC-001", "SRC-007", "SRC-103", "SRC-013", "SRC-019" ], "questions": [ { "id": "dep-mut-q-command-identity", "text": "Which identifier identifies a mutation command instance, and what is used when no master-system identifier exists?", "kind": "identity", "answer_data": [ "Master-system command identifier", "Governed IRI fallback", "UUID or ULID fallback assigned by the adopting Dimension" ] }, { "id": "dep-mut-q-mandatory-envelope", "text": "Which envelope fields must every state-changing command carry before it can be admitted?", "kind": "requirement", "answer_data": [ "Actor party reference", "Subject statement reference and expected version token", "Authorization decision reference", "Command type and contract version identifier" ] }, { "id": "dep-mut-q-agent-provenance", "text": "How are the acting agent, the software that submitted the command, and the consulted authorization decision recorded as provenance?", "kind": "provenance", "answer_data": [ "Association of the command activity with a responsible agent and a role", "Software agent reference for automated submission", "Delegation or on-behalf-of chain", "Authorization decision reference" ] }, { "id": "dep-mut-q-command-timestamps", "text": "Which timestamps must a command record, and how are submission, decision and effective times kept apart?", "kind": "temporal", "answer_data": [ "Submission or ingestion timestamp", "Decision timestamp for gated commands", "Effective-from value asserted for the statement", "All values as RFC 3339 with seconds and explicit offset" ] } ], "data_elements": [ { "id": "dep-mut-de-command-id", "name": "Command identifier", "description": "Stable identifier of a single command instance, used to correlate its outcome record, version history entry, emitted events and audit hook.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-123", "SRC-124" ] }, { "id": "dep-mut-de-actor-ref", "name": "Acting agent reference", "description": "Reference to the human or software agent responsible for the command, optionally qualified with the role in which it acted and any on-behalf-of delegation.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001" ] }, { "id": "dep-mut-de-subject-ref", "name": "Subject statement reference", "description": "Reference to the dependency or impact statement the command acts on, plus the endpoint references the statement names, all resolved read-only against their owning models.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-013" ] }, { "id": "dep-mut-de-submitted-at", "name": "Command submission time", "description": "Time at which the command was received for processing, recorded separately from any effective time the command asserts about the dependency itself.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-007", "SRC-065" ] }, { "id": "dep-mut-de-audit-hook-ref", "name": "Audit hook reference", "description": "Correlation reference passed to the external audit model so the command can be reconciled with an audit record that this model neither writes nor retains.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-123" ] }, { "id": "dep-mut-de-lifecycle-scope-input", "name": "Declared lifecycle scope input", "description": "Lifecycle context supplied with a declare or revise command (for example build, runtime or test), because a build dependency and an operational dependency carry different implications.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-019", "SRC-013" ] } ], "artifacts": [ { "id": "dep-mut-art-command-record", "name": "Mutation command record", "description": "The immutable record of one submitted command: identity, command type, contract version, actor and software agent references, subject binding and expected version token, supplied inputs, authorization decision reference, audit hook reference, submission timestamp and terminal outcome pointer.", "media_or_form": [ "structured command record", "append-only journal entry", "signed request envelope" ], "serial": true, "identity_strategy": "Prefer the authoritative master-system command identifier from the system of record for the mutation; otherwise a governed IRI; otherwise a UUID or ULID. A client-supplied idempotency key and the request fingerprint are correlation and replay-detection values, never the record identity, and no timestamp is ever used as an identifier.", "source_refs": [ "SRC-119", "SRC-001", "SRC-128" ] } ], "inline_only_rationale": null }, { "id": "dep-mut-find-validation-contract", "name": "Validation contract and outcome reporting", "description": "The contract for the validate command: which classes of check run (envelope completeness, reference resolvability, transition legality, and the statement invariants defined by the structural area and referenced schemas), which findings block a transition and which are advisory, and what the outcome record must contain to be reproducible. Validation evaluates invariants owned elsewhere; this contract owns only when validation runs, what its outcome contains and whether an outcome blocks.", "source_refs": [ "SRC-126", "SRC-120", "SRC-013", "SRC-121" ], "questions": [ { "id": "dep-mut-q-validation-classes", "text": "Which classes of check does the validate command run, and which of them block a transition rather than warn?", "kind": "validation", "answer_data": [ "Check class identifier", "Severity level from fatal to information", "Blocking versus advisory flag per severity" ] }, { "id": "dep-mut-q-validation-reproducibility", "text": "What does a validation outcome record contain so that a failure is reproducible against a specific statement version?", "kind": "evidence", "answer_data": [ "Evaluated statement identifier and version token", "Expression or path locating each offending element", "Identifier and version of the rule set applied", "Timestamp of evaluation" ] }, { "id": "dep-mut-q-invariant-ownership", "text": "Who owns the invariant definitions that validation evaluates, and how are they referenced rather than restated here?", "kind": "ownership", "answer_data": [ "Reference to the owning structural model or schema", "Rule set version pin", "Statement that no rule text is stored locally" ] }, { "id": "dep-mut-q-unresolved-and-noassertion", "text": "How are advisory findings, unresolved references and explicit no-assertion values reported without blocking the command?", "kind": "quality", "answer_data": [ "Advisory issue codes", "Unresolved reference marker", "Distinction between asserted absence and no assertion", "Completeness qualifier on the statement" ] } ], "data_elements": [ { "id": "dep-mut-de-issue-severity", "name": "Validation issue severity", "description": "Severity assigned to a single validation finding, using a fatal, error, warning, information and success scale.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-126" ] }, { "id": "dep-mut-de-issue-code", "name": "Validation issue code", "description": "Machine-readable type of the validation finding, enabling a caller to distinguish a structural problem from a conflict, an unresolved reference or a policy-gate failure.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-126", "SRC-120" ] }, { "id": "dep-mut-de-issue-location", "name": "Validation issue location", "description": "Expression identifying the element within the evaluated statement or command envelope that produced the finding.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-126" ] }, { "id": "dep-mut-de-ruleset-ref", "name": "Applied rule set reference", "description": "Version-pinned reference to the externally owned profile, schema or invariant set that validation evaluated.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013", "SRC-126" ] }, { "id": "dep-mut-de-completeness-qualifier", "name": "Completeness qualifier", "description": "Qualifier stating whether the set of related endpoints asserted by the statement is complete, incomplete, explicitly none, or not asserted.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013" ] } ], "artifacts": [ { "id": "dep-mut-art-validation-report", "name": "Validation outcome report", "description": "A structured list of validation findings produced by one validate invocation, each with severity, issue code and location, bound to the evaluated statement version, the applied rule set version and the invoking command identifier.", "media_or_form": [ "structured outcome record", "issue list attached to a command record" ], "serial": true, "identity_strategy": "Use the master-system outcome identifier where the executing registry issues one; otherwise a ULID. The report always carries the invoking command identifier and the evaluated statement version token so that identity, subject and evidence remain separable.", "source_refs": [ "SRC-126", "SRC-120" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "dep-mut-bundle-execution-semantics", "name": "Execution guarantees, history and effects", "description": "How commands behave under repetition and concurrency, how immutable history is preserved across revision, correction, supersession and retirement, how machine observations refresh a statement, and what a command is allowed to return, emit and touch.", "rationale": "Dependency statements are frequently written by retrying clients and concurrent automated observers, and are relied on for downstream impact reasoning; without explicit replay, conflict, history and containment guarantees, a mutation contract silently permits duplicate assertions, lost updates, rewritten history and unintended side effects on records this model does not own.", "source_refs": [ "SRC-119", "SRC-124", "SRC-001", "SRC-054", "SRC-123" ], "layers": [ { "id": "dep-mut-layer-safe-application", "name": "Safe repetition and concurrent application", "description": "Replay detection for repeated submissions and precondition-based conflict detection for concurrent ones, including the atomicity unit when a command spans several statements.", "source_refs": [ "SRC-119", "SRC-124", "SRC-121", "SRC-122" ], "findings": [ { "id": "dep-mut-find-idempotency-replay", "name": "Idempotency scope, fingerprinting and replay behaviour", "description": "Defines when a repeated command is a replay that must return the original result rather than create a second statement, how the request fingerprint is computed over a canonical form, which envelope fields are excluded from the fingerprint, how long a key is honoured, and what happens when the same key arrives with different content. Declare is made effectively idempotent by a uniqueness criterion in the same style as a conditional create; review, approve, activate, supersede and retire are naturally idempotent because a repeated invocation leaves the intended state unchanged.", "source_refs": [ "SRC-119", "SRC-124", "SRC-122", "SRC-128" ], "questions": [ { "id": "dep-mut-q-replay-definition", "text": "What makes a repeated submission of the same command a replay rather than a new mutation?", "kind": "process", "answer_data": [ "Idempotency key value", "Matching request fingerprint", "Uniqueness criterion identifying an equivalent existing statement", "Replay outcome code distinguishing created from matched" ] }, { "id": "dep-mut-q-fingerprint-computation", "text": "How is the request fingerprint computed, and which envelope fields are excluded from it?", "kind": "identity", "answer_data": [ "Canonicalization scheme applied before hashing", "Hash algorithm identifier", "Excluded volatile fields such as receipt time and transport metadata" ] }, { "id": "dep-mut-q-replay-window", "text": "For how long is a replayed key honoured, and what happens after that window expires?", "kind": "temporal", "answer_data": [ "Replay window duration", "Expiry behaviour code", "Timestamp of first acceptance in RFC 3339 with offset" ] }, { "id": "dep-mut-q-key-conflict", "text": "What must happen when the same idempotency key arrives with a different payload?", "kind": "exception", "answer_data": [ "Fingerprint mismatch outcome code", "Problem type reference returned to the caller", "Assertion that no partial change is applied" ] } ], "data_elements": [ { "id": "dep-mut-de-idempotency-key", "name": "Idempotency key", "description": "Client-generated value used to recognize retries of the same command; a correlation value only, never the identity of the resulting record.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-128", "SRC-119" ] }, { "id": "dep-mut-de-request-fingerprint", "name": "Request fingerprint", "description": "Hash over the canonical serialization of the command's semantic content, used to decide whether a repeated key represents the same intended effect.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-122" ] }, { "id": "dep-mut-de-replay-window", "name": "Replay window", "description": "Declared period during which a previously seen idempotency key is honoured as a replay rather than treated as a new command.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-007", "SRC-128" ] }, { "id": "dep-mut-de-replay-outcome", "name": "Replay outcome", "description": "Result classification telling the caller whether the command created a new record, matched an existing equivalent one, or was refused because the key was reused with different content.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-124", "SRC-120" ] } ], "artifacts": [], "inline_only_rationale": "Idempotency is a property of the command contract and is materialized entirely as fields on the mutation command record already declared in the admission layer: the key, the fingerprint, the first-acceptance time and the replay outcome. Introducing a separate replay-ledger artifact would create a second identity for the same command instance and would push a purely operational implementation structure into a format-neutral semantic model; deduplication indexes are a storage projection, not context." }, { "id": "dep-mut-find-concurrency-atomicity", "name": "Version preconditions, conflict outcomes and atomicity", "description": "Requires every version-producing command to carry an expected-version precondition so that a concurrent writer cannot be overwritten unnoticed, defines how a precondition failure is reported distinctly from an illegal-transition conflict, fixes the atomicity unit when one command touches several statements, and states how these interface-neutral preconditions bind to a concrete protocol.", "source_refs": [ "SRC-119", "SRC-124", "SRC-121", "SRC-126" ], "questions": [ { "id": "dep-mut-q-version-precondition", "text": "Which precondition must a version-producing command carry so that a lost update is impossible?", "kind": "constraint", "answer_data": [ "Expected current version token", "Behaviour when the precondition is absent", "Outcome code when the token does not match" ] }, { "id": "dep-mut-q-conflict-classification", "text": "How is a precondition failure distinguished from a state-machine conflict in the outcome?", "kind": "state", "answer_data": [ "Distinct outcome codes for stale version and illegal transition", "Current state and current version token returned to the caller", "Retry guidance flag" ] }, { "id": "dep-mut-q-atomicity-unit", "text": "When one command touches several statements, what is the atomicity unit and what is rolled back on partial failure?", "kind": "process", "answer_data": [ "Declared atomicity mode such as all-or-nothing or per-statement", "Rollback scope description", "Partial-failure outcome list keyed by statement identifier" ] }, { "id": "dep-mut-q-precondition-binding", "text": "How do these preconditions bind to a concrete interface without the model itself depending on that interface?", "kind": "interoperability", "answer_data": [ "Mapping of the expected-version token to a protocol validator", "Mapping of conflict outcomes to protocol status signals", "Statement that the binding is declared by the interface layer" ] } ], "data_elements": [ { "id": "dep-mut-de-expected-version-token", "name": "Expected version token", "description": "Opaque token identifying the statement version the caller believes is current; the command is refused if it no longer matches.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-124", "SRC-119" ] }, { "id": "dep-mut-de-current-version-token", "name": "Current version token", "description": "Opaque token identifying the version actually current at evaluation time, returned to the caller on both success and conflict.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-124" ] }, { "id": "dep-mut-de-conflict-outcome", "name": "Conflict outcome", "description": "Classification of a refused command as a stale-version precondition failure, an illegal transition, or a competing concurrent command.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-119", "SRC-126" ] }, { "id": "dep-mut-de-atomicity-mode", "name": "Atomicity mode", "description": "Declared scope of all-or-nothing application when a single command carries changes to more than one statement or more than one field.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-121" ] } ], "artifacts": [], "inline_only_rationale": "Concurrency control produces no record of its own: the expected version token is an envelope field of the command record, the current token is a property of the version history entry, and a refusal is reported through the validation or failure outcome already declared elsewhere. Declaring a separate lock or transaction artifact would model an implementation mechanism rather than context, and would imply this model owns an execution engine it explicitly does not." } ] }, { "id": "dep-mut-layer-history-and-currency", "name": "Immutable history and assertion currency", "description": "How versions are preserved and linked across revision, correction, supersession and retirement, and how machine observations keep a statement current without rewriting what was previously asserted.", "source_refs": [ "SRC-001", "SRC-124", "SRC-065", "SRC-054" ], "findings": [ { "id": "dep-mut-find-revision-supersession", "name": "Immutable version identity, correction and supersession", "description": "Fixes the identity of a historical version as the pair of statement identifier and version token, forbids reuse of a token, and separates three distinct acts: revision, which asserts a changed but legitimately new state of affairs; correction, which marks an earlier version as erroneous without denying that it was recorded; and supersession, which closes one statement's currency in favour of a successor. Retirement ends applicability without asserting error. In all cases prior content remains readable and is never overwritten.", "source_refs": [ "SRC-001", "SRC-124", "SRC-065", "SRC-127" ], "questions": [ { "id": "dep-mut-q-version-identity", "text": "What identifies a specific historical version of a statement, and why can that identity never be reused?", "kind": "identity", "answer_data": [ "Statement identifier", "Version token unique within the statement", "Rule forbidding reuse after retirement or correction" ] }, { "id": "dep-mut-q-correction-vs-revision", "text": "How does a correction of an erroneous record differ from a revision and from a supersession in what each asserts about the past?", "kind": "lifecycle", "answer_data": [ "Change-nature code covering revision, correction, supersession and retirement", "Erroneous-record marker on the affected version", "Derivation link from the new version to the prior one", "Statement of what each act claims about the earlier assertion" ] }, { "id": "dep-mut-q-validity-interval", "text": "Which validity interval does supersession close, and how is that different from the record's transaction time?", "kind": "temporal", "answer_data": [ "Effective-from and effective-to of the asserted dependency", "Record creation and invalidation times", "Rule that the two timelines are recorded independently" ] }, { "id": "dep-mut-q-history-retention", "text": "What must remain readable after retirement, and what may never be overwritten by a later change?", "kind": "retention", "answer_data": [ "Set of fields preserved for every historical version", "Prohibition on in-place overwrite", "Reference to the external retention policy that governs destruction" ] }, { "id": "dep-mut-q-supersession-link", "text": "How is the link from a superseded statement to its successor represented so that both directions are traversable?", "kind": "relationship", "answer_data": [ "Superseded-by reference on the predecessor", "Supersedes reference on the successor", "Reason code for the supersession" ] } ], "data_elements": [ { "id": "dep-mut-de-version-token", "name": "Statement version token", "description": "Opaque, non-reusable token that, together with the statement identifier, identifies exactly one immutable historical version.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-124", "SRC-001" ] }, { "id": "dep-mut-de-previous-version-ref", "name": "Previous version reference", "description": "Derivation link from a version to the version it was produced from, expressing revision rather than independent creation.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "dep-mut-de-change-nature", "name": "Change nature", "description": "Classification of what a version-producing act asserts: revision of a legitimately changed fact, correction of an erroneous record, supersession by a successor, or retirement of applicability.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-065", "SRC-001", "SRC-127" ] }, { "id": "dep-mut-de-superseded-by-ref", "name": "Superseded-by reference", "description": "Reference from a statement whose currency has ended to the successor statement that replaces it.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-127", "SRC-013" ] }, { "id": "dep-mut-de-validity-interval", "name": "Asserted validity interval", "description": "Start and end of the period for which the dependency or impact is asserted to hold, recorded separately from the times at which records were created or invalidated.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013", "SRC-065", "SRC-007" ] }, { "id": "dep-mut-de-erroneous-marker", "name": "Entered-in-error marker", "description": "Marker stating that a specific version should never have been asserted, preserved alongside the original content rather than replacing it.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-065", "SRC-001" ] } ], "artifacts": [ { "id": "dep-mut-art-version-history-entry", "name": "Statement version history entry", "description": "An immutable entry recording one version of a dependency or impact statement: version token, producing command identifier, change nature, previous-version and superseded-by links, asserted validity interval, record creation and invalidation times, and any entered-in-error marker.", "media_or_form": [ "append-only version record", "immutable history entry", "content-addressed snapshot" ], "serial": true, "identity_strategy": "Identity is the pair of the statement's authoritative master-system identifier and its version token; where the statement has no master-system identifier, a governed IRI or a ULID is used for the statement and the token remains a monotonic, opaque, never-reused sequence within it. Version tokens are not dates.", "source_refs": [ "SRC-124", "SRC-001", "SRC-122" ] } ], "inline_only_rationale": null }, { "id": "dep-mut-find-observation-update", "name": "Observation-update command for machine-asserted dependency facts", "description": "The contract for refreshing a statement from automated observation: which observer, procedure and confidence must accompany the update, how the time the dependency condition held is kept separate from the time the observation completed or was ingested, how an observer expresses that a dependency is no longer present as opposed to unknown, and when an observation may change a statement directly rather than being attached as competing evidence to a human-declared one.", "source_refs": [ "SRC-054", "SRC-065", "SRC-013", "SRC-007" ], "questions": [ { "id": "dep-mut-q-observer-attribution", "text": "Which observer, procedure and confidence values must an observation-update carry to be usable as evidence?", "kind": "measurement", "answer_data": [ "Observer or sensing agent reference", "Procedure or scan method reference", "Confidence or reliability value", "Observed property identifier" ] }, { "id": "dep-mut-q-observation-times", "text": "How are the time the dependency condition held and the time the observation was completed or ingested recorded separately?", "kind": "temporal", "answer_data": [ "Phenomenon time of the observed condition", "Result time when the observation completed", "Ingestion time when the update was received", "All values in RFC 3339 with seconds and explicit offset" ] }, { "id": "dep-mut-q-observed-absence", "text": "How does an observation that no longer sees a dependency express absence rather than ignorance?", "kind": "quality", "answer_data": [ "Explicit asserted-none value", "Explicit no-assertion value", "Coverage or scope statement of what the observer could see" ] }, { "id": "dep-mut-q-observation-precedence", "text": "When does an observation-update supersede a human-declared statement, and when must it only be attached as competing evidence?", "kind": "decision", "answer_data": [ "Observation-managed flag on the statement", "Precedence rule between asserted and observed statements", "Marker that the statement now carries unreconciled competing evidence", "Reference to the approval gate that remains unbypassed" ] } ], "data_elements": [ { "id": "dep-mut-de-observer-ref", "name": "Observer reference", "description": "Reference to the sensor, scanner or agent that made the observation, resolved in the tooling or party model rather than defined here.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-054", "SRC-001" ] }, { "id": "dep-mut-de-phenomenon-time", "name": "Phenomenon time", "description": "Time or interval to which the observed dependency condition applies, as distinct from when the observation was carried out.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-054", "SRC-007" ] }, { "id": "dep-mut-de-result-time", "name": "Result time", "description": "Instant at which the observing activity was completed, recorded independently of the phenomenon time and of the ingestion time of the command.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-054", "SRC-065" ] }, { "id": "dep-mut-de-observed-presence", "name": "Observed presence value", "description": "Whether the observer saw the dependency as present, explicitly absent, or could make no assertion about it.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-013", "SRC-065" ] }, { "id": "dep-mut-de-observation-confidence", "name": "Observation confidence", "description": "Reported confidence or reliability of the observation, used by precedence rules rather than by any computation owned here.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-054" ] } ], "artifacts": [ { "id": "dep-mut-art-observation-statement", "name": "Observation-update statement record", "description": "A record of one machine observation about a dependency statement: observer and procedure references, observed presence value, confidence, phenomenon time, result time, ingestion time, coverage scope, and the resulting statement version if the observation was allowed to change it.", "media_or_form": [ "structured observation record", "sensor or scanner report entry", "evidence attachment to a statement version" ], "serial": true, "identity_strategy": "Identity is the observer source identifier combined with the observation identifier issued by that observer, which must be unique per source; where the observer issues no identifier, the adopting Dimension assigns a ULID. Phenomenon or result time is evidence, never identity.", "source_refs": [ "SRC-054", "SRC-123", "SRC-065" ] } ], "inline_only_rationale": null } ] }, { "id": "dep-mut-layer-effects-and-containment", "name": "Command effects, signals and containment", "description": "What a command returns, how it reports failure, which events it must emit, and the hard limits on what it may change or set in motion.", "source_refs": [ "SRC-120", "SRC-123", "SRC-103", "SRC-119" ], "findings": [ { "id": "dep-mut-find-effect-contract", "name": "Result, failure, emitted events and side-effect containment", "description": "Specifies the success result a caller receives (resulting state, new version token, produced record references), the structured failure representation that distinguishes retryable conditions from ones requiring a corrected request without leaking exploitable detail, the change events that must be emitted with an envelope whose identity is unique per producer, and the containment rules: a command may create or modify only records this model owns plus the named statement, and may never create, modify or delete an endpoint record, evaluate or enforce a policy, write audit evidence, or trigger resolution, deployment, remediation or notification delivery.", "source_refs": [ "SRC-120", "SRC-123", "SRC-103", "SRC-013", "SRC-126" ], "questions": [ { "id": "dep-mut-q-emitted-events", "text": "Which change events must a command emit, and which envelope attributes make an event uniquely identifiable and correlatable?", "kind": "event", "answer_data": [ "Event type per command outcome", "Producer source identifier and event identifier unique within it", "Subject reference naming the affected statement", "Event time and correlation identifier" ] }, { "id": "dep-mut-q-success-result", "text": "What does a successful command return so that a caller can act without re-reading the statement?", "kind": "requirement", "answer_data": [ "Resulting lifecycle state", "New current version token", "References to records produced such as outcome and history entries", "Replay or created indicator" ] }, { "id": "dep-mut-q-failure-representation", "text": "How are failures represented so a caller can tell a retryable condition from one that requires a corrected request?", "kind": "exception", "answer_data": [ "Problem type identifier and short title", "Instance reference for this occurrence", "Retryable flag or guidance", "Rule against embedding sensitive internal detail" ] }, { "id": "dep-mut-q-forbidden-mutations", "text": "Which records outside this model's boundary must a command never create, modify or delete?", "kind": "constraint", "answer_data": [ "List of externally owned record classes such as endpoints, policies and audit records", "Read-only resolution rule for referenced endpoints", "Outcome code when a command attempts an out-of-boundary write" ] }, { "id": "dep-mut-q-forbidden-actions", "text": "Which downstream actions must a command never trigger directly, and how is that separation expressed in the effect list?", "kind": "process", "answer_data": [ "Prohibited action list covering resolution, deployment, remediation and notification delivery", "Statement that emitted events are signals rather than instructions", "Reference to the model that owns each prohibited action" ] } ], "data_elements": [ { "id": "dep-mut-de-result-status", "name": "Command result status", "description": "Terminal outcome of a command instance: accepted, matched as a replay, refused on precondition, refused on validation, or refused on authorization reference.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-120", "SRC-126", "SRC-119" ] }, { "id": "dep-mut-de-problem-type", "name": "Problem type reference", "description": "Stable identifier of the failure category, resolvable to human-readable documentation and accompanied by an occurrence-specific instance reference.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-120" ] }, { "id": "dep-mut-de-event-type", "name": "Emitted event type", "description": "Type value describing the change signal emitted for a command outcome, minted in the adopting Dimension's own namespace.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-123" ] }, { "id": "dep-mut-de-event-source", "name": "Emitted event source", "description": "Producer identifier that, combined with the event identifier, must be unique for each distinct emitted event.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-123" ] }, { "id": "dep-mut-de-correlation-id", "name": "Correlation identifier", "description": "Shared value linking the command record, the emitted events and the external audit hook so that a single mutation can be reconstructed across boundaries.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-123", "SRC-001" ] } ], "artifacts": [ { "id": "dep-mut-art-change-event", "name": "Emitted change-event envelope", "description": "The envelope of a signal emitted when a dependency or impact statement changes state: event identifier and producer source, event type, subject reference to the affected statement, event time, correlation identifier and the resulting version token. It announces that a change occurred and never instructs a consumer to act.", "media_or_form": [ "structured event envelope", "message payload", "change-feed entry" ], "serial": true, "identity_strategy": "Identity is the producer source identifier combined with an event identifier that the producer must keep unique for each distinct event; the subject reference and version token identify what changed, and the event time is never used as identity. Delivery identifiers assigned by transport are out of scope.", "source_refs": [ "SRC-123", "SRC-119" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "dep-qry-read-surface", "name": "Dependency and impact read surface", "description": "The set of read operations an agent may invoke against dependency assertions held by an adopting Dimension, and the meaning of each returned result class: stored assertions, traversed regions, computed paths, comparisons, scenario projections and referenced health indicators.", "rationale": "A dependency mixin is only useful if callers can ask bounded, reproducible questions. Grounding each operation in an existing normative read pattern (dataset-scoped pattern matching and property paths, datetime-negotiated prior states, resolved-versus-declared dependency graphs) keeps the surface small, explicit and testable, and keeps derived answers separable from asserted ones.", "source_refs": [ "SRC-129", "SRC-131", "SRC-013", "SRC-133" ], "layers": [ { "id": "dep-qry-assertion-reads", "name": "Assertion reads and temporal framing", "description": "Reads that return stored dependency assertions for a resolved endpoint, either at the current reference point or as of a stated instant on an explicitly named temporal axis.", "source_refs": [ "SRC-129", "SRC-131", "SRC-013" ], "findings": [ { "id": "dep-qry-current-read", "name": "Current stored-assertion read contract", "description": "Contract for returning the dependency assertions an adopting Dimension currently holds for a resolved subject endpoint: which filters are honoured, how each returned edge is marked as stored rather than inferred, observed or scenario-derived, and which provenance references travel with each edge. No inference is performed implicitly.", "source_refs": [ "SRC-129", "SRC-013", "SRC-132", "SRC-001" ], "questions": [ { "id": "dep-qry-current-read-q-subject", "text": "Which subject endpoint identifier anchors the read, and under which identifier authority is it resolved?", "kind": "identity", "answer_data": [ "Endpoint identifier value with its issuing authority or namespace", "Resolution outcome (resolved, ambiguous, unresolved) and the alias or equivalence set applied", "Identifier resolution policy version used" ] }, { "id": "dep-qry-current-read-q-filter", "text": "Which edge types, roles and attribute predicates constrain the returned assertion set?", "kind": "constraint", "answer_data": [ "Requested edge-type codes with their code-system reference", "Attribute predicates accepted and applied", "Requested filters rejected as unsupported, with the rejection reason" ] }, { "id": "dep-qry-current-read-q-stored", "text": "How does the response mark each returned edge as a stored assertion rather than an inferred, observed or scenario result?", "kind": "classification", "answer_data": [ "Derivation class code per edge (stored-assertion, inferred-path, observation, scenario-result)", "Reference to the underlying assertion record for stored edges", "Reference to the inference or propagation rule where the class is not stored-assertion" ] }, { "id": "dep-qry-current-read-q-attribution", "text": "Which agent asserted each returned edge, on what evidence, and when was that assertion recorded?", "kind": "provenance", "answer_data": [ "Asserting agent reference", "Evidence, method or detection technique reference", "Assertion recording timestamp distinct from the period the edge holds" ] } ], "data_elements": [ { "id": "dep-qry-subject-endpoint-ref", "name": "Subject endpoint reference", "description": "Resolved reference to the node the read is anchored on, carrying the identifier and its issuing authority.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-013", "SRC-132" ] }, { "id": "dep-qry-edge-type-filter", "name": "Edge-type filter", "description": "Namespaced dependency edge-type codes the caller asked to be included; an empty filter means the published default set, never 'all types'.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-013", "SRC-132" ] }, { "id": "dep-qry-derivation-class", "name": "Derivation class", "description": "Per-edge marker separating stored assertions from inferred paths, observations and scenario-derived results.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-133" ] }, { "id": "dep-qry-assertion-provenance-ref", "name": "Assertion provenance reference", "description": "Reference to the asserting agent, evidence and source record for a returned stored edge.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001", "SRC-013" ] } ], "artifacts": [ { "id": "dep-qry-assertion-result-set", "name": "Dependency assertion result set", "description": "Immutable issue of the edges matched by one read, each carrying its derivation class and provenance references, together with the resolved scope, bound reference point and result-integrity block.", "media_or_form": [ "structured result set (format-neutral)", "tabular edge projection", "graph fragment projection" ], "serial": true, "identity_strategy": "Use the assertion store's native result or snapshot identifier when the master system issues one; otherwise mint a UUID or ULID in the adopting Dimension's namespace and bind it to the resolved scope identifier and reference-point identifier. The identifier never encodes a date.", "source_refs": [ "SRC-129", "SRC-013", "SRC-132" ] } ], "inline_only_rationale": null }, { "id": "dep-qry-as-of-read", "name": "As-of read and temporal axis binding", "description": "Contract for reading assertions as they stood at a stated point. The read must name the axis it binds (the period during which the dependency held, versus the time the assertion was recorded or observed), disclose how a requested instant was resolved to an available reference point, and behave explicitly when the request falls outside the retained horizon.", "source_refs": [ "SRC-131", "SRC-013", "SRC-001", "SRC-130" ], "questions": [ { "id": "dep-qry-as-of-read-q-axis", "text": "Does the as-of instant apply to the period the dependency held, or to the time the assertion was recorded or observed?", "kind": "temporal", "answer_data": [ "Temporal axis code (valid-time, assertion-time, observation-time)", "Axis support declaration for the underlying source", "Axis marked unknown where the source cannot separate them" ] }, { "id": "dep-qry-as-of-read-q-resolution", "text": "How is a requested instant resolved when no reference point exists exactly at it, and how is the resolved point disclosed?", "kind": "process", "answer_data": [ "Requested instant as supplied by the caller", "Resolved reference point identifier and its instant", "Resolution rule applied (nearest preceding, nearest following, exact-only) and the resulting offset" ] }, { "id": "dep-qry-as-of-read-q-retroactive", "text": "How are retroactive corrections represented so that repeating the same as-of read can legitimately return a different answer?", "kind": "provenance", "answer_data": [ "Correction or supersession reference for affected assertions", "Assertion-time of the correction distinct from the corrected valid-time period", "Flag marking a result as affected by later corrections when re-read" ] }, { "id": "dep-qry-as-of-read-q-horizon", "text": "What is the earliest retained reference point, and how is a request before that horizon answered?", "kind": "exception", "answer_data": [ "Earliest retained reference point and its instant", "Explicit out-of-horizon error rather than a silent fall back to current state", "Pointer to the retention policy owner for the horizon" ] } ], "data_elements": [ { "id": "dep-qry-as-of-instant", "name": "Requested as-of instant", "description": "The instant supplied by the caller, expressed with an explicit offset; absence means the current reference point.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-131" ] }, { "id": "dep-qry-temporal-axis", "name": "Temporal axis", "description": "Named axis the as-of instant binds to, distinguishing when the dependency held from when it was asserted or observed.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-013", "SRC-001" ] }, { "id": "dep-qry-resolved-reference-point", "name": "Resolved reference point", "description": "Identifier of the reference point actually read, to which every operation of the invocation is bound.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-131", "SRC-130" ] }, { "id": "dep-qry-earliest-reference-point", "name": "Earliest retained reference point", "description": "The oldest reference point still retrievable, disclosed so a caller can distinguish 'no data then' from 'not retained'.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-131" ] } ], "artifacts": [ { "id": "dep-qry-as-of-binding-record", "name": "As-of binding record", "description": "The temporal binding block attached to a result: requested instant, temporal axis, resolution rule, resolved reference point, offset from the request and the retained horizon at issue time.", "media_or_form": [ "structured envelope block attached to a result artifact", "standalone binding record referenced by identifier" ], "serial": true, "identity_strategy": "Derive from the master system's snapshot or version identifier where one exists; otherwise mint a UUID or ULID bound to the query-invocation identifier. Instants are attributes of the record, never its identifier.", "source_refs": [ "SRC-131", "SRC-013" ] } ], "inline_only_rationale": null } ] }, { "id": "dep-qry-traversal-reads", "name": "Traversal and path reads", "description": "Reads that expand beyond one edge: bounded neighborhood expansion around seed endpoints, and path queries asking whether and how two endpoints are connected.", "source_refs": [ "SRC-129", "SRC-133", "SRC-135" ], "findings": [ { "id": "dep-qry-neighborhood", "name": "Endpoint-neighborhood traversal contract", "description": "Contract for bounded expansion from one or more seed endpoints: explicit direction, depth, breadth and budget bounds, how repeated visits and parallel edges are handled, how multiple seeds combine, and mandatory stop reasons so a partial region is never mistaken for the whole region.", "source_refs": [ "SRC-129", "SRC-133", "SRC-132" ], "questions": [ { "id": "dep-qry-neighborhood-q-direction", "text": "In which direction is the neighborhood expanded, and how is that direction recorded on every returned edge?", "kind": "relationship", "answer_data": [ "Direction code (upstream-dependencies, downstream-dependents, both)", "Per-edge orientation preserved as asserted (from-endpoint and to-endpoint)", "Rejection of the request when no direction is stated and no published default applies" ] }, { "id": "dep-qry-neighborhood-q-bounds", "text": "Which depth, breadth and budget bounds apply, and what is emitted when a bound halts expansion before the region is exhausted?", "kind": "constraint", "answer_data": [ "Maximum depth, maximum node and edge budgets, and time budget applied", "Stop reason codes per frontier (depth-reached, budget-reached, scope-boundary, source-unavailable)", "Frontier endpoints left unexpanded" ] }, { "id": "dep-qry-neighborhood-q-multiplicity", "text": "How are repeated visits to the same endpoint and parallel edges between the same pair collapsed or preserved?", "kind": "quality", "answer_data": [ "Endpoint de-duplication rule and whether visit counts are retained", "Parallel-edge policy (preserve per edge type and assertion, or collapse)", "Whether the seed endpoint itself is included in the returned region" ] }, { "id": "dep-qry-neighborhood-q-seeds", "text": "How are multiple seed endpoints combined, and is the combination a union of regions or an intersection?", "kind": "composition", "answer_data": [ "Seed combination mode (union, intersection, per-seed partition)", "Per-endpoint attribution to the seed or seeds that reached it", "Behaviour when one seed fails to resolve while others succeed" ] } ], "data_elements": [ { "id": "dep-qry-traversal-direction", "name": "Traversal direction", "description": "Explicit direction of expansion relative to the seed, never defaulted silently.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-013", "SRC-132" ] }, { "id": "dep-qry-traversal-bound", "name": "Traversal bound", "description": "Applied depth, node, edge or time bound, recorded with the value actually enforced rather than the value requested.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-130", "SRC-133" ] }, { "id": "dep-qry-stop-reason", "name": "Traversal stop reason", "description": "Reason expansion halted at a given frontier, required whenever the region returned is not exhaustive for the resolved scope.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-133", "SRC-132" ] }, { "id": "dep-qry-frontier-endpoint-ref", "name": "Unexpanded frontier endpoint", "description": "Endpoint reached but not expanded, disclosed so the caller knows where the region was cut.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-129", "SRC-133" ] } ], "artifacts": [ { "id": "dep-qry-neighborhood-projection", "name": "Neighborhood projection", "description": "Immutable issue of the endpoints and edges visited by one bounded traversal, with direction, applied bounds, stop reasons and unexpanded frontier, bound to a single resolved scope and reference point.", "media_or_form": [ "structured graph fragment (nodes and directed edges)", "adjacency projection", "hierarchical tree projection with explicit revisit markers" ], "serial": true, "identity_strategy": "Mint a UUID or ULID for the traversal invocation in the adopting Dimension's namespace, bound to the seed endpoint identifiers, direction, resolved scope and reference point; prefer the master system's traversal identifier when one is issued.", "source_refs": [ "SRC-129", "SRC-133" ] } ], "inline_only_rationale": null }, { "id": "dep-qry-path-query", "name": "Path query, path mode and direction-reversal contract", "description": "Contract for asking whether and how two endpoints are connected: the declared path mode governing repetition of nodes and edges, whether the answer enumerates individual paths or only reports connectivity between endpoint pairs, how cycles are kept finite, and which edge types may be traversed in reverse.", "source_refs": [ "SRC-129", "SRC-135", "SRC-073", "SRC-013" ], "questions": [ { "id": "dep-qry-path-query-q-mode", "text": "Which declared path mode governs repetition of nodes and edges along a returned path?", "kind": "constraint", "answer_data": [ "Path mode code (walk, trail, simple, acyclic) with its code-system reference", "Whether the projection's engine natively supports the requested mode", "Explicit rejection when the requested mode cannot be honoured" ] }, { "id": "dep-qry-path-query-q-shape", "text": "Does the result enumerate individual paths, or report only that a connection exists between an endpoint pair?", "kind": "definition", "answer_data": [ "Result shape code (path-enumeration, endpoint-pair-connectivity, shortest-path-only)", "Whether path multiplicity is counted or deliberately not counted", "Maximum number of paths returned and whether more exist" ] }, { "id": "dep-qry-path-query-q-cycles", "text": "How are cycles handled so a connectivity answer stays finite without silently dropping members of a cycle?", "kind": "quality", "answer_data": [ "Cycle handling rule implied by the declared path mode", "Cycle detection markers on returned endpoints or edges", "Disclosure when cycle handling reduced the number of reported paths" ] }, { "id": "dep-qry-path-query-q-inversion", "text": "When traversal runs against the asserted edge direction, which edge types are semantically invertible and which must not be reversed?", "kind": "relationship", "answer_data": [ "Per-edge-type invertibility flag and the inverse type where a named inverse exists", "Edge types excluded from reverse traversal with the exclusion reason", "Record of whether each returned edge was traversed forward or in reverse" ] }, { "id": "dep-qry-path-query-q-unreachable", "text": "What does an unreachable determination mean, and which qualifications must accompany it?", "kind": "evidence", "answer_data": [ "Unreachability statement scoped to the resolved scope, path mode, direction and reference point", "Completeness code and truncation state at the time of the determination", "Explicit statement that unreachability under an open-world scope is not independence" ] } ], "data_elements": [ { "id": "dep-qry-path-mode", "name": "Path mode", "description": "Declared repetition rule for nodes and edges along returned paths, aligned to the GQL walk/trail/simple/acyclic vocabulary.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-135", "SRC-129" ] }, { "id": "dep-qry-path-result-shape", "name": "Path result shape", "description": "Whether the answer enumerates paths, reports endpoint-pair connectivity only, or returns a single shortest path.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-129", "SRC-135" ] }, { "id": "dep-qry-edge-invertibility", "name": "Edge-type invertibility", "description": "Per-edge-type declaration of whether reverse traversal preserves meaning, and the named inverse type where one exists.", "value_kind": "boolean", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-013", "SRC-132" ] }, { "id": "dep-qry-traversal-orientation", "name": "Per-edge traversal orientation", "description": "Marker recording whether each edge on a returned path was traversed in its asserted direction or in reverse.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-129", "SRC-013" ] } ], "artifacts": [ { "id": "dep-qry-path-result", "name": "Path query result", "description": "Immutable issue of a path query: the declared mode and shape, returned paths or connectivity determinations, per-edge orientation, cycle markers, and any unreachable determination with its scope and completeness qualification.", "media_or_form": [ "ordered path list with per-edge orientation", "endpoint-pair connectivity table", "single shortest-path projection" ], "serial": true, "identity_strategy": "Mint a UUID or ULID for the path-query invocation, bound to source and target endpoint identifiers, path mode, result shape, resolved scope and reference point; use the master system's query identifier where one is issued.", "source_refs": [ "SRC-129", "SRC-135" ] } ], "inline_only_rationale": null } ] }, { "id": "dep-qry-derived-reads", "name": "Comparison, scenario and referenced-indicator reads", "description": "Reads whose answers are computed rather than stored: differences between two bound reads, scenario-bound impact projections, and read-through references to externally produced dependency-health indicators.", "source_refs": [ "SRC-001", "SRC-012", "SRC-133" ], "findings": [ { "id": "dep-qry-comparison", "name": "Comparison read between two bound reads", "description": "Contract for diffing two bound reads (two as-of points, two scopes, or asserted versus observed sets) into added, removed and changed edge sets, with a comparability test that prevents scope, filter, truncation or exclusion differences being reported as substantive change.", "source_refs": [ "SRC-130", "SRC-013", "SRC-001", "SRC-014" ], "questions": [ { "id": "dep-qry-comparison-q-basis", "text": "Which two bound reads form the comparison basis, and are their resolved scopes, filters and completeness declarations identical?", "kind": "validation", "answer_data": [ "References to both bound reads with their scope and reference-point identifiers", "Field-by-field comparability test result across scope, filters, direction and path mode", "Comparability flag with the reasons any dimension differs" ] }, { "id": "dep-qry-comparison-q-classes", "text": "How is each difference classified between the two bases?", "kind": "classification", "answer_data": [ "Difference class per edge (added, removed, attribute-changed, unchanged, re-asserted-without-change)", "Changed attribute names and their before and after values", "Count per difference class" ] }, { "id": "dep-qry-comparison-q-artefacts", "text": "How are differences caused by scope, filter, truncation or authorization exclusion separated from real change?", "kind": "quality", "answer_data": [ "Incomparability reason codes attached to affected edges rather than a change class", "Edges suppressed from the difference set because one side was truncated or withheld", "Residual set of differences that remain attributable to substantive change" ] }, { "id": "dep-qry-comparison-q-empty", "text": "What does an empty difference set mean, and under which declaration may it be reported as 'no change'?", "kind": "evidence", "answer_data": [ "Completeness code of both bases", "Truncation state of both bases", "Permitted phrasing, restricted to 'no change within the compared scope' unless both bases are complete and untruncated" ] } ], "data_elements": [ { "id": "dep-qry-comparison-basis-ref", "name": "Comparison basis reference", "description": "References to exactly the two bound reads being compared, each carrying its resolved scope and reference point.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-130", "SRC-131" ] }, { "id": "dep-qry-difference-class", "name": "Difference class", "description": "Per-edge classification of the difference between the two bases.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-013" ] }, { "id": "dep-qry-comparability-flag", "name": "Comparability flag", "description": "Whether the two bases are comparable at all; false forces every difference to be reported as indeterminate.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-014", "SRC-132" ] }, { "id": "dep-qry-incomparability-reason", "name": "Incomparability reason", "description": "Reason a difference cannot be attributed to substantive change, such as differing filters, truncation on one side, or withheld edges.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-014", "SRC-103" ] } ], "artifacts": [ { "id": "dep-qry-comparison-report", "name": "Dependency comparison report", "description": "Immutable issue holding the two basis references, the comparability verdict, classified differences, suppressed differences with incomparability reasons, and the combined completeness and truncation states of both bases.", "media_or_form": [ "structured difference set keyed by edge", "side-by-side basis summary", "narrative difference report projection" ], "serial": true, "identity_strategy": "Mint a UUID or ULID bound to the ordered pair of basis read identifiers; the report inherits no identifier from either basis and never uses a date as an identifier.", "source_refs": [ "SRC-130", "SRC-013" ] } ], "inline_only_rationale": null }, { "id": "dep-qry-impact-scenario", "name": "Scenario-bound impact projection contract", "description": "Contract for 'what is affected if X changes, fails or is removed' reads. The result is computed under a stated hypothesis and a referenced propagation rule set, is labelled derived and non-authoritative with a validity window, is never written back as a stored assertion, and cites rather than restates external status assertions.", "source_refs": [ "SRC-001", "SRC-012", "SRC-129", "SRC-073" ], "questions": [ { "id": "dep-qry-impact-scenario-q-hypothesis", "text": "Which hypothesis and which referenced propagation rule set produced this impact set?", "kind": "process", "answer_data": [ "Hypothesis descriptor (change, removal, failure, version transition) with its affected endpoints", "Propagation rule-set reference with resolvable version", "Parameters supplied to the rule set for this invocation" ] }, { "id": "dep-qry-impact-scenario-q-qualifier", "text": "How is each endpoint in the impact set qualified?", "kind": "classification", "answer_data": [ "Impact qualifier per endpoint (reachable-by-rule, conditionally-impacted, shielded-by-stated-condition, indeterminate)", "The rule or condition that produced the qualifier", "Distance or propagation depth from the hypothesised endpoint" ] }, { "id": "dep-qry-impact-scenario-q-authority", "text": "How is the result marked as derived and non-authoritative, and for how long may it be relied on?", "kind": "provenance", "answer_data": [ "Derivation class fixed to scenario-result with the generating activity and agent references", "Validity window or recomputation trigger", "Reference to the bound read the projection was computed from" ] }, { "id": "dep-qry-impact-scenario-q-external", "text": "Which external status assertions does the projection reference rather than restate?", "kind": "interoperability", "answer_data": [ "References to external advisory, exploitability or support-status assertions with their issuing authority", "Statement that referenced statuses are not re-derived or overridden locally", "Behaviour when a referenced status is absent, which is treated as no assertion rather than a negative status" ] } ], "data_elements": [ { "id": "dep-qry-scenario-hypothesis", "name": "Scenario hypothesis", "description": "The stated counterfactual the projection assumes, including the endpoints it applies to and the nature of the assumed change.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-001" ] }, { "id": "dep-qry-propagation-rule-ref", "name": "Propagation rule-set reference", "description": "Resolvable reference with version to the externally owned rule set that determined how impact propagates.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001", "SRC-034" ] }, { "id": "dep-qry-impact-qualifier", "name": "Impact qualifier", "description": "Per-endpoint qualification of the projected impact, keeping conditional and indeterminate outcomes distinct from asserted effect.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-012", "SRC-001" ] }, { "id": "dep-qry-result-validity-window", "name": "Derived-result validity window", "description": "Period after which the projection must be recomputed rather than reused, expressed as a duration or explicit expiry.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-133" ] } ], "artifacts": [ { "id": "dep-qry-impact-scenario-result", "name": "Scenario impact result", "description": "Immutable issue of one impact projection: hypothesis, rule-set reference and version, qualified impact set, referenced external statuses, bound read reference, completeness and truncation states inherited from that read, and the validity window.", "media_or_form": [ "structured impact set with per-endpoint qualifiers", "ranked or layered propagation projection", "narrative impact summary projection" ], "serial": true, "identity_strategy": "Mint a UUID or ULID bound to the hypothesis descriptor, rule-set version and the identifier of the bound read used as input; never reuse the input read's identifier and never encode a date.", "source_refs": [ "SRC-001", "SRC-012" ] } ], "inline_only_rationale": null }, { "id": "dep-qry-health-read", "name": "Referenced dependency-health indicator read", "description": "Contract for attaching health, maintenance or support-status indicators to endpoints and edges as typed references to an external assessor's published result, carrying assessor, method version, observation time, binding target and freshness state, with no local recomputation, thresholding or verdict.", "source_refs": [ "SRC-133", "SRC-001", "SRC-012" ], "questions": [ { "id": "dep-qry-health-read-q-assessor", "text": "Which assessor, method and method version produced each referenced indicator, and when was it observed?", "kind": "provenance", "answer_data": [ "Assessor identity and the published result reference", "Assessment method name and version", "Observation time of the indicator, separate from the time this read retrieved it" ] }, { "id": "dep-qry-health-read-q-binding", "text": "To which exact endpoint or edge version is each indicator bound, and does that binding still hold at the read's reference point?", "kind": "identity", "answer_data": [ "Binding target identifier at the granularity the assessor used (project, package, version, edge)", "Whether the bound target matches the endpoint returned by the read or an ancestor of it", "Binding mismatch flag when the indicator applies to a different version than the one in scope" ] }, { "id": "dep-qry-health-read-q-freshness", "text": "How stale may a referenced indicator be before the read must mark it expired instead of returning it silently?", "kind": "quality", "answer_data": [ "Freshness state (current, stale, expired, unavailable)", "Maximum age policy applied and its owner", "Behaviour when the assessor is unreachable at read time" ] }, { "id": "dep-qry-health-read-q-noverdict", "text": "What prevents this read from converting an indicator into a pass or fail verdict, a threshold breach or an alert?", "kind": "authority", "answer_data": [ "Statement that indicator interpretation and thresholds belong to the referenced monitoring or risk model", "Prohibition on storing a locally derived score alongside the reference", "Pointer to the owner accountable for any downstream verdict" ] } ], "data_elements": [ { "id": "dep-qry-health-indicator-ref", "name": "Health indicator reference", "description": "Typed reference to an externally published indicator result, carrying the assessor and the result identifier rather than the indicator's computed value semantics.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-133" ] }, { "id": "dep-qry-assessment-method-version", "name": "Assessment method version", "description": "Version of the external assessment method, without which two indicator values are not comparable.", "value_kind": "text", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-133", "SRC-001" ] }, { "id": "dep-qry-indicator-observed-at", "name": "Indicator observation time", "description": "Time the external assessor observed the indicator, recorded separately from the time this read retrieved it.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001", "SRC-131" ] }, { "id": "dep-qry-indicator-freshness-state", "name": "Indicator freshness state", "description": "Qualification of the referenced indicator at read time so that stale or unavailable signals are never presented as current.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-133", "SRC-012" ] } ], "artifacts": [], "inline_only_rationale": "Dependency-health indicators are results owned and published by external assessment services and, downstream, interpreted by the adopting Dimension's monitoring and risk models. This finding contributes only inline reference data carried inside result envelopes defined elsewhere in this pass: a typed pointer to the assessor's published result, the binding to a specific endpoint or edge version, the assessor's observation time and a freshness state. Issuing a separate health artifact here would copy an external record, create a second point of truth for its validity and version, and inevitably pull threshold, verdict and alerting semantics into a model whose boundary explicitly excludes them." } ] } ] }, { "id": "dep-qry-answer-integrity", "name": "Answer integrity and disclosure contract", "description": "The obligations every result of this model must satisfy so that an answer cannot be over-read: declared scope and completeness, disciplined negative results, deterministic ordering, snapshot-bound continuation, and explicit disclosure of truncation and of edges excluded by decisions made elsewhere.", "rationale": "The dominant failure mode of dependency and impact queries is silent under-reporting: an empty or partial result read as proof of independence. Monotonic, open-world entailment semantics forbid that inference; existing completeness vocabularies and paging specifications show that completeness, unknown counts and partial results are disclosed rather than assumed. This bundle turns those norms into a mandatory result-integrity contract.", "source_refs": [ "SRC-073", "SRC-130", "SRC-014", "SRC-132", "SRC-103" ], "layers": [ { "id": "dep-qry-scope-completeness", "name": "Scope declaration, completeness and negative results", "description": "How a result states what it examined, whether that scope was exhaustively searched, and under what conditions an empty result may be treated as a claim of independence.", "source_refs": [ "SRC-073", "SRC-014", "SRC-132", "SRC-012" ], "findings": [ { "id": "dep-qry-completeness", "name": "World-scope declaration, completeness code and negative-result semantics", "description": "Every result declares the scope examined and whether that scope was exhaustively searched. Open-world reads may report only that nothing was found within the stated scope; independence may be claimed only under an explicitly declared, evidenced and untruncated closed-world scope, declared by a named authority.", "source_refs": [ "SRC-073", "SRC-014", "SRC-132", "SRC-129", "SRC-012" ], "questions": [ { "id": "dep-qry-completeness-q-world", "text": "Was the read executed under an open-world scope or an explicitly declared closed-world scope, and who declared it?", "kind": "authority", "answer_data": [ "World-scope mode (open-world, declared-closed-world)", "Declaration reference, declaring role and validity period of a closed-world scope", "Conditions that invalidate the declaration, such as an unreachable in-scope partition" ] }, { "id": "dep-qry-completeness-q-code", "text": "Which completeness code applies to the returned edge set, and what evidence supports a claim of exhaustiveness?", "kind": "evidence", "answer_data": [ "Completeness code (complete, incomplete, no-assertion) with its code-system reference", "Partition qualification where completeness holds only for part of the population", "Evidence supporting a complete claim, such as an exhaustive source enumeration" ] }, { "id": "dep-qry-completeness-q-empty", "text": "What does an empty result mean under this declaration, and which phrasing may a consuming agent use?", "kind": "definition", "answer_data": [ "Permitted statement for open-world reads, limited to 'no dependencies found within the declared scope at the bound reference point'", "Permitted statement for a complete, untruncated closed-world read", "Explicitly forbidden statements, including any unqualified claim of independence" ] }, { "id": "dep-qry-completeness-q-partitions", "text": "Which underlying assertion sources or partitions were in scope, and which were unreachable or skipped at read time?", "kind": "quality", "answer_data": [ "Enumerated in-scope partitions or source systems", "Partitions unreachable, degraded or deliberately skipped, with reasons", "Effect of each unavailable partition on the completeness code" ] }, { "id": "dep-qry-completeness-q-negative", "text": "Under what conditions may a caller record a negative finding as a durable claim rather than a momentary observation?", "kind": "decision", "answer_data": [ "Required conjunction of declared closed-world scope, complete code and truncation state of none", "Reference point and validity horizon the negative claim is bound to", "Re-verification trigger after which the negative claim must not be reused" ] } ], "data_elements": [ { "id": "dep-qry-world-scope-mode", "name": "World-scope mode", "description": "Whether the result was produced under open-world assumptions or under an explicitly declared closed-world scope.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-073", "SRC-129" ] }, { "id": "dep-qry-completeness-code", "name": "Completeness code", "description": "Exhaustiveness of the returned edge set for the resolved scope, aligned to complete, incomplete and no-assertion semantics.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-014", "SRC-132" ] }, { "id": "dep-qry-scope-partition-ref", "name": "In-scope partition reference", "description": "Reference to a source system or partition that the resolved scope covers.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-129", "SRC-133" ] }, { "id": "dep-qry-unavailable-source-ref", "name": "Unavailable source reference", "description": "Reference to an in-scope partition that could not be read, with the reason, so its absence is visible rather than silent.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-133", "SRC-132" ] } ], "artifacts": [ { "id": "dep-qry-completeness-declaration", "name": "Result completeness declaration", "description": "The declaration attached to every issued result: world-scope mode, completeness code and its partition qualification, enumerated in-scope partitions, unavailable sources, and the permitted phrasing for an empty result.", "media_or_form": [ "structured envelope block attached to every result artifact", "standalone reusable closed-world scope declaration referenced by identifier" ], "serial": true, "identity_strategy": "For a per-result declaration, derive the identifier from the query-invocation identifier it qualifies. For a reusable closed-world scope declaration, use the adopting Dimension's governed scope identifier, or mint a UUID or ULID with the declaring authority recorded; identifiers never encode a date.", "source_refs": [ "SRC-014", "SRC-132", "SRC-073" ] } ], "inline_only_rationale": null } ] }, { "id": "dep-qry-result-delivery", "name": "Delivery, continuation and exclusion disclosure", "description": "How a result is delivered across pages without changing its meaning, and how truncation and authorization-driven exclusions are disclosed rather than hidden.", "source_refs": [ "SRC-130", "SRC-006", "SRC-103", "SRC-134" ], "findings": [ { "id": "dep-qry-delivery", "name": "Ordering, snapshot-bound continuation, truncation and exclusion disclosure", "description": "Contract for paged and bounded delivery: deterministic ordering that makes paging reproducible, an opaque continuation bound to one resolved scope and reference point, a truncation state that distinguishes 'more pages' from 'cut by a budget', disclosure of edges withheld by an authorization decision made elsewhere, and rules for absent or approximate match counts.", "source_refs": [ "SRC-130", "SRC-006", "SRC-134", "SRC-103", "SRC-129" ], "questions": [ { "id": "dep-qry-delivery-q-ordering", "text": "Which deterministic ordering makes paged results reproducible, and what happens when no ordering is requested?", "kind": "constraint", "answer_data": [ "Ordering keys applied, including the tie-breaker that guarantees total order", "Published default ordering used when none is requested", "Statement that page boundaries are undefined without a total order, and that unordered paging is refused rather than approximated" ] }, { "id": "dep-qry-delivery-q-snapshot", "text": "To which resolved scope and reference point is a continuation bound, and how does a caller learn that the underlying data moved during an in-progress traversal?", "kind": "temporal", "answer_data": [ "Reference point and resolved scope identifiers embedded in the continuation", "Rejection of a continuation presented with altered request arguments", "Continuation expiry behaviour and the explicit error returned when the bound reference point is no longer retrievable" ] }, { "id": "dep-qry-delivery-q-truncation", "text": "How does the response distinguish an unfinished page sequence from a result cut short by a budget or limit?", "kind": "quality", "answer_data": [ "Truncation state (none, page-boundary, budget-truncated, scope-truncated)", "The budget or limit that caused truncation and the value actually enforced", "Interaction rule stating that any truncation other than none forbids a complete completeness code" ] }, { "id": "dep-qry-delivery-q-withheld", "text": "How are edges withheld by an authorization decision disclosed without leaking their content?", "kind": "access", "answer_data": [ "Count of withheld edges and, where permitted, their withheld edge types", "Authorization decision reference issued by the external decision point", "Explicit statement that a withheld edge is neither absent nor asserted, and that this model neither renders nor re-evaluates the decision" ] }, { "id": "dep-qry-delivery-q-counts", "text": "When may a total match count be omitted or approximated, and how must a caller treat a missing count?", "kind": "measurement", "answer_data": [ "Returned-count for the page and matched-count for the scope where computable", "Permission to omit the matched count when it is unknown or costly, with an explicit unknown marker", "Rule that a missing or approximate count may never be interpreted as zero or as completeness" ] } ], "data_elements": [ { "id": "dep-qry-continuation-token", "name": "Continuation token", "description": "Opaque, non-parseable continuation value bound to one resolved scope and reference point; it conveys position only and grants no authorization.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-134", "SRC-130" ] }, { "id": "dep-qry-result-ordering-key", "name": "Result ordering key", "description": "Ordered list of keys, ending in a unique tie-breaker, that fixes a total order over the result sequence.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-129", "SRC-130" ] }, { "id": "dep-qry-truncation-state", "name": "Truncation state", "description": "Whether the result is complete for its page sequence, continues on a further page, or was cut by a budget or scope boundary.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-130", "SRC-133" ] }, { "id": "dep-qry-withheld-edge-count", "name": "Withheld edge count", "description": "Number of edges excluded from the result by an authorization decision, disclosed so exclusion is never silent.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-103" ] }, { "id": "dep-qry-authorization-decision-ref", "name": "Authorization decision reference", "description": "Reference to the decision rendered by the external decision point that caused edges to be withheld; carried, never computed here.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-103", "SRC-034" ] }, { "id": "dep-qry-match-count", "name": "Matched-count", "description": "Number of items matching the resolved scope where computable; explicitly marked unknown when the count is unavailable or costly.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-130" ] } ], "artifacts": [ { "id": "dep-qry-page-continuation", "name": "Page continuation envelope", "description": "The delivery block accompanying each page: ordering keys applied, returned-count and matched-count or its unknown marker, truncation state, opaque continuation value with its bound scope and reference point, and typed links to the next and superseding pages.", "media_or_form": [ "structured envelope block attached to a paged result", "typed link set using registered relation types" ], "serial": true, "identity_strategy": "Identify each page by the query-invocation identifier plus a monotonic page sequence number; the continuation value itself is opaque, is not an identifier of record, and never encodes a date.", "source_refs": [ "SRC-130", "SRC-006", "SRC-134" ] }, { "id": "dep-qry-exclusion-notice", "name": "Exclusion notice", "description": "Disclosure block listing why content is missing from a result: withheld-edge counts with their authorization decision reference, budget or scope truncation, unavailable sources, and edge types excluded because they are not invertible for the requested direction.", "media_or_form": [ "structured envelope block attached to a result artifact", "standalone notice referenced by result identifier" ], "serial": true, "identity_strategy": "Derive the identifier from the query-invocation identifier it qualifies; where a notice is issued separately, mint a UUID or ULID bound to that invocation. Identifiers contain no date component.", "source_refs": [ "SRC-103", "SRC-132", "SRC-130" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "dep-rpt-construction", "name": "Impact and Readiness Report Construction", "description": "How an impact or readiness report is framed, computed and disclosed: what kind of report it is, what analysis frame it declares, and what evidence and disclosure obligations it must satisfy before it may be cited.", "rationale": "Published dependency and advisory standards treat an assessment as a revisioned, attributable document whose conclusions are meaningless without a declared scope, a declared completeness and a declared basis. CSAF fixes tracking, status and revision history; SPDX fixes per-relationship completeness; SARIF fixes replayable graph traversal; PROV-O fixes attribution and derivation. Grouping these into one construction bundle keeps the report's frame inseparable from its conclusions.", "source_refs": [ "SRC-013", "SRC-014", "SRC-012", "SRC-137", "SRC-001", "SRC-140" ], "layers": [ { "id": "dep-rpt-report-frame", "name": "Report Instance Frame", "description": "The citable identity of a report instance, its kind, revision and release status, and the mandatory content core each of the five report kinds must carry.", "source_refs": [ "SRC-012", "SRC-058", "SRC-023", "SRC-139", "SRC-140" ], "findings": [ { "id": "dep-rpt-report-instance", "name": "Report Instance Identity, Kind and Release Status", "description": "Establishes a report as a citable record independent of its storage or serialization: which identifier resolves it, which of the five kinds it declares, which revision and release status it carries, which agent issued it under whose delegated authority, and how it is superseded or revoked. The status of the report is deliberately distinct from the status of the change it describes.", "source_refs": [ "SRC-012", "SRC-138", "SRC-140" ], "questions": [ { "id": "dep-rpt-q-instance-identifier", "text": "Which identifier makes this report instance citable and re-resolvable independently of its file name, storage collection or serialization format?", "kind": "identity", "answer_data": [ "authoritative master-system report identifier issued by the Dimension's report system of record", "governed IRI where a registry already governs the report", "fallback UUID or ULID minted by the adopting Dimension", "explicit statement that snapshot digest, title and issue date are not identifiers" ] }, { "id": "dep-rpt-q-instance-kind", "text": "Which of the five report kinds does this instance declare, and may a single instance declare more than one kind?", "kind": "classification", "answer_data": [ "kind code from the closed set analyze-impact, dependency-conflict, change-readiness, mitigation-reference, notification-content", "single-kind constraint or an explicit composite declaration rule", "kind-specific mandatory content core reference" ] }, { "id": "dep-rpt-q-instance-status", "text": "What release status does the instance carry, and which status values permit downstream citation?", "kind": "state", "answer_data": [ "release status value from draft, interim, final", "citable-from-status rule", "superseded and withdrawn markers held separately from release status" ] }, { "id": "dep-rpt-q-instance-authority", "text": "Which agent issued this report, and under whose delegated authority was the issuance made?", "kind": "authority", "answer_data": [ "issuing agent reference", "delegating role or organisational unit reference", "explicit statement that issuing authority conveys no approval authority" ] }, { "id": "dep-rpt-q-instance-supersession", "text": "How is a report instance superseded or withdrawn, and what happens to existing citations of the superseded revision?", "kind": "lifecycle", "answer_data": [ "monotonic revision number", "supersedes and superseded-by pointers", "withdrawal flag with reason code", "rule that superseded content is retained and never rewritten" ] } ], "data_elements": [ { "id": "dep-rpt-de-report-identifier", "name": "Report identifier", "description": "Identifier of the report record under the model's identity priority; stable across storage migration and never reused.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-012" ] }, { "id": "dep-rpt-de-report-kind", "name": "Report kind code", "description": "Closed-vocabulary code naming which of the five report kinds this instance is.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-012" ] }, { "id": "dep-rpt-de-report-revision", "name": "Report revision", "description": "Monotonically increasing integer revision of the report identifier; never renumbered.", "value_kind": "number", "cardinality": "1", "required": true, "source_refs": [ "SRC-012" ] }, { "id": "dep-rpt-de-release-status", "name": "Release status", "description": "Draft, interim or final; controls whether the revision may be cited outside the authoring role.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-012" ] }, { "id": "dep-rpt-de-issuing-agent-ref", "name": "Issuing agent reference", "description": "Reference to the agent that issued the revision, resolved in the Dimension's identity model.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-001" ] }, { "id": "dep-rpt-de-report-issued-at", "name": "Report issue time", "description": "RFC 3339 timestamp with seconds and explicit offset recording when the revision was issued, distinct from any graph or observation time.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-012", "SRC-138" ] }, { "id": "dep-rpt-de-supersedes-ref", "name": "Supersedes reference", "description": "Pointer from a revision to the revision it replaces.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-012" ] }, { "id": "dep-rpt-de-withdrawn-flag", "name": "Withdrawal marker", "description": "Marker that the issuer has withdrawn the revision's conclusions, with a reason code; content is retained.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-138" ] } ], "artifacts": [], "inline_only_rationale": "Identity, kind, revision, status and issuing-agent values are header fields carried inside the report artifacts declared in dep-rpt-report-kind-contract. Minting a separate identity artifact would create two competing carriers of record for the same report and allow the header to drift from the conclusions it labels, so this finding contributes inline reference data only." }, { "id": "dep-rpt-report-kind-contract", "name": "Report Kinds and Their Mandatory Content Cores", "description": "Defines the five report kinds and the minimum content each must carry to be citable: what an analyze-impact report enumerates, how a dependency-conflict report expresses incompatibility and alternatives without asserting a resolution, which readiness criteria a change-readiness report must evaluate or explicitly mark unevaluated, what a mitigation-reference report may state about a candidate mitigation, and what content and handling marking a notification-content draft carries given that this model never transmits it.", "source_refs": [ "SRC-012", "SRC-058", "SRC-023", "SRC-139", "SRC-136" ], "questions": [ { "id": "dep-rpt-q-kind-impact-core", "text": "What must an analyze-impact report contain before it may be cited as a basis for a change decision?", "kind": "requirement", "answer_data": [ "reached-element set with per-element impact class", "impact path set reference", "excluded-edge register reference", "confidence and completeness disclosure block", "bound snapshot and propagation rule version" ] }, { "id": "dep-rpt-q-kind-conflict-expression", "text": "How does a dependency-conflict report express incompatibility, alternative satisfiers and provided or virtual capabilities without asserting a resolution?", "kind": "composition", "answer_data": [ "conflict assertion with the two or more constraints in tension", "version relation operators and ranges", "alternative satisfier set with no selection", "provided or virtual capability references", "explicit no-resolution statement" ] }, { "id": "dep-rpt-q-kind-readiness-criteria", "text": "Which readiness criteria must a change-readiness report evaluate, and which may it only record as unevaluated?", "kind": "decision", "answer_data": [ "criterion identifier and its declared source", "per-criterion verdict from met, unmet, unevaluated", "reason for any unevaluated criterion", "statement that the aggregate verdict is advisory input to an external decision" ] }, { "id": "dep-rpt-q-kind-mitigation-limits", "text": "What may a mitigation-reference report state about a candidate mitigation, and what must it leave to the remediation model?", "kind": "ownership", "answer_data": [ "citation of the mitigation as published by its owning source", "applicability conditions and affected element bindings", "restart or precondition notes carried verbatim by reference", "explicit exclusion of selection, application and effectiveness verification" ] }, { "id": "dep-rpt-q-kind-notification-content", "text": "What content and handling marking must a notification-content draft carry, given that this model performs no transmission?", "kind": "access", "answer_data": [ "recipient class rather than individual addressees", "handling marking such as a TLP label", "conclusions cleared for that audience with their anchors", "statement naming the delivery model that owns transmission" ] } ], "data_elements": [ { "id": "dep-rpt-de-content-core-ref", "name": "Content core reference", "description": "Reference to the mandatory content checklist for the declared report kind.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-012" ] }, { "id": "dep-rpt-de-conflict-assertion", "name": "Conflict assertion", "description": "Statement that two or more dependency constraints cannot be satisfied together, naming each constraint and its version relation.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-023" ] }, { "id": "dep-rpt-de-alternative-satisfier-set", "name": "Alternative satisfier set", "description": "Set of elements any one of which satisfies a requirement, including virtual or provided capabilities; reported without selection.", "value_kind": "collection", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-023", "SRC-136" ] }, { "id": "dep-rpt-de-readiness-criterion", "name": "Readiness criterion verdict", "description": "One criterion with its verdict of met, unmet or unevaluated, its evidence citation and its confidence.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-140" ] }, { "id": "dep-rpt-de-mitigation-reference", "name": "Mitigation reference", "description": "Citation of an externally owned candidate mitigation with its applicability conditions and affected element bindings.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-012", "SRC-058" ] }, { "id": "dep-rpt-de-recipient-class", "name": "Recipient class", "description": "Named audience class for a notification-content draft; never an individual address or transport endpoint.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-139" ] }, { "id": "dep-rpt-de-handling-marking", "name": "Handling marking", "description": "Sharing-restriction label applied to a report or draft, such as a TLP 2.0 label, inherited from the most restrictive incorporated evidence item.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-139", "SRC-012" ] } ], "artifacts": [ { "id": "dep-rpt-art-analyze-impact-report", "name": "Analyze-Impact Report", "description": "Issued report enumerating the elements reached downstream of a declared scenario over a bound snapshot, with per-element impact class, path citations and a disclosure block. It states impact, never permission to proceed.", "media_or_form": [ "structured conclusion record", "narrative impact assessment", "tabular reached-element listing" ], "serial": true, "identity_strategy": "Master-system report identifier plus integer revision; the bound snapshot digest, scenario identifier and issue date are attributes, never identifiers.", "source_refs": [ "SRC-013", "SRC-137", "SRC-140" ] }, { "id": "dep-rpt-art-dependency-conflict-report", "name": "Dependency-Conflict Report", "description": "Report of constraint incompatibilities discovered over the bound snapshot: version-range violations, mutually exclusive requirements, breakage relations and the alternative or virtual satisfiers available. It reports the conflict set and does not assert a resolution.", "media_or_form": [ "structured conflict record", "narrative conflict summary" ], "serial": true, "identity_strategy": "Master-system report identifier plus integer revision; each conflict carries its own stable conflict identifier within the revision.", "source_refs": [ "SRC-023", "SRC-015", "SRC-136" ] }, { "id": "dep-rpt-art-change-readiness-report", "name": "Change-Readiness Report", "description": "Per-criterion statement of whether the technical prerequisites for a declared scenario are met, unmet or unevaluated, each with evidence citation and confidence. It is an input to a decision owned by the change approval model.", "media_or_form": [ "structured criterion verdict record", "narrative readiness statement" ], "serial": true, "identity_strategy": "Master-system report identifier plus integer revision; criterion verdicts are addressed by criterion identifier within the revision.", "source_refs": [ "SRC-140", "SRC-012" ] }, { "id": "dep-rpt-art-mitigation-reference-report", "name": "Mitigation-Reference Report", "description": "Reference list of candidate mitigations or workarounds already published by their owning sources, bound to impacted elements with applicability conditions. It carries citations, never an instruction to apply.", "media_or_form": [ "structured reference list", "narrative mitigation options summary" ], "serial": true, "identity_strategy": "Master-system report identifier plus integer revision; each entry retains the external identifier issued by the mitigation's owning source.", "source_refs": [ "SRC-012", "SRC-058" ] }, { "id": "dep-rpt-art-notification-content-draft", "name": "Notification-Content Draft", "description": "Drafted notification body addressed to a named recipient class, carrying a handling marking and only those conclusions cleared for that audience, each anchored to the machine-readable rendition. Drafting only; no transmission occurs in this model.", "media_or_form": [ "drafted message body", "structured audience and marking record" ], "serial": true, "identity_strategy": "Master-system report identifier plus integer revision plus recipient-class discriminator; no transport message identifier is minted here.", "source_refs": [ "SRC-139", "SRC-012" ] } ], "inline_only_rationale": null } ] }, { "id": "dep-rpt-analysis-frame", "name": "Analysis Frame", "description": "The declared, frozen inputs that make a reported conclusion reproducible: the change scenario, the bound graph snapshot with its temporal semantics, and the traversal and propagation parameters together with the excluded-edge register.", "source_refs": [ "SRC-013", "SRC-015", "SRC-136", "SRC-137", "SRC-023" ], "findings": [ { "id": "dep-rpt-scenario-declaration", "name": "Change Scenario and Subject Declaration", "description": "Declares the perturbation being analysed: the subject elements, the proposed action, the variants that must be reported alongside the primary scenario, the assumptions treated as preconditions rather than findings, and how a scenario is re-identified when the same change is re-analysed against a later snapshot.", "source_refs": [ "SRC-140", "SRC-012", "SRC-023" ], "questions": [ { "id": "dep-rpt-q-scenario-definition", "text": "What subject elements and proposed action define this scenario, and how is a multi-part scenario bounded?", "kind": "definition", "answer_data": [ "subject element references resolved in the host model", "proposed action code such as add, upgrade, downgrade, remove, replace, deprecate or unavailability", "bounding rule for grouping several actions into one scenario" ] }, { "id": "dep-rpt-q-scenario-variants", "text": "Which scenario variants must be reported alongside the primary scenario, and how are they distinguished from it?", "kind": "decision", "answer_data": [ "variant identifier and label such as do-nothing, rollback or alternative substitution", "primary-variant marker", "per-variant conclusion set kept separately addressable" ] }, { "id": "dep-rpt-q-scenario-assumptions", "text": "Which assumptions are declared as scenario preconditions rather than reported as findings?", "kind": "constraint", "answer_data": [ "declared assumption statement", "assumption source and whether it was verified or asserted", "effect on conclusions if the assumption fails" ] }, { "id": "dep-rpt-q-scenario-reidentification", "text": "How is a scenario re-identified when the same proposed change is re-analysed against a later snapshot?", "kind": "identity", "answer_data": [ "stable scenario identifier independent of snapshot", "rule that a new snapshot produces a new report revision, not a new scenario", "comparison pointer to the prior report revision" ] } ], "data_elements": [ { "id": "dep-rpt-de-scenario-identifier", "name": "Scenario identifier", "description": "Stable identifier of the declared change scenario, independent of any snapshot or report revision.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-140" ] }, { "id": "dep-rpt-de-subject-element-ref", "name": "Subject element reference", "description": "Reference to an element in the host subject model that the scenario acts upon.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-013" ] }, { "id": "dep-rpt-de-proposed-action-code", "name": "Proposed action code", "description": "Closed-vocabulary code describing the perturbation applied to the subject elements.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-023" ] }, { "id": "dep-rpt-de-scenario-variant", "name": "Scenario variant", "description": "A named alternative framing of the same change whose conclusions are reported separately from the primary variant.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-012" ] }, { "id": "dep-rpt-de-declared-assumption", "name": "Declared assumption", "description": "A precondition taken as given for the analysis, with its source and the stated consequence of its failure.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-058" ] } ], "artifacts": [], "inline_only_rationale": "A scenario is the report's declared input frame rather than a separately issued deliverable. It is carried as reference data inside every report artifact that depends on it so that a report and the scenario it analysed cannot be separated, re-dated or re-bound independently; issuing it as its own artifact would permit exactly that drift." }, { "id": "dep-rpt-snapshot-binding", "name": "Graph Snapshot Binding and Temporal Validity", "description": "Every report binds to one immutable, digest-corroborated snapshot of the dependency graph owned by an external source of record, and records graph event time, observation or ingestion time and report issue time as separate values. Also fixes the report's validity horizon, what invalidates it earlier, and how the snapshot's own declared coverage limits are restated.", "source_refs": [ "SRC-013", "SRC-015", "SRC-136", "SRC-138", "SRC-014" ], "questions": [ { "id": "dep-rpt-q-snapshot-binding", "text": "To which snapshot of the dependency graph is this report bound, and how is that binding kept verifiable after the graph has moved on?", "kind": "provenance", "answer_data": [ "resolvable snapshot reference in the owning source of record", "content digest of the snapshot", "identifier of the snapshot-producing activity and agent" ] }, { "id": "dep-rpt-q-snapshot-times", "text": "How are graph event time, observation or ingestion time and report issue time recorded when they differ?", "kind": "temporal", "answer_data": [ "graph event time when the dependency fact became true", "observation or ingestion time when the snapshot captured it", "report issue time", "rule forbidding overwriting an observation time with a later ingestion time" ] }, { "id": "dep-rpt-q-snapshot-validity", "text": "For how long does this report assert validity, and what invalidates it before that horizon?", "kind": "state", "answer_data": [ "validity-until value", "invalidating events such as snapshot supersession, propagation rule version change or withdrawal of a cited evidence item", "resulting status transition of the report" ] }, { "id": "dep-rpt-q-snapshot-ownership", "text": "Which model owns the snapshot itself, and what may this report legitimately record about it?", "kind": "ownership", "answer_data": [ "owning source-of-record model reference", "permitted local fields limited to reference, digest, times and restated completeness", "explicit prohibition on authoring or correcting inventory content here" ] }, { "id": "dep-rpt-q-snapshot-coverage", "text": "How does the report restate the snapshot's own declared coverage so that a reader does not mistake snapshot gaps for analysis gaps?", "kind": "quality", "answer_data": [ "snapshot-level completeness aggregate carried verbatim", "attribution of each gap to snapshot origin or to traversal", "statement that a no-assertion snapshot caps the report's own completeness claim" ] } ], "data_elements": [ { "id": "dep-rpt-de-snapshot-ref", "name": "Snapshot reference", "description": "Resolvable reference to the graph snapshot in its owning source of record.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-015" ] }, { "id": "dep-rpt-de-snapshot-digest", "name": "Snapshot digest", "description": "Content digest corroborating that the snapshot read is the snapshot cited; never used as an identifier.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-015" ] }, { "id": "dep-rpt-de-graph-event-time", "name": "Graph event time", "description": "RFC 3339 timestamp with seconds and offset for when the underlying dependency fact became true, where known.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-013" ] }, { "id": "dep-rpt-de-snapshot-observed-at", "name": "Snapshot observation time", "description": "RFC 3339 timestamp with seconds and offset for when the snapshot captured or ingested the graph state.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-137", "SRC-138" ] }, { "id": "dep-rpt-de-validity-until", "name": "Validity horizon", "description": "Time after which the report's conclusions are not asserted to hold without re-analysis.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-138" ] }, { "id": "dep-rpt-de-snapshot-completeness", "name": "Restated snapshot completeness", "description": "The snapshot's own completeness aggregate, carried verbatim so that snapshot gaps are attributable to the snapshot.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-136", "SRC-014" ] } ], "artifacts": [], "inline_only_rationale": "The snapshot is authored and owned by an external inventory or graph source of record. Materialising a snapshot artifact here would duplicate that model's deliverable and invite divergence between two copies of the same state, so this finding carries only a resolvable reference, a corroborating digest, the separated time values and the restated coverage claim." }, { "id": "dep-rpt-path-propagation-exclusion", "name": "Impact Paths, Propagation Rules and Excluded Edges", "description": "How downstream impact is actually derived and made replayable: traversal direction, edge-type filters and depth or fan-out bounds; the versioned propagation rules mapping each traversed edge type to an impact class; the representation of an individual path as ordered edge steps; the register of edges not traversed with typed exclusion reasons; and how dependency strength distinctions affect propagation.", "source_refs": [ "SRC-137", "SRC-013", "SRC-023", "SRC-136", "SRC-015" ], "questions": [ { "id": "dep-rpt-q-path-traversal-params", "text": "Which traversal direction, edge-type filters and depth or fan-out bounds produced the reported impact set?", "kind": "process", "answer_data": [ "direction of traversal relative to the subject", "included edge-type filter list", "maximum depth and fan-out bounds and whether either was reached" ] }, { "id": "dep-rpt-q-path-propagation-rule", "text": "Which propagation rule mapped each traversed edge type to an impact class, and where is that rule set versioned?", "kind": "relationship", "answer_data": [ "propagation rule set reference and version", "per-edge-type mapping to impact class", "register location where rule versions are published" ] }, { "id": "dep-rpt-q-path-exclusions", "text": "Which edges were excluded from traversal, and was each exclusion a policy choice, a traversal bound or a data gap?", "kind": "exception", "answer_data": [ "excluded edge reference", "exclusion reason code distinguishing policy, bound and gap", "stated effect of the exclusion on the affected conclusions" ] }, { "id": "dep-rpt-q-path-replay", "text": "How is an individual impact path represented so that a reader can replay it edge by edge?", "kind": "evidence", "answer_data": [ "ordered edge steps with source and target node identifiers", "edge type and applied propagation rule at each step", "step message explaining the transition", "path identifier stable within the revision" ] }, { "id": "dep-rpt-q-path-strength", "text": "How are absolute, recommended and optional dependency strengths reflected in propagation weight and in the reported impact class?", "kind": "classification", "answer_data": [ "dependency strength code consumed from the graph surface", "weighting or downgrade rule per strength", "rule for optional edges that are traversed but reported at reduced impact" ] } ], "data_elements": [ { "id": "dep-rpt-de-traversal-direction", "name": "Traversal direction", "description": "Whether the traversal followed dependents, dependencies or both from the subject elements.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-137" ] }, { "id": "dep-rpt-de-edge-type-filter", "name": "Edge-type filter", "description": "The set of edge types admitted into the traversal, consumed by reference from the graph surface.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-013" ] }, { "id": "dep-rpt-de-depth-bound", "name": "Depth or fan-out bound", "description": "Configured traversal limit and a marker recording whether the limit was actually reached.", "value_kind": "number", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-137" ] }, { "id": "dep-rpt-de-propagation-rule-ref", "name": "Propagation rule set version", "description": "Versioned reference to the rule set mapping edge types and strengths to impact classes.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-137" ] }, { "id": "dep-rpt-de-impact-path", "name": "Impact path", "description": "An ordered sequence of edge steps from a subject element to a reached element.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-137" ] }, { "id": "dep-rpt-de-path-edge-step", "name": "Path edge step", "description": "One traversal step recording edge identifier, source and target node, edge type, applied rule and an explanatory message.", "value_kind": "object", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-137" ] }, { "id": "dep-rpt-de-excluded-edge-entry", "name": "Excluded edge entry", "description": "An edge that was not traversed, with its reason code and stated effect on conclusions.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-014", "SRC-136" ] }, { "id": "dep-rpt-de-dependency-strength", "name": "Dependency strength", "description": "Strength class of a traversed edge, such as absolute, recommended, suggested or enhancing, consumed from the graph surface.", "value_kind": "code", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-023" ] }, { "id": "dep-rpt-de-impact-class", "name": "Impact class", "description": "The class of impact asserted for a reached element under the applied propagation rule.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-137" ] } ], "artifacts": [ { "id": "dep-rpt-art-impact-path-set", "name": "Impact Path Set", "description": "Replayable traversal record for one report revision: every reported path as ordered edge steps with source and target node identifiers, edge type and the propagation rule applied at each step.", "media_or_form": [ "directed graph traversal record", "ordered edge-step listing" ], "serial": false, "identity_strategy": "Addressed by owning report identifier and revision plus a path identifier unique within that revision; a content digest corroborates integrity only.", "source_refs": [ "SRC-137", "SRC-013", "SRC-015" ] }, { "id": "dep-rpt-art-excluded-edge-register", "name": "Excluded-Edge Register", "description": "Register of edges deliberately or unavoidably left untraversed, each with a reason code distinguishing policy exclusion, traversal bound and data gap, plus the effect of the exclusion on the conclusions it touches.", "media_or_form": [ "structured exclusion register", "tabular exclusion listing" ], "serial": false, "identity_strategy": "Addressed by owning report identifier and revision plus the excluded edge's identifier from the graph surface.", "source_refs": [ "SRC-014", "SRC-136" ] } ], "inline_only_rationale": null } ] }, { "id": "dep-rpt-disclosure", "name": "Evidence and Disclosure", "description": "What a conclusion must cite and what it must admit: the evidence register with provenance and attribution, and the mandatory confidence, completeness and coverage disclosures that qualify every conclusion.", "source_refs": [ "SRC-001", "SRC-055", "SRC-014", "SRC-138", "SRC-058" ], "findings": [ { "id": "dep-rpt-evidence-provenance", "name": "Evidence Items, Attribution and Derivation", "description": "Each conclusion cites evidence items; each evidence item records the activity that generated it, the prior entity it was derived from, the agent responsible for it and when it was observed, so a conclusion can be re-derived or falsified. Distinguishes observed from asserted evidence, handles issuer withdrawal, and keeps the register distinct from the Dimension's audit trail.", "source_refs": [ "SRC-001", "SRC-137", "SRC-138", "SRC-058" ], "questions": [ { "id": "dep-rpt-q-evidence-citation", "text": "Which evidence items support each reported conclusion, and how is that citation expressed as a resolvable link rather than restated prose?", "kind": "evidence", "answer_data": [ "conclusion anchor identifier", "evidence item identifiers linked to that anchor", "resolvable pointer to the evidence in its owning source", "prohibition on citation by array index or line number" ] }, { "id": "dep-rpt-q-evidence-derivation", "text": "Which activity generated each evidence item, from which prior entity was it derived, and to which agent is it attributed?", "kind": "provenance", "answer_data": [ "generating activity identifier with start and end times", "derived-from entity reference", "responsible agent reference", "alignment terms from a provenance vocabulary" ] }, { "id": "dep-rpt-q-evidence-observed-vs-asserted", "text": "How is evidence observed by the report generator distinguished from evidence asserted by a third party?", "kind": "classification", "answer_data": [ "evidence kind code separating observation, assertion and inference", "asserting party reference for third-party assertions", "rule that an inference must cite the observations it rests on" ] }, { "id": "dep-rpt-q-evidence-withdrawal", "text": "What must be recorded when a cited evidence item is later withdrawn or revoked by its issuer?", "kind": "lifecycle", "answer_data": [ "evidence withdrawal marker with time and issuer", "affected conclusion anchors", "required downgrade of dependent confidence and completeness disclosures", "report status transition triggered by the downgrade" ] }, { "id": "dep-rpt-q-evidence-vs-audit", "text": "How is the report's evidence register kept distinct from the adopting Dimension's audit trail?", "kind": "ownership", "answer_data": [ "scope statement limiting the register to one report revision", "reference to the audit model that owns event records", "list of record content this model must emit to that audit model", "explicit disclaimer of audit storage, retention and evaluation" ] } ], "data_elements": [ { "id": "dep-rpt-de-evidence-item-id", "name": "Evidence item identifier", "description": "Identifier of a cited evidence item within the report revision, resolvable to its owning source.", "value_kind": "identifier", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001" ] }, { "id": "dep-rpt-de-evidence-kind", "name": "Evidence kind", "description": "Whether the item is a direct observation, a third-party assertion or an inference drawn from other items.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-138", "SRC-058" ] }, { "id": "dep-rpt-de-generating-activity", "name": "Generating activity", "description": "The activity that produced the evidence item, with its start and end times.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "dep-rpt-de-derived-from-ref", "name": "Derived-from reference", "description": "Prior entity from which the evidence item was derived.", "value_kind": "reference", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "dep-rpt-de-attributed-to-agent", "name": "Responsible agent", "description": "Agent to which the evidence item is attributed.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "dep-rpt-de-evidence-observed-at", "name": "Evidence observation time", "description": "RFC 3339 timestamp with seconds and offset for when the evidence was observed, held separately from when it was asserted.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-137", "SRC-138" ] }, { "id": "dep-rpt-de-evidence-withdrawn-flag", "name": "Evidence withdrawal marker", "description": "Marker that the evidence item's issuer has revoked it, with time and issuer reference.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-138" ] }, { "id": "dep-rpt-de-conclusion-anchor", "name": "Conclusion anchor", "description": "Stable identifier of a single reported conclusion, used by both renditions and by every evidence citation.", "value_kind": "identifier", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-137" ] } ], "artifacts": [ { "id": "dep-rpt-art-evidence-register", "name": "Report Evidence Register", "description": "Citation register for one report revision listing each evidence item with its generating activity, derivation source, responsible agent and observation time, and the conclusion anchors it supports. It is a citation list scoped to the report, not the Dimension's audit trail.", "media_or_form": [ "structured citation register", "tabular evidence listing" ], "serial": false, "identity_strategy": "Addressed by owning report identifier and revision; each entry retains the identifier issued by the evidence item's owning source.", "source_refs": [ "SRC-001", "SRC-137" ] } ], "inline_only_rationale": null }, { "id": "dep-rpt-confidence-completeness", "name": "Confidence, Completeness and Coverage Disclosure", "description": "The mandatory disclosures attached to each conclusion and to the report as a whole: a confidence value expressed on a named scale, a completeness assertion for each traversed relationship set drawn from complete, incomplete or explicit no-assertion, the fraction of the in-scope graph actually reached with a characterisation of what was not, and the method by which each was derived. Fixes the minimum disclosure set that gates release from draft.", "source_refs": [ "SRC-014", "SRC-136", "SRC-138", "SRC-055", "SRC-058" ], "questions": [ { "id": "dep-rpt-q-disclosure-confidence", "text": "What confidence value is attached to each conclusion, and on which explicitly named scale is that value expressed?", "kind": "measurement", "answer_data": [ "confidence value", "reference to the declared scale definition and its range", "derivation method for the value", "prohibition on transferring a numeric value between scales without restating the scale" ] }, { "id": "dep-rpt-q-disclosure-completeness", "text": "Is each reported relationship set asserted as complete, as incomplete, or as an explicit no-assertion?", "kind": "quality", "answer_data": [ "completeness value per relationship set", "scope to which the value applies", "basis for the assertion", "rule that absence of a value is not a completeness claim" ] }, { "id": "dep-rpt-q-disclosure-minimum-set", "text": "Which minimum disclosure set must be present before a report may leave draft status?", "kind": "requirement", "answer_data": [ "snapshot binding and digest", "propagation rule set version", "excluded-edge register", "confidence value with named scale", "completeness assertion", "coverage statement", "degradation register reference" ] }, { "id": "dep-rpt-q-disclosure-consistency", "text": "How is a confidence value checked for consistency with the completeness and evidence it claims to summarise?", "kind": "validation", "answer_data": [ "consistency rule capping confidence when completeness is incomplete or no-assertion", "rule capping confidence when a cited evidence item is withdrawn or stale", "verdict record from the disclosure-contract check" ] }, { "id": "dep-rpt-q-disclosure-survival", "text": "Which disclosures must survive summarisation into a shortened or executive rendition?", "kind": "constraint", "answer_data": [ "non-droppable disclosure list", "rule that a dropped disclosure invalidates rendition equivalence", "required pointer from a summary back to the full disclosure block" ] } ], "data_elements": [ { "id": "dep-rpt-de-confidence-value", "name": "Confidence value", "description": "Confidence attached to a conclusion or to the report as a whole.", "value_kind": "quantity", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-138" ] }, { "id": "dep-rpt-de-confidence-scale-ref", "name": "Confidence scale reference", "description": "Reference to the named scale definition, without which a confidence value is not interoperable.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-138", "SRC-055" ] }, { "id": "dep-rpt-de-completeness-assertion", "name": "Completeness assertion", "description": "Assertion of complete, incomplete or no-assertion for a named relationship set or scope.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-014", "SRC-136" ] }, { "id": "dep-rpt-de-coverage-fraction", "name": "Coverage measurement", "description": "Measured proportion of the in-scope graph actually traversed, with the metric definition it was measured against.", "value_kind": "quantity", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-055" ] }, { "id": "dep-rpt-de-unreached-region-note", "name": "Unreached region characterisation", "description": "Description of the territory not traversed and why, so that unreached is not read as unaffected.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-014", "SRC-058" ] }, { "id": "dep-rpt-de-disclosure-method-ref", "name": "Disclosure method reference", "description": "Versioned reference to the method used to derive confidence, completeness and coverage values.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-055" ] }, { "id": "dep-rpt-de-minimum-disclosure-set", "name": "Minimum disclosure set reference", "description": "Reference to the Dimension-published list of disclosures that must be present before release from draft.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-014", "SRC-136" ] } ], "artifacts": [], "inline_only_rationale": "Disclosures are qualifiers that must travel attached to the specific conclusion or scope they qualify. Separating them into a standalone artifact would allow a conclusion to be quoted without its confidence, completeness and coverage caveats, which is the precise failure mode this finding exists to prevent, so they are declared as inline fields on the report artifacts and their conclusion anchors." } ] } ] }, { "id": "dep-rpt-integrity", "name": "Report Integrity, Degradation and Handoff", "description": "How a report stays honest when the graph or its evidence is not clean, and how its conclusions are presented and handed on without acquiring authority the model does not have.", "rationale": "Real dependency graphs contain contradictions, expired assertions, unresolvable endpoints, cycles and choice points, and are almost never fully known. Every consulted standard provides an explicit construct for admitting this - SPDX no-assertion, CycloneDX unknown aggregates, CSAF and OpenVEX under-investigation, STIX revocation and validity windows, Debian cycle-cutting guidance. This bundle turns those constructs into obligations, and pairs them with the equally load-bearing rule that a report is an analytical instrument distinct from configuration change control.", "source_refs": [ "SRC-014", "SRC-136", "SRC-012", "SRC-137", "SRC-138", "SRC-058", "SRC-023", "SRC-139", "SRC-140" ], "layers": [ { "id": "dep-rpt-degraded-graph", "name": "Degraded Graph and Contested Evidence", "description": "Required behaviour when the graph or its evidence is contradictory, stale, unresolvable, cyclic, ambiguous or only partly known.", "source_refs": [ "SRC-014", "SRC-138", "SRC-058", "SRC-023", "SRC-136" ], "findings": [ { "id": "dep-rpt-degraded-conditions", "name": "Degraded Graph Conditions and Contested Evidence", "description": "How contradictory assertions, stale assertions, unresolvable endpoints, cycles, alternative satisfiers and partial coverage are detected, recorded and disclosed. The governing rule is that degradation is reported rather than silently resolved: both sides of a contradiction are retained, a cut cycle is disclosed with its cut point, an unknown endpoint is marked rather than dropped, and a choice point is presented without selection.", "source_refs": [ "SRC-138", "SRC-058", "SRC-023", "SRC-014", "SRC-136", "SRC-137" ], "questions": [ { "id": "dep-rpt-q-degraded-contradiction", "text": "How are two contradictory assertions about the same edge reported without silently choosing a winner?", "kind": "exception", "answer_data": [ "contradiction record holding both assertions with their sources and assertion times", "optional preferred reading with an explicit stated rationale", "rule retaining the non-preferred assertion", "mandatory confidence downgrade for dependent conclusions" ] }, { "id": "dep-rpt-q-degraded-staleness", "text": "At what point is an assertion treated as stale, and what must the report say when it has to rely on one?", "kind": "temporal", "answer_data": [ "declared staleness threshold or validity-until value from the assertion", "stale marker with the age at time of use", "statement of the conclusions that depend on stale input", "required completeness or confidence downgrade" ] }, { "id": "dep-rpt-q-degraded-unknown-endpoint", "text": "How is an edge whose target cannot be resolved reported, and how does it affect the conclusions downstream of it?", "kind": "state", "answer_data": [ "unknown-endpoint marker retaining the unresolved reference as given", "reason such as missing record, ambiguous identifier or out-of-scope namespace", "truncation note on every path that terminates at the unknown endpoint", "effect on the coverage measurement" ] }, { "id": "dep-rpt-q-degraded-cycles", "text": "How are cycles detected, cut and disclosed so that the reported path set stays finite without hiding the cycle?", "kind": "constraint", "answer_data": [ "cycle record listing the participating nodes and edges", "declared and versioned cut rule with the chosen cut point", "statement that the cut is a reporting device and not an assertion about the real graph", "effect on impact classes computed across the cycle" ] }, { "id": "dep-rpt-q-degraded-alternatives", "text": "When several alternative satisfiers exist for one requirement, how are they reported without asserting a selection?", "kind": "decision", "answer_data": [ "alternative satisfier set with each option's identifier", "per-option impact consequence where computed", "explicit no-selection statement", "identification of the model or role that owns selection" ] } ], "data_elements": [ { "id": "dep-rpt-de-contradiction-record", "name": "Contradiction record", "description": "Two or more mutually inconsistent assertions about the same edge or element, retained together with their sources and assertion times.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-138" ] }, { "id": "dep-rpt-de-staleness-threshold", "name": "Staleness threshold", "description": "Declared age or validity boundary past which an assertion is marked stale for reporting purposes.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-138" ] }, { "id": "dep-rpt-de-stale-marker", "name": "Stale assertion marker", "description": "Marker on an input assertion that it exceeded the staleness threshold at the time it was used.", "value_kind": "boolean", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-138" ] }, { "id": "dep-rpt-de-unknown-endpoint-marker", "name": "Unknown endpoint marker", "description": "Marker for an edge target that could not be resolved, retaining the unresolved reference and the reason.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-014", "SRC-058" ] }, { "id": "dep-rpt-de-cycle-record", "name": "Cycle record", "description": "Detected cycle with participating nodes and edges, the versioned cut rule applied and the chosen cut point.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-023" ] }, { "id": "dep-rpt-de-partial-coverage-flag", "name": "Partial coverage marker", "description": "Marker that the traversal covered only part of the in-scope graph, bound to the region and cause.", "value_kind": "boolean", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-136", "SRC-014" ] }, { "id": "dep-rpt-de-degradation-effect-note", "name": "Degradation effect note", "description": "Statement of how a specific degraded condition changes the reading of the conclusions it touches.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-058" ] } ], "artifacts": [ { "id": "dep-rpt-art-degradation-register", "name": "Degradation and Known-Unknowns Register", "description": "Register of every degraded condition encountered while producing one report revision: contradictions with both assertions retained, stale assertions, unresolvable endpoints, cut cycles, alternative satisfier sets and partial-coverage regions, each with its effect on the affected conclusions.", "media_or_form": [ "structured degradation register", "narrative limitations statement" ], "serial": false, "identity_strategy": "Addressed by owning report identifier and revision plus a condition identifier unique within that revision; each entry retains the source identifier of the assertion or element it concerns.", "source_refs": [ "SRC-014", "SRC-138", "SRC-058", "SRC-023" ] } ], "inline_only_rationale": null } ] }, { "id": "dep-rpt-rendition-handoff", "name": "Rendition and Handoff", "description": "How one report revision is presented in machine-readable and human-readable form against a single evidence set, and how it declares the limits of its own authority.", "source_refs": [ "SRC-137", "SRC-012", "SRC-139", "SRC-140" ], "findings": [ { "id": "dep-rpt-rendition-traceability", "name": "Dual Rendition Traceability and Non-Authorising Handoff", "description": "The machine-readable and human-readable renditions of one report revision must resolve to the same conclusion anchors and the same evidence register, and every rendition must carry an explicit declaration of the acts it does not perform together with the model or role that owns each of those acts. Also covers who may read each rendition and how a rendition is corrected without creating a second conclusion of record.", "source_refs": [ "SRC-137", "SRC-012", "SRC-139", "SRC-140", "SRC-001" ], "questions": [ { "id": "dep-rpt-q-rendition-anchoring", "text": "How does a sentence in the human-readable rendition resolve to the same conclusion anchor and evidence citations as the machine-readable rendition?", "kind": "interoperability", "answer_data": [ "conclusion anchor identifier embedded in both renditions", "evidence identifiers referenced identically in both", "rule that a human-readable claim without an anchor is not a conclusion of record" ] }, { "id": "dep-rpt-q-rendition-equivalence", "text": "What must be true before two renditions of one report revision may be published as equivalent?", "kind": "validation", "answer_data": [ "equivalence attestation naming both renditions and the attesting role", "check that every machine conclusion has an anchored human counterpart or a declared omission", "check that no non-droppable disclosure was lost", "shared revision digest chain" ] }, { "id": "dep-rpt-q-rendition-non-authorising", "text": "Which downstream acts does this report explicitly not perform, and which model or role is named as owning each of them?", "kind": "authority", "answer_data": [ "enumerated non-performed acts covering approval, execution, remediation, delivery and audit storage", "named owning model or role for each act", "statement that no field in the report constitutes a decision, dispatch or completion record" ] }, { "id": "dep-rpt-q-rendition-access", "text": "Who may read each rendition, and how does the report's handling marking constrain onward sharing?", "kind": "access", "answer_data": [ "read scope per rendition", "handling marking inherited from the most restrictive incorporated evidence", "marking placement requirements on the rendition itself", "named access model that executes grants and revocations" ] }, { "id": "dep-rpt-q-rendition-correction", "text": "How is a rendition regenerated or corrected without creating a second conclusion of record?", "kind": "lifecycle", "answer_data": [ "rule that renditions share the revision number of the report they render", "regeneration permitted only while the digest chain resolves to the same revision", "content correction forcing a new revision and a new equivalence attestation" ] } ], "data_elements": [ { "id": "dep-rpt-de-rendition-identifier", "name": "Rendition identifier", "description": "Identifier of one rendition, composed of the report identifier, its revision and a rendition discriminator.", "value_kind": "identifier", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-137" ] }, { "id": "dep-rpt-de-rendition-form", "name": "Rendition form", "description": "Whether the rendition is the machine-readable carrier or a human-readable presentation, stated without naming a file format.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-137" ] }, { "id": "dep-rpt-de-equivalence-attestation", "name": "Rendition equivalence attestation", "description": "Attestation by a named role that two renditions of one revision carry the same conclusions, anchors and non-droppable disclosures.", "value_kind": "object", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-137", "SRC-001" ] }, { "id": "dep-rpt-de-non-authorising-declaration", "name": "Non-authorising declaration", "description": "Explicit statement of the acts the report does not perform, carried on every rendition.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-140" ] }, { "id": "dep-rpt-de-downstream-owner-ref", "name": "Downstream act owner reference", "description": "Reference naming the model or role that owns each non-performed downstream act.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-140", "SRC-012" ] }, { "id": "dep-rpt-de-revision-digest", "name": "Revision digest", "description": "Digest over the canonical form of the revision, binding both renditions to the same content.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-137" ] } ], "artifacts": [ { "id": "dep-rpt-art-machine-rendition", "name": "Machine-Readable Rendition", "description": "The normative carrier of one report revision's conclusion anchors, evidence citations, path references and disclosure block, expressed in a structured form for programmatic consumption.", "media_or_form": [ "structured serialization independent of any particular encoding" ], "serial": true, "identity_strategy": "Report identifier plus revision plus a machine-rendition discriminator; validity requires that its digest resolve to the revision's canonical form.", "source_refs": [ "SRC-137", "SRC-012" ] }, { "id": "dep-rpt-art-human-rendition", "name": "Human-Readable Rendition", "description": "Narrative or tabular presentation of the same revision in which every asserted conclusion carries the anchor of the machine-readable conclusion it restates, together with the handling marking and the non-authorising declaration.", "media_or_form": [ "narrative document", "tabular summary", "presentation extract" ], "serial": true, "identity_strategy": "Report identifier plus revision plus a human-rendition discriminator and, where applicable, a language variant tag; shares the revision digest of its machine counterpart.", "source_refs": [ "SRC-137", "SRC-139" ] } ], "inline_only_rationale": null } ] } ] }, { "id": "dep-proj-fidelity-bundle", "name": "Projection Fidelity and Expressivity Contract", "description": "What a rendering of a dependency or impact assertion must preserve, how it is canonicalised and ordered, which target formats cannot carry the full semantics, how that shortfall is declared, and how terms and namespaces are bound to external vocabularies.", "rationale": "Dependency and impact assertions are minimally a directional relation with one source endpoint, one or more target endpoints, a relation type, a completeness qualifier and optional start/end times (SRC-013, SRC-014). Most carriers cannot hold that shape: RDF can express relations over more than two entities only indirectly (SRC-143), CSV cells hold only atomic or list values with no nesting and no graph links (SRC-146), and CSV itself has never been formally specified (SRC-142). A fidelity contract is therefore required before any format is emitted, so that loss is declared rather than discovered.", "source_refs": [ "SRC-013", "SRC-014", "SRC-142", "SRC-143", "SRC-146" ], "layers": [ { "id": "dep-proj-invariants-layer", "name": "Projection Invariants and Canonical Form", "description": "The properties of an assertion that every projection must carry regardless of format, and the deterministic byte-level form used to identify, compare and digest a projection.", "source_refs": [ "SRC-013", "SRC-122", "SRC-149", "SRC-154" ], "findings": [ { "id": "dep-proj-assertion-identity-carry", "name": "Assertion identity, direction and endpoint-role carriage", "description": "Every projection must carry a resolvable assertion identifier, the assertion's revision, the direction of the relation, and the role of each endpoint (single source endpoint versus one or more target endpoints), so that a consumer can rejoin the projection to the authoritative assertion without re-deriving it. Where the target format has no place for these, the projection must nominate a sidecar or embedded machine block rather than dropping them.", "source_refs": [ "SRC-013", "SRC-145", "SRC-149", "SRC-152" ], "questions": [ { "id": "dep-proj-q-identity-carrier", "text": "Which field, attribute or URI in each target format carries the authoritative assertion identifier, and is it dereferenceable?", "kind": "identity", "answer_data": [ "Target format code", "Carrier path expression (JSON Pointer, XPath, column name, itemid attribute, resource URI)", "Dereferenceable flag", "Resolution base IRI" ] }, { "id": "dep-proj-q-endpoint-roles", "text": "How does the projection distinguish the single source endpoint from the one-or-many target endpoints when the carrier only has undirected or symmetric structures?", "kind": "relationship", "answer_data": [ "Source endpoint reference", "Ordered target endpoint reference list", "Role label vocabulary term", "Direction encoding strategy" ] }, { "id": "dep-proj-q-nonassertion-encoding", "text": "How is 'no dependency exists' encoded distinctly from 'no assertion is being made' in each carrier?", "kind": "classification", "answer_data": [ "Completeness code (complete, incomplete, noAssertion)", "None-endpoint sentinel encoding", "No-assertion sentinel encoding", "Carrier-specific null-handling note" ] }, { "id": "dep-proj-q-carrier-vs-assertion-id", "text": "When a carrier assigns its own identifier, such as a Git object hash or a document primary key, which identifier is authoritative for the assertion?", "kind": "provenance", "answer_data": [ "Carrier-assigned identifier", "Authoritative assertion identifier", "Precedence rule statement", "Mapping record reference" ] }, { "id": "dep-proj-q-invariant-verification", "text": "What check confirms that all mandatory invariants survived a given rendering before it is stored?", "kind": "validation", "answer_data": [ "Invariant checklist identifier", "Per-invariant pass or fail result", "Failing invariant list", "Verification timestamp" ] } ], "data_elements": [ { "id": "dep-proj-de-assertion-ref", "name": "Projected assertion reference", "description": "Reference to the authoritative dependency/impact assertion and its revision that this projection renders.", "value_kind": "reference", "cardinality": "1", "required": true, "source_refs": [ "SRC-013" ] }, { "id": "dep-proj-de-endpoint-role-binding", "name": "Endpoint role binding", "description": "Mapping from each assertion endpoint and its role (source or target) to the concrete location in the target format that carries it.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-013", "SRC-149" ] }, { "id": "dep-proj-de-direction-encoding", "name": "Direction encoding strategy", "description": "Coded strategy used to preserve relation direction in the carrier (native directed edge, role-named property, reified relation node, ordered column pair).", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-143", "SRC-144" ] }, { "id": "dep-proj-de-completeness-carrier", "name": "Completeness qualifier carrier", "description": "Where the complete / incomplete / noAssertion qualifier is placed in the projection, or the declared reason it cannot be placed.", "value_kind": "text", "cardinality": "1", "required": true, "source_refs": [ "SRC-014" ] } ], "artifacts": [ { "id": "dep-proj-art-identity-binding-map", "name": "Projection Identity Binding Map", "description": "Per-format table binding assertion identifier, revision, direction, endpoint roles and completeness qualifier to concrete carrier locations, including the sidecar or embedded block used where the carrier has no native slot.", "media_or_form": [ "structured field-binding table", "embedded machine-readable block (JSON-LD @context plus @id, or HTML microdata itemid/itemprop)", "sidecar metadata descriptor" ], "serial": false, "identity_strategy": "Identified by the adopting Dimension's authoritative binding-map identifier; where none exists, a governed IRI formed from the model namespace and the target format code, with the map revision recorded separately.", "source_refs": [ "SRC-145", "SRC-149", "SRC-146" ] } ], "inline_only_rationale": null }, { "id": "dep-proj-canonical-form", "name": "Canonical form, deterministic ordering and integrity digest", "description": "The deterministic serialization used to compare, digest and sign a projection: recursive key ordering, whitespace suppression, number and string normalisation, a declared collation for collection ordering, and a content digest that binds the bytes. Canonical form exists for comparison and integrity, not as the published presentation form.", "source_refs": [ "SRC-122", "SRC-141", "SRC-154", "SRC-155" ], "questions": [ { "id": "dep-proj-q-canonical-algorithm", "text": "Which canonicalization algorithm and version applies to this projection profile, and what is its normative status?", "kind": "constraint", "answer_data": [ "Canonicalization algorithm identifier", "Algorithm version or RFC reference", "Normative status note (standards-track versus informational)", "Deviation list" ] }, { "id": "dep-proj-q-collection-ordering", "text": "What total order is applied to the target-endpoint list and to any repeated structures, and which collation is used?", "kind": "constraint", "answer_data": [ "Sort key expression", "Collation identifier (for example UTF-16 code-unit order)", "Tie-break rule", "Stability guarantee statement" ] }, { "id": "dep-proj-q-digest-binding", "text": "Which digest algorithm binds the canonical bytes, and what exactly is covered by the digest?", "kind": "evidence", "answer_data": [ "Digest algorithm identifier", "Digest value", "Covered byte range or component list", "Digest computation time" ] }, { "id": "dep-proj-q-byte-stability", "text": "How are line endings, encoding and trailing bytes fixed so that the same input yields identical bytes on every platform?", "kind": "quality", "answer_data": [ "Character encoding declaration", "Line-ending policy", "Trailing-newline rule", "Idempotence test result for repeated generation" ] }, { "id": "dep-proj-q-canonical-scope", "text": "Is the canonical form the published form, and if not which transformation produces the published form?", "kind": "decision", "answer_data": [ "Published form code", "Transformation identifier applied after canonicalization", "Reversibility flag", "Rationale note" ] } ], "data_elements": [ { "id": "dep-proj-de-canonical-algorithm", "name": "Canonicalization algorithm binding", "description": "Identifier and version of the canonicalization rule set applied, with any declared deviations.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-122" ] }, { "id": "dep-proj-de-order-key", "name": "Ordering key and collation", "description": "The declared sort key, collation and tie-break used to impose a total order on projected collections.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-122", "SRC-149" ] }, { "id": "dep-proj-de-content-digest", "name": "Canonical content digest", "description": "Algorithm-qualified digest over the canonical byte sequence, used as the integrity and comparison handle for the projection.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-155", "SRC-141" ] }, { "id": "dep-proj-de-encoding-policy", "name": "Encoding and byte-stability policy", "description": "Character encoding, line-ending normalisation and trailing-byte rules that make repeated generation byte-identical.", "value_kind": "object", "cardinality": "1", "required": true, "source_refs": [ "SRC-154" ] } ], "artifacts": [ { "id": "dep-proj-art-canonical-serialization", "name": "Canonical Projection Serialization", "description": "The deterministic byte sequence produced for a specific assertion set, target profile and profile version, retained as the comparison and digest basis for the corresponding published projection.", "media_or_form": [ "deterministic byte stream", "canonical JSON (sorted keys, no inter-token whitespace)", "canonical RDF serialization", "content-addressed repository object" ], "serial": true, "identity_strategy": "Identified by its algorithm-qualified content digest; where the adopting Dimension operates an authoritative artifact register, the register identifier takes precedence and the digest is retained as the integrity claim.", "source_refs": [ "SRC-122", "SRC-155" ] } ], "inline_only_rationale": null } ] }, { "id": "dep-proj-expressivity-layer", "name": "Expressivity Mapping, Loss Declaration and Round-Trip", "description": "The per-format capability assessment for n-ary, conditional, temporal and uncertain assertion semantics, the mandatory machine-readable loss report when a format falls short, and the round-trip expectation attached to each projection pair.", "source_refs": [ "SRC-142", "SRC-143", "SRC-144", "SRC-146", "SRC-147", "SRC-153" ], "findings": [ { "id": "dep-proj-capability-matrix", "name": "Per-format expressivity capability assessment", "description": "For each target format, a recorded assessment of whether it can natively express relations over more than two entities, conditions or guards on an assertion, validity intervals, and uncertainty or non-assertion - and if not, which documented workaround pattern is mandated. RDF expresses relations over more than two entities only indirectly; CSV cells hold only atomic or list values; YAML discards anchors, comments and style as presentation detail; document stores lose numeric and date type distinctions in relaxed mode.", "source_refs": [ "SRC-143", "SRC-144", "SRC-146", "SRC-147", "SRC-153", "SRC-148" ], "questions": [ { "id": "dep-proj-q-nary-support", "text": "Can this format natively express an assertion linking a source endpoint to several target endpoints, and if not which reification or relation-class pattern is mandated?", "kind": "interoperability", "answer_data": [ "Format code", "Native n-ary support flag", "Mandated workaround pattern code (relation-class node, reifier triple, list, join table)", "Reference to pattern definition" ] }, { "id": "dep-proj-q-conditional-support", "text": "How are conditions or guards that qualify an assertion represented, and what happens to them when the carrier has no slot?", "kind": "constraint", "answer_data": [ "Condition carrier path", "Representation strategy code", "Degradation behaviour code (retain, sidecar, drop-with-report)", "Consumer warning text" ] }, { "id": "dep-proj-q-temporal-support", "text": "Which time semantics can this format carry: validity interval endpoints, event time, and observation or generation time?", "kind": "temporal", "answer_data": [ "Validity start support flag", "Validity end support flag", "Event time support flag", "Observation or generation time support flag", "Timestamp encoding rule" ] }, { "id": "dep-proj-q-uncertainty-support", "text": "How is confidence, inference status or explicit non-assertion represented without a consumer reading it as a firm claim?", "kind": "quality", "answer_data": [ "Confidence encoding strategy", "Asserted versus non-asserted marker", "Completeness qualifier placement", "Consumer interpretation note" ] }, { "id": "dep-proj-q-capability-evidence", "text": "Which specification clause supports each capability verdict, and when was that clause last checked?", "kind": "evidence", "answer_data": [ "Specification reference URL", "Clause or section identifier", "Specification version or date", "Verdict review timestamp" ] } ], "data_elements": [ { "id": "dep-proj-de-format-code", "name": "Target format code", "description": "Coded identifier of the projection target (files and Git, Markdown, HTML, JSON, YAML, CSV, RDF, HTTP API, MCP, document store, domain-standard carrier).", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-119", "SRC-152", "SRC-015" ] }, { "id": "dep-proj-de-capability-verdict", "name": "Capability verdict", "description": "Per semantic dimension (n-ary, conditional, temporal, uncertainty, provenance), a verdict of native, workaround-required or unsupported.", "value_kind": "code", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-143", "SRC-146" ] }, { "id": "dep-proj-de-workaround-pattern", "name": "Mandated workaround pattern", "description": "The documented pattern to be used where support is not native, such as a relation-class node or a reifying triple.", "value_kind": "code", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-144", "SRC-143" ] }, { "id": "dep-proj-de-capability-evidence-ref", "name": "Capability evidence reference", "description": "Specification URL, clause and version supporting each verdict, with the date the clause was last verified.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-147", "SRC-153" ] } ], "artifacts": [ { "id": "dep-proj-art-capability-matrix", "name": "Projection Capability Matrix", "description": "Versioned matrix of target formats against the semantic dimensions of a dependency/impact assertion, recording native support, mandated workaround, or unsupported, each with a citation to the governing specification clause and version.", "media_or_form": [ "versioned decision matrix", "tabular record with per-cell citations", "machine-readable capability descriptor" ], "serial": false, "identity_strategy": "Identified by the adopting Dimension's authoritative matrix identifier; otherwise a governed IRI under the model namespace, with revisions distinguished by a monotonically increasing revision counter rather than by publication date.", "source_refs": [ "SRC-143", "SRC-146", "SRC-153" ] } ], "inline_only_rationale": null }, { "id": "dep-proj-loss-report", "name": "Mandatory projection loss report", "description": "A machine-readable report emitted with every projection whose target format cannot carry the full assertion semantics, naming each dropped or degraded element, the reason, the severity, and where the omitted content can still be obtained. A projection into a lossy format is only valid when accompanied by this report; silent degradation is a defect.", "source_refs": [ "SRC-120", "SRC-142", "SRC-146", "SRC-153", "SRC-141" ], "questions": [ { "id": "dep-proj-q-loss-inventory", "text": "Which specific assertion elements were dropped, flattened or coerced in this rendering, and at which path?", "kind": "validation", "answer_data": [ "Dropped element path list", "Degradation kind code (dropped, flattened, coerced, truncated, sentinel-substituted)", "Original value reference", "Occurrence count" ] }, { "id": "dep-proj-q-loss-severity", "text": "How severe is each loss for a consumer making an impact decision from this projection?", "kind": "decision", "answer_data": [ "Severity code", "Affected decision class", "Safe-use statement", "Unsafe-use warning" ] }, { "id": "dep-proj-q-loss-recovery", "text": "Where can a consumer obtain the omitted content, and is that route available to the same audience as the projection?", "kind": "access", "answer_data": [ "Recovery locator or IRI", "Recovery format code", "Audience equivalence flag", "Fallback instruction" ] }, { "id": "dep-proj-q-loss-report-shape", "text": "What is the wire shape of the loss report and how is it correlated with the projection it describes?", "kind": "interoperability", "answer_data": [ "Report media type", "Problem type IRI", "Correlation key (projection digest or run identifier)", "Extension member list" ] }, { "id": "dep-proj-q-loss-threshold", "text": "Which losses block emission outright rather than being reported and accepted?", "kind": "exception", "answer_data": [ "Blocking loss class list", "Threshold rule expression", "Override request reference", "Override decision owner reference" ] } ], "data_elements": [ { "id": "dep-proj-de-loss-entry", "name": "Loss entry", "description": "One recorded degradation: the source path, the degradation kind, the reason clause, the severity and the occurrence count.", "value_kind": "object", "cardinality": "0..n", "required": true, "source_refs": [ "SRC-120" ] }, { "id": "dep-proj-de-loss-type-iri", "name": "Loss problem type identifier", "description": "Stable IRI identifying the class of loss, resolvable to human-readable documentation of its cause and consequences.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-120" ] }, { "id": "dep-proj-de-recovery-locator", "name": "Omitted-content recovery locator", "description": "Locator for a representation that still carries the omitted content, plus a flag indicating whether the same audience can reach it.", "value_kind": "reference", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-119", "SRC-141" ] }, { "id": "dep-proj-de-lossless-claim", "name": "Lossless claim flag", "description": "Explicit boolean asserting that no semantic element was dropped or degraded; must be false whenever any loss entry exists.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-142", "SRC-146" ] } ], "artifacts": [ { "id": "dep-proj-art-loss-report", "name": "Projection Loss Report", "description": "Machine-readable report accompanying a projection run, listing every dropped, flattened, coerced or sentinel-substituted element with a stable problem-type identifier, severity, recovery locator and correlation to the projection digest.", "media_or_form": [ "problem-details style JSON document with extension members", "sidecar report file adjacent to the projection", "API error or warning payload" ], "serial": true, "identity_strategy": "Identified by the projection run identifier it is correlated with, which itself derives from the adopting Dimension's authoritative run register; the canonical digest of the described projection is carried as a correlation key, not as the report identifier.", "source_refs": [ "SRC-120", "SRC-119" ] } ], "inline_only_rationale": null }, { "id": "dep-proj-roundtrip-conformance", "name": "Round-trip expectation and conformance verdict", "description": "For each projection profile, the declared round-trip class - byte-lossless, semantics-lossless, one-way presentational, or not round-trippable - and the corpus-based test that substantiates it. Filter and rendering pipelines must be idempotent, and a claim of losslessness requires a passing verdict, not an assumption.", "source_refs": [ "SRC-154", "SRC-147", "SRC-148", "SRC-122", "SRC-141" ], "questions": [ { "id": "dep-proj-q-roundtrip-class", "text": "What round-trip class is claimed for this projection profile, and is the claim symmetric in both directions?", "kind": "requirement", "answer_data": [ "Round-trip class code", "Forward direction claim", "Reverse direction claim", "Asymmetry note" ] }, { "id": "dep-proj-q-roundtrip-comparator", "text": "What comparison decides whether a round trip succeeded: byte equality, canonical digest equality or semantic equivalence?", "kind": "validation", "answer_data": [ "Comparator code", "Canonicalization step applied before comparison", "Tolerated difference list", "Comparison result" ] }, { "id": "dep-proj-q-roundtrip-corpus", "text": "Which test corpus exercises the hard cases - multi-target assertions, conditional assertions, open intervals and explicit non-assertions?", "kind": "evidence", "answer_data": [ "Corpus identifier and revision", "Case count by semantic dimension", "Coverage gap list", "Last execution timestamp" ] }, { "id": "dep-proj-q-idempotence", "text": "Is repeated application of the rendering and parsing filters idempotent, and what evidence shows it?", "kind": "quality", "answer_data": [ "Idempotence test result", "Repeated-application difference report", "Filter identifier and version", "Known non-idempotent step list" ] }, { "id": "dep-proj-q-roundtrip-failure-handling", "text": "What happens when a profile that previously claimed losslessness fails its round-trip test?", "kind": "process", "answer_data": [ "Failure verdict record reference", "Claim downgrade action", "Consumer notification requirement", "Owner responsible for the downgrade decision" ] } ], "data_elements": [ { "id": "dep-proj-de-roundtrip-class", "name": "Round-trip class", "description": "Declared class for the projection pair: byte-lossless, semantics-lossless, one-way presentational, or not round-trippable.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-147", "SRC-148" ] }, { "id": "dep-proj-de-comparator", "name": "Round-trip comparator", "description": "The comparison basis used to judge round-trip success, including the canonicalization applied before comparison.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-122" ] }, { "id": "dep-proj-de-conformance-verdict", "name": "Conformance verdict", "description": "Pass, fail or partial verdict for a corpus execution against a named profile revision, with the failing case list.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-141" ] }, { "id": "dep-proj-de-idempotence-result", "name": "Filter idempotence result", "description": "Result of applying the rendering and parsing filters repeatedly, confirming that repeated application does not alter the output.", "value_kind": "boolean", "cardinality": "1", "required": true, "source_refs": [ "SRC-154" ] } ], "artifacts": [ { "id": "dep-proj-art-roundtrip-corpus", "name": "Round-Trip Conformance Corpus", "description": "Curated set of dependency and impact assertion cases covering multi-target, conditional, open-interval, uncertain and explicitly non-asserted forms, held with the expected projection output for each declared profile.", "media_or_form": [ "versioned test case collection", "paired input and expected-output fixtures", "corpus manifest" ], "serial": false, "identity_strategy": "Identified by the adopting Dimension's authoritative corpus register identifier; otherwise a governed IRI under the model namespace with a monotonic revision counter.", "source_refs": [ "SRC-141", "SRC-148" ] }, { "id": "dep-proj-art-roundtrip-verdict", "name": "Round-Trip Conformance Verdict", "description": "Record of one corpus execution against one profile revision, stating comparator, per-case outcome, idempotence result and the resulting round-trip class claim.", "media_or_form": [ "structured verdict record", "conformance summary report" ], "serial": true, "identity_strategy": "Identified by the run identifier issued by the adopting Dimension's execution register, with the corpus revision and profile revision recorded as attributes rather than embedded in the identifier.", "source_refs": [ "SRC-122", "SRC-154" ] } ], "inline_only_rationale": null } ] }, { "id": "dep-proj-binding-layer", "name": "Namespace, Term and Domain-Standard Binding", "description": "How local assertion terms are bound to stable global identifiers in each carrier, and how the projection declares alignment to independent domain standards for dependency information without asserting conformance to them.", "source_refs": [ "SRC-145", "SRC-013", "SRC-015", "SRC-149" ], "findings": [ { "id": "dep-proj-namespace-binding", "name": "Namespace, prefix and term binding declaration", "description": "The declared mapping from local assertion terms to stable global identifiers, the prefixes used, the resolution base, and the versioning of the mapping itself. A projection must declare its term bindings explicitly so that two projections emitted at different times cannot silently disagree about what a term means.", "source_refs": [ "SRC-145", "SRC-149", "SRC-143", "SRC-146" ], "questions": [ { "id": "dep-proj-q-term-mapping", "text": "Which global identifier does each local relation type, endpoint role and qualifier map to in this projection profile?", "kind": "interoperability", "answer_data": [ "Local term name", "Target IRI", "Mapping kind (exact, broader, narrower, no match)", "Vocabulary version" ] }, { "id": "dep-proj-q-prefix-governance", "text": "Which prefixes are bound in this profile, and who governs the namespaces they abbreviate?", "kind": "authority", "answer_data": [ "Prefix string", "Namespace IRI", "Governing organisation", "Namespace stability statement" ] }, { "id": "dep-proj-q-unmapped-terms", "text": "How are local terms with no global counterpart emitted so that consumers do not mistake them for standard terms?", "kind": "constraint", "answer_data": [ "Unmapped term list", "Local namespace IRI used", "Consumer handling instruction", "Escalation route for adding a mapping" ] }, { "id": "dep-proj-q-context-versioning", "text": "How is a change to the term binding map versioned and correlated with previously emitted projections?", "kind": "lifecycle", "answer_data": [ "Binding map revision identifier", "Change classification", "Affected projection profile list", "Superseded binding reference" ] } ], "data_elements": [ { "id": "dep-proj-de-term-binding", "name": "Term binding entry", "description": "One local term mapped to a target IRI with an explicit mapping kind and the source vocabulary version.", "value_kind": "object", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-145" ] }, { "id": "dep-proj-de-prefix-binding", "name": "Prefix binding", "description": "Prefix string bound to a namespace IRI, with the governing organisation and stability statement recorded.", "value_kind": "object", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-143", "SRC-149" ] }, { "id": "dep-proj-de-resolution-base", "name": "Resolution base IRI", "description": "Base IRI against which relative references in the projection are resolved.", "value_kind": "identifier", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-145" ] }, { "id": "dep-proj-de-binding-revision", "name": "Binding map revision", "description": "Monotonic revision identifier of the binding map applied to a given projection run.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-145", "SRC-146" ] } ], "artifacts": [ { "id": "dep-proj-art-namespace-binding-map", "name": "Projection Namespace and Term Binding Map", "description": "Machine-readable declaration of prefixes, namespace IRIs, resolution base and per-term mappings used when rendering dependency and impact assertions into a semantic or tabular carrier, including explicit handling for terms with no global counterpart.", "media_or_form": [ "linked-data context document", "tabular metadata descriptor for columnar carriers", "prefix and vocabulary manifest" ], "serial": false, "identity_strategy": "Identified by the authoritative namespace-registry identifier of the adopting Dimension where one exists; otherwise a governed IRI under the model namespace, with revisions carried in a separate revision attribute.", "source_refs": [ "SRC-145", "SRC-146" ] } ], "inline_only_rationale": null }, { "id": "dep-proj-domain-standard-profile", "name": "Domain-standard carrier alignment", "description": "Declared alignments between this model's dependency and impact assertions and independent domain standards for dependency information, recorded as bindings and mapping gaps rather than as conformance claims. At least two independently governed carriers are recognised so that no single consortium format is treated as canonical.", "source_refs": [ "SRC-013", "SRC-014", "SRC-141", "SRC-015", "SRC-001" ], "questions": [ { "id": "dep-proj-q-standard-selection", "text": "Which domain standards are recognised as carriers for these assertions, and which independent bodies govern each?", "kind": "interoperability", "answer_data": [ "Standard identifier and edition", "Governing organisation", "Carrier scope statement", "Selection rationale" ] }, { "id": "dep-proj-q-relation-type-mapping", "text": "How does each local relation type map onto the target standard's relationship vocabulary, and which types have no counterpart?", "kind": "classification", "answer_data": [ "Local relation type", "Target vocabulary term", "Mapping kind", "Unmapped type list with reason" ] }, { "id": "dep-proj-q-alignment-conflicts", "text": "Where do two recognised standards disagree about direction, cardinality or completeness semantics for the same relation?", "kind": "constraint", "answer_data": [ "Conflicting standard pair", "Conflict description", "Affected assertion property", "Resolution or non-resolution statement" ] }, { "id": "dep-proj-q-conformance-evidence", "text": "What evidence would be required before claiming conformance rather than alignment to a domain standard?", "kind": "evidence", "answer_data": [ "Required test suite reference", "Certification or self-attestation route", "Current claim level (alignment only)", "Evidence gap list" ] } ], "data_elements": [ { "id": "dep-proj-de-standard-binding", "name": "Domain standard binding", "description": "Reference to a recognised domain standard, its edition, its governing body and the profile subset this model binds to.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-141", "SRC-015" ] }, { "id": "dep-proj-de-relation-type-map", "name": "Relation type mapping entry", "description": "Local relation type mapped to a target-standard vocabulary term with an explicit mapping kind, including no-match entries.", "value_kind": "object", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-013" ] }, { "id": "dep-proj-de-alignment-conflict", "name": "Alignment conflict record", "description": "Recorded disagreement between two recognised standards about direction, cardinality or completeness for the same relation concept.", "value_kind": "text", "cardinality": "0..n", "required": false, "source_refs": [ "SRC-014", "SRC-015" ] }, { "id": "dep-proj-de-claim-level", "name": "Standard claim level", "description": "Explicit claim level for each binding: alignment, partial conformance with evidence, or conformance with cited test results.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-141", "SRC-001" ] } ], "artifacts": [], "inline_only_rationale": "This finding produces no artifact of its own. It is a set of reference declarations pointing at externally governed vocabularies whose definitions, versions and change control belong to the issuing standards bodies. Materialising a local copy of a domain-standard vocabulary would create a second, unauthoritative source of relation-type meaning that would drift from the upstream edition, and would breach the alignment-not-conformance rule by implying local ownership of terms this model only references. The binding parameters - standard reference, edition, mapped term, mapping kind, conflict note and claim level - are small, purely referential values that belong inline on the projection profile; the concrete carrier documents they enable are produced by the projection run, not by this finding." } ] } ] }, { "id": "dep-proj-operation-bundle", "name": "Projection Generation and Compatibility Control", "description": "How a projection run is executed and recorded as derived output with its own provenance and timing, and how changes to a projection profile are classified and declared to consumers - with generation deliberately separated from publication approval and from any mutation of the assertion endpoints.", "rationale": "A projection is a representation of a resource, and one resource may have many representations selected per request (SRC-119); the representation is therefore derived, never authoritative. Derivation of one entity from another, by an activity, at a time, is exactly what PROV-O models (SRC-001), and consumer-visible compatibility is governed by the increment rules of semantic versioning (SRC-156) and by date-stamped protocol revisions that change only on backwards-incompatible change (SRC-151). Recording the run and the compatibility class is in scope; approving release and writing to endpoints is not.", "source_refs": [ "SRC-119", "SRC-001", "SRC-151", "SRC-156" ], "layers": [ { "id": "dep-proj-generation-layer", "name": "Generation Run and Derivation Provenance", "description": "The record of a single projection generation: inputs, profile, agent, event time versus generation and observation time, digest, verdicts, and the explicit statement that the run produced a candidate only.", "source_refs": [ "SRC-001", "SRC-119", "SRC-155", "SRC-152" ], "findings": [ { "id": "dep-proj-generation-run", "name": "Projection run record and derivation provenance", "description": "One record per generation, binding the source assertion revision, the profile and binding-map revisions, the executing agent, the canonical digest, the loss report and the round-trip verdict, and distinguishing the time the underlying assertion held from the time it was observed and the time the projection bytes were produced. The record's effect ends at a stored candidate; it neither publishes nor mutates any endpoint.", "source_refs": [ "SRC-001", "SRC-119", "SRC-152", "SRC-155" ], "questions": [ { "id": "dep-proj-q-run-inputs", "text": "Exactly which assertion revision, profile revision and binding-map revision were consumed by this run?", "kind": "provenance", "answer_data": [ "Source assertion revision reference", "Projection profile revision", "Binding map revision", "Capability matrix revision" ] }, { "id": "dep-proj-q-run-times", "text": "How are the assertion's own validity time, the observation time and the generation time recorded separately in this run?", "kind": "temporal", "answer_data": [ "Assertion validity interval", "Observation or ingestion timestamp", "Generation start timestamp", "Generation completion timestamp" ] }, { "id": "dep-proj-q-run-agent", "text": "Which agent executed the run and under whose delegated authority?", "kind": "ownership", "answer_data": [ "Executing agent identifier", "Agent kind (software, person, organisation)", "Delegating owner reference", "Software version" ] }, { "id": "dep-proj-q-run-outcome", "text": "What is the run's outcome state, and which candidate artifacts did it produce?", "kind": "state", "answer_data": [ "Run outcome code (succeeded, degraded, failed)", "Produced artifact digest list", "Loss report reference", "Round-trip verdict reference" ] }, { "id": "dep-proj-q-run-boundary", "text": "What confirms that the run performed no publication and no endpoint mutation?", "kind": "security", "answer_data": [ "Write-target allowlist", "Attempted-write rejection count", "Candidate storage location", "Handoff reference to the approving owner" ] } ], "data_elements": [ { "id": "dep-proj-de-run-id", "name": "Projection run identifier", "description": "Identifier of a single generation execution, issued by the adopting Dimension's authoritative run register.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-001" ] }, { "id": "dep-proj-de-derived-from", "name": "Derived-from reference", "description": "Reference to the source assertion revision the projection was derived from, expressed as a derivation link rather than a copy.", "value_kind": "reference", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-001" ] }, { "id": "dep-proj-de-generation-time", "name": "Generation timestamp", "description": "Time at which the projection bytes were produced, recorded separately from the assertion's validity interval and from the observation time.", "value_kind": "timestamp", "cardinality": "1", "required": true, "source_refs": [ "SRC-001", "SRC-119" ] }, { "id": "dep-proj-de-observation-time", "name": "Observation or ingestion timestamp", "description": "Time at which the source assertion state used by the run was observed or ingested, where this differs from the assertion's own validity time.", "value_kind": "timestamp", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-001" ] }, { "id": "dep-proj-de-run-outcome", "name": "Run outcome", "description": "Coded outcome of the run and the references to the loss report and round-trip verdict it produced.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-120", "SRC-152" ] } ], "artifacts": [ { "id": "dep-proj-art-run-record", "name": "Projection Run Record", "description": "Immutable record of one generation execution: inputs and their revisions, executing agent, the three time values, produced candidate digests, loss report and verdict references, and the write-target allowlist proving that no publication or endpoint mutation occurred.", "media_or_form": [ "structured provenance record", "append-only run log entry", "content-addressed repository object" ], "serial": true, "identity_strategy": "Identified by the run identifier from the adopting Dimension's authoritative run register; where no such register exists, a ULID assigned at run start, with the produced-artifact digests recorded as attributes and never used as the run identifier.", "source_refs": [ "SRC-001", "SRC-155" ] } ], "inline_only_rationale": null } ] }, { "id": "dep-proj-compatibility-layer", "name": "Profile Versioning and Consumer Compatibility", "description": "How a change to a projection profile, binding map or capability matrix is classified for consumer impact, declared, and negotiated at read time.", "source_refs": [ "SRC-156", "SRC-151", "SRC-150", "SRC-121", "SRC-119" ], "findings": [ { "id": "dep-proj-version-compatibility", "name": "Projection profile version and compatibility declaration", "description": "The versioning contract for a projection profile: a compatibility class assigned to every change, the distinction between the profile version, the underlying specification version and the version of the assertion content described, the machine-readable change set, and the negotiation behaviour when a consumer asks for an unsupported version.", "source_refs": [ "SRC-156", "SRC-150", "SRC-151", "SRC-121", "SRC-119" ], "questions": [ { "id": "dep-proj-q-compatibility-class", "text": "What compatibility class does this profile change carry, and which consumer behaviour would break without a major increment?", "kind": "constraint", "answer_data": [ "Compatibility class code (major, minor, patch)", "Breaking change description", "Affected consumer behaviour list", "Justification reference" ] }, { "id": "dep-proj-q-version-axes", "text": "Which distinct versions must a consumer read: the profile version, the underlying format specification version, and the version of the described assertion content?", "kind": "interoperability", "answer_data": [ "Projection profile version", "Underlying specification version", "Described content version", "Field carrying each version" ] }, { "id": "dep-proj-q-change-set", "text": "How is the difference between two profile revisions expressed so a consumer can apply it mechanically?", "kind": "process", "answer_data": [ "Change set representation (pointer-based operation list)", "Operation sequence", "Atomicity guarantee statement", "Precondition test operations" ] }, { "id": "dep-proj-q-version-negotiation", "text": "What does a reader receive when it requests a profile version the emitter does not support?", "kind": "exception", "answer_data": [ "Error or status code", "Supported version list returned", "Retry guidance", "Fallback representation reference" ] }, { "id": "dep-proj-q-deprecation-window", "text": "How long does a superseded profile version remain readable, and who decides its removal?", "kind": "retention", "answer_data": [ "Minimum support window duration", "Deprecation notice reference", "Removal decision owner reference", "Migration path statement" ] } ], "data_elements": [ { "id": "dep-proj-de-profile-version", "name": "Projection profile version", "description": "Version identifier of the projection profile itself, incremented per the declared compatibility rules.", "value_kind": "identifier", "cardinality": "1", "required": true, "source_refs": [ "SRC-156", "SRC-151" ] }, { "id": "dep-proj-de-compatibility-class", "name": "Compatibility class", "description": "Classification of a profile change as backward-incompatible, backward-compatible addition, or corrective.", "value_kind": "code", "cardinality": "1", "required": true, "source_refs": [ "SRC-156" ] }, { "id": "dep-proj-de-change-set", "name": "Profile change set", "description": "Ordered, all-or-nothing operation list expressing the difference between two profile revisions, with precondition tests.", "value_kind": "collection", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-121" ] }, { "id": "dep-proj-de-supported-versions", "name": "Supported version list", "description": "Versions an emitter can currently produce or an endpoint can currently serve, returned when a requested version is unsupported.", "value_kind": "collection", "cardinality": "1..n", "required": true, "source_refs": [ "SRC-151", "SRC-119" ] }, { "id": "dep-proj-de-support-window", "name": "Support window duration", "description": "Minimum period a superseded profile version remains readable after a deprecation notice.", "value_kind": "duration", "cardinality": "0..1", "required": false, "source_refs": [ "SRC-151" ] } ], "artifacts": [ { "id": "dep-proj-art-compatibility-declaration", "name": "Projection Compatibility Declaration", "description": "Consumer-facing declaration for one profile revision: version identifiers on all three axes, compatibility class against the prior revision, the mechanical change set, the supported version list, negotiation error behaviour and the deprecation window for superseded revisions.", "media_or_form": [ "structured compatibility declaration", "interface description document", "release note with machine-readable change set" ], "serial": true, "identity_strategy": "Identified by the profile identifier combined with its version identifier from the adopting Dimension's authoritative profile register; the version identifier is a monotonic version string, never a date-derived key, and supersession is recorded as an explicit link.", "source_refs": [ "SRC-156", "SRC-150", "SRC-121" ] } ], "inline_only_rationale": null } ] } ] } ] }, "functions": [ { "id": "dep-core-fn-record-assertion", "name": "Record dependency assertion", "description": "Create an identified dependency assertion envelope binding a dependent endpoint reference to one or more prerequisite endpoint references under a typed relation term, within a declared scope and effective interval.", "inputs": [ "Issuer reference and authority basis", "Dependent endpoint locator and role binding", "Prerequisite endpoint locators and role bindings", "Relation-type term reference from a governed vocabulary", "Declared-at time and effective interval", "Adopting Dimension, tenant and applicability scope" ], "outputs": [ "Assertion envelope record at its first revision with an identifier assigned under the identity priority order", "Correlation key for later duplicate and disagreement detection" ], "preconditions": [ "Each endpoint reference carries a scheme-qualified locator or an explicit host-scope flag", "The relation-type term resolves in a vocabulary this model does not own", "An identifier is obtainable at one of the three identity tiers" ], "effects": [ "A new assertion identity exists within the adopting Dimension's namespace", "No endpoint is created, allocated, renamed, configured, deployed or invoked", "No graph closure, impact score or authorization decision is produced" ], "source_refs": [ "SRC-001", "SRC-005", "SRC-011", "SRC-013" ] }, { "id": "dep-core-fn-bind-endpoint-reference", "name": "Bind endpoint reference to a role", "description": "Attach a scheme-qualified locator, optional sub-endpoint anchor and endpoint type reference to the dependent or a prerequisite role slot, recording the comparison level that will govern equivalence.", "inputs": [ "Role slot (dependent or prerequisite)", "Endpoint locator, scheme and namespace", "Optional sub-endpoint anchor", "Optional endpoint type reference", "Comparison level to apply" ], "outputs": [ "Role-bound endpoint reference within the envelope", "Recorded locator scope flag and comparison level" ], "preconditions": [ "The role slot is vacant or the binding forms part of a new revision", "The scheme is registered or its assignment rules are documented", "Document-local references are rebound or explicitly marked host-scoped" ], "effects": [ "The reference is recorded without any attempt to dereference it", "Endpoint identity, custody and configuration remain wholly external", "Anchored sub-endpoints are addressed without minting new endpoint identifiers" ], "source_refs": [ "SRC-005", "SRC-006", "SRC-009", "SRC-016" ] }, { "id": "dep-core-fn-pin-endpoint-reference", "name": "Pin endpoint reference", "description": "Fix a role-bound reference to a specific endpoint version, content digest or snapshot, or declare it live, and record the issuer's compatibility range.", "inputs": [ "Role-bound endpoint reference", "Pin mode", "Pinned version, or digest algorithm and value, or snapshot reference", "Declared compatibility range" ], "outputs": [ "Pin descriptor attached to the role binding", "Statement of what may change upstream without invalidating the assertion" ], "preconditions": [ "Digest algorithm is named from a registered hash-algorithm registry", "Live mode carries no pinned value", "Version labels are recorded exactly as published by the endpoint owner" ], "effects": [ "The reference becomes version-fixed or self-verifying by digest", "No content is fetched, copied, cached or verified by this model", "Upstream version creation and withdrawal remain owned by the endpoint owner" ], "source_refs": [ "SRC-001", "SRC-010", "SRC-013", "SRC-016" ] }, { "id": "dep-core-fn-record-reference-state", "name": "Record reference state and staleness", "description": "Record the epistemic, completeness and resolution states of an assertion and its references, together with the verification time and staleness horizon.", "inputs": [ "Resolution outcome reported by an external resolver", "Epistemic state and its reason", "Completeness qualifier for the prerequisite set", "Verification timestamp and staleness horizon" ], "outputs": [ "Recorded epistemic, completeness and resolution states", "Derived stale marker when verification is older than the horizon" ], "preconditions": [ "The resolution outcome originates from a resolver external to this model", "Timestamps are RFC 3339 values with seconds and an explicit offset", "The absence of a report is admissible only as not-assessed" ], "effects": [ "Unknown, not-assessed and unresolved remain distinguishable from asserted-absent", "No resolution, scanning, discovery or disambiguation is performed here", "Stale observations are marked rather than silently refreshed or deleted" ], "source_refs": [ "SRC-005", "SRC-007", "SRC-013", "SRC-014" ] }, { "id": "dep-core-fn-declare-non-dependency", "name": "Declare explicit non-dependency", "description": "Record an attributed statement that a dependent has no prerequisite of a given relation type within a stated scope, so that independence is asserted rather than inferred from silence.", "inputs": [ "Dependent endpoint reference", "Relation type and applicability scope", "Completeness qualifier", "Issuer reference and declared-at time" ], "outputs": [ "Explicit non-dependency statement carrying its own assertion identifier", "Correlation key over dependent, relation type and scope" ], "preconditions": [ "Issuer and authority basis are recorded", "Scope and relation type are stated explicitly", "No prerequisite role binding accompanies the negative marker" ], "effects": [ "An explicit negative claim exists that is distinguishable from an unrecorded dependency", "Nothing is asserted about endpoints or relation types outside the declared scope", "No inference of absence is created for any other dependent" ], "source_refs": [ "SRC-013", "SRC-014", "SRC-016" ] }, { "id": "dep-core-fn-normalize-direction", "name": "Normalize relation direction", "description": "Map an imported relation term stated in a foreign direction onto the canonical dependent-to-prerequisite binding while preserving the original term and its native direction verbatim.", "inputs": [ "Imported relation term and its defining vocabulary", "Published native direction of that term", "Source document or exchange-format reference" ], "outputs": [ "Canonical role binding in the dependent-to-prerequisite direction", "Preserved source term, native direction and reversal flag" ], "preconditions": [ "The native direction is documented by the source vocabulary", "Terms with ambiguous or undocumented direction are rejected rather than guessed", "The mapping rule used is itself referenceable" ], "effects": [ "Direction is normalized exactly once, at import", "No vocabulary term is redefined, extended or republished", "The original statement remains reconstructible from the preserved fields" ], "source_refs": [ "SRC-006", "SRC-011", "SRC-012", "SRC-013" ] }, { "id": "dep-core-fn-supersede-assertion", "name": "Revise, supersede or retract assertion", "description": "Advance an assertion to a new revision, replace it with a successor identity, or retract it, keeping prior revisions readable and leaving both endpoints untouched.", "inputs": [ "Current assertion identity and revision", "Change set", "Supersession or retraction reason", "Issuer reference and declared-at time" ], "outputs": [ "New revision entry, or a successor assertion with supersession pointers in both directions", "Tombstone record on retraction" ], "preconditions": [ "The change is classified as revision-preserving or identity-breaking by the canonicalization rules", "The record is not already in a terminal state", "Competing assertions by other issuers are left untouched" ], "effects": [ "Prior revisions remain retrievable and the content digest chain stays verifiable", "Retraction removes no endpoint and cancels no downstream consumer's own records", "Erasure of tombstones is deferred to the adopting Dimension's retention policy" ], "source_refs": [ "SRC-001", "SRC-002", "SRC-008", "SRC-013" ] }, { "id": "dep-tech-govern-kind-register", "name": "Govern the dependency kind register", "description": "Propose, adjudicate, publish, deprecate or supersede a dependency kind or referent class, together with its full facet set, under an overlap-disjointness test against every existing entry.", "inputs": [ "Proposed kind code or referent class code and definition", "Facet set: canonical direction, source and target endpoint class constraints, cardinality bounds, permitted lifecycle phases, version or compatibility expression rule, false-positive exemplars", "Cited primary source or explicit Dimension-local justification", "Proposed external alignment pointers" ], "outputs": [ "Registered, revised, deprecated or rejected entry with lifecycle status", "Overlap adjudication note naming the nearest existing kinds and the discriminating property", "New register version identifier with effective interval and successor mapping for anything superseded" ], "preconditions": [ "The candidate is semantically disjoint from every registered kind, or the proposal explicitly supersedes the kind it overlaps", "A source citation or a recorded Dimension-local justification is present", "An accountable steward is named" ], "effects": [ "Register version is incremented; facet changes never occur in place", "Superseded entries remain resolvable with a successor mapping for the declared retention interval", "No existing edge assertion is retyped as a side effect; retyping requires a separate remap record" ], "source_refs": [ "SRC-018", "SRC-020", "SRC-021", "SRC-022", "SRC-023" ] }, { "id": "dep-tech-classify-edge", "name": "Classify a candidate relation into exactly one kind", "description": "Assign one registered kind code, one nature code, a phase set and a qualifier set to a candidate relation, or park it as unclassified with a stated reason.", "inputs": [ "Source and target endpoint references with their referent classes", "Candidate relation statement and its declaring or observing context", "Pinned kind-register and referent-class-register versions" ], "outputs": [ "Assigned kind code with nature, phase set and qualifier flags", "Excluded candidate kinds with per-kind exclusion reason", "Unclassified parking record with the ambiguity that blocked assignment" ], "preconditions": [ "Both endpoints resolve to a registered referent class", "The register versions to be applied are pinned before classification begins" ], "effects": [ "Exactly one kind is assigned per edge; a relation needing two kinds becomes two edges", "Ambiguous candidates are parked rather than defaulted to a generic requirement kind", "A candidate matching a recorded false-positive exemplar is rejected with that exemplar cited" ], "source_refs": [ "SRC-020", "SRC-021", "SRC-022", "SRC-023", "SRC-024" ] }, { "id": "dep-tech-record-edge-assertion", "name": "Record or supersede an edge assertion", "description": "Append an assertion about a classified edge, or supersede or withdraw an earlier assertion, preserving identity and both time axes.", "inputs": [ "Classified edge with kind, nature, phase set, qualifiers, constraint expression and grammar", "Determination method and evidence references", "Asserter identity, event time, observation time and validity interval", "Predecessor assertion identifier when superseding or withdrawing" ], "outputs": [ "Edge assertion record with its identifier, assertion sequence and integrity digest", "Supersession or tombstone record carrying the termination reason" ], "preconditions": [ "Classification is complete and the kind-register version is pinned on the assertion", "Both endpoints carry an identifier from the highest tier available to them", "Event time and observation time are supplied in RFC 3339 with seconds and an explicit offset" ], "effects": [ "Records are append-only; corrections and withdrawals never overwrite prior content", "A withdrawn edge retains its identifier so withdrawal is distinguishable from non-existence", "Endpoint re-identification produces a new assertion with an explicit predecessor link" ], "source_refs": [ "SRC-021", "SRC-026", "SRC-029", "SRC-001" ] }, { "id": "dep-tech-validate-edge-conformance", "name": "Validate an edge against its kind facets", "description": "Perform a structural check of an edge assertion against the pinned register entry, covering direction, endpoint classes, cardinality, phase admissibility, qualifier compatibility and well-formedness of the constraint expression within its declared grammar.", "inputs": [ "Edge assertion record", "Kind-register entry at the version pinned on the assertion", "Referent-class register at its pinned version" ], "outputs": [ "Conformance report listing each violated facet with the rule text it violates", "Pass, fail or unverifiable verdict with the reason for unverifiability" ], "preconditions": [ "The pinned register versions are resolvable", "The constraint grammar identifier is present whenever a constraint expression is present" ], "effects": [ "A non-conforming assertion is flagged and withheld from publication; nothing is auto-corrected", "The check is structural only: it does not resolve versions, contact any system, execute policy or produce an enforcement decision", "Unverifiable results are reported as such rather than passed" ], "source_refs": [ "SRC-021", "SRC-022", "SRC-023", "SRC-025" ] }, { "id": "dep-tech-map-external-relation", "name": "Bind a local kind to an external vocabulary term", "description": "Record a crosswalk binding between a local kind, phase or qualifier and a term in an external dependency vocabulary or manifest grammar, with mapping strength, direction normalisation and residue.", "inputs": [ "External relation term with its vocabulary identifier and pinned version or edition", "Local kind, phase or qualifier to bind", "Round-trip test inputs where reversibility is being assessed" ], "outputs": [ "Binding record with mapping strength (exact, broader, narrower, no-match) and direction normalisation applied", "Residue note naming dropped and presumed facets", "Conflict entry where two external vocabularies cannot both be honoured" ], "preconditions": [ "The external vocabulary version or edition is identified, not merely named", "The local kind exists in the pinned register version" ], "effects": [ "Alignment is recorded; conformance is never claimed without published evidence", "Unmapped semantics are recorded as residue or conflict rather than forced into the nearest term", "Inverse-direction external terms are normalised on intake with the original term retained" ], "source_refs": [ "SRC-018", "SRC-020", "SRC-021", "SRC-015", "SRC-022", "SRC-001" ] }, { "id": "dep-tech-declare-propagation-licence", "name": "Declare a propagation licence for a kind", "description": "State, per kind and phase, whether a downstream consumer may traverse the edge for impact purposes, in which direction, with what transitivity limit and under which stop conditions.", "inputs": [ "Kind code and phase", "Proposed traversal direction relative to the canonical edge direction", "Transitivity rule with any depth, phase or referent-class bound", "Stop conditions and the qualifier or boundary that triggers each", "Evidence threshold for discovered and inferred determination methods" ], "outputs": [ "Propagation licence entry bound to the kind-register version it was approved against", "Approval record with approving role and approval event time" ], "preconditions": [ "The kind is registered and active at the pinned register version", "An approving role is named and distinct from the asserter role" ], "effects": [ "Grants or withholds permission only; no traversal, closure computation, ranking, notification or enforcement is performed or implied", "Relations whose nature is co-location or correlation are recorded with a licence of withheld", "Revoking or narrowing a licence issues a new profile version rather than editing in place" ], "source_refs": [ "SRC-021", "SRC-022", "SRC-023", "SRC-030" ] }, { "id": "dep-tech-assert-edge-completeness", "name": "Assert completeness of an edge set", "description": "State, for a named subject and a named kind and phase scope, how complete the recorded outgoing edge set is and what is explicitly not known.", "inputs": [ "Subject reference and the kind and phase scope covered", "Completeness level and the method by which it was established", "Known-unknown statement naming what was not examined and why", "As-of event time and observation time" ], "outputs": [ "Completeness assertion attached to the subject and scope", "Publication gate result indicating whether the edge set may be released" ], "preconditions": [ "The subject identity resolves in its system of record", "The scope is stated in terms of registered kinds and phases, not left implicit" ], "effects": [ "An empty edge set is never published or exported as evidence of independence", "Completeness is recorded per subject and scope and is never inherited by transitive targets", "Publication of an edge set without a current completeness assertion is blocked" ], "source_refs": [ "SRC-021", "SRC-026", "SRC-030" ] }, { "id": "dep-soc-fn-declare-typed-dependency", "name": "Declare a typed socio-operational dependency", "description": "Record one canonical dependency assertion between a dependent endpoint and a depended-on endpoint under a published kind, with applicability qualifiers, at least one evidence entry and an attributed asserter.", "inputs": [ "Dependent endpoint reference", "Depended-on endpoint reference", "Kind identifier and profile version", "Applicability qualifier set", "At least one evidence entry", "Asserter reference and assertion time" ], "outputs": [ "Canonical dependency assertion in draft or declared state", "Validation report listing any profile violations" ], "preconditions": [ "The kind profile is published and its version resolves", "Both endpoint references resolve in their owning master systems", "The direction matches the profile's canonical direction", "No existing assertion shares the same canonical tuple" ], "effects": [ "Creates an assertion and binds it to the profile version used", "Records asserter identity and assertion time distinct from observation time", "Changes nothing in the real-world arrangement, process, contract or staffing that the assertion describes" ], "source_refs": [ "SRC-032", "SRC-001", "SRC-007" ] }, { "id": "dep-soc-fn-classify-dependency-kind", "name": "Propose a dependency kind for a candidate reliance", "description": "Given a candidate reliance statement and its endpoint types, propose the socio-operational kind that fits, or report that no published kind fits.", "inputs": [ "Candidate reliance statement", "Endpoint types on both sides", "Basis description" ], "outputs": [ "Proposed kind identifier with rationale", "Typing confidence indicator", "Unresolved-typing note where no kind fits" ], "preconditions": [ "The kind profile registry is readable", "Endpoint types are stated or derivable from the endpoint references" ], "effects": [ "Produces a proposal only and never publishes an assertion", "Escalates ambiguous or unfitting cases to the kind steward", "Records the typing rationale for later review" ], "source_refs": [ "SRC-031", "SRC-032", "SRC-034", "SRC-035", "SRC-042" ] }, { "id": "dep-soc-fn-validate-endpoints-cardinality", "name": "Validate endpoints, direction and cardinality against the kind profile", "description": "Check an assertion against its declared kind profile for endpoint type conformance, direction, cardinality, cycle permission and transitivity behaviour.", "inputs": [ "Dependency assertion", "Kind profile at the cited version", "Existing assertion set for cardinality and cycle evaluation" ], "outputs": [ "Conformance result", "Ordered list of violations with the constraint breached" ], "preconditions": [ "The cited profile version resolves", "The assertion set in scope is readable" ], "effects": [ "Marks the assertion conformant or non-conformant", "Blocks publication while violations remain", "Performs no remediation and alters no endpoint record" ], "source_refs": [ "SRC-032", "SRC-001", "SRC-031" ] }, { "id": "dep-soc-fn-screen-discrimination-tests", "name": "Screen a candidate assertion for false positives", "description": "Apply the four discrimination tests, ownership versus dependency, sequence versus causation, correlation versus declared dependency and obligation versus reliance, and record their outcomes.", "inputs": [ "Candidate assertion", "Ownership or consolidation reference data", "Ordering evidence such as a modelled flow or event ordering", "Cited obligation reference", "Statistical association evidence where offered" ], "outputs": [ "Outcome per discrimination test with reason", "Status recommendation of declared, candidate or refuted" ], "preconditions": [ "At least one evidence entry exists", "The reference data needed for each applicable test is reachable or the test is marked not performed" ], "effects": [ "Records test outcomes on the assertion", "Downgrades to candidate any assertion supported only by association", "Computes no risk score, criticality rating or impact severity" ], "source_refs": [ "SRC-001", "SRC-041", "SRC-034", "SRC-033" ] }, { "id": "dep-soc-fn-bind-applicability", "name": "Bind temporal, spatial and jurisdictional applicability", "description": "Attach the applicability qualifiers under which an assertion holds: interval relation and lead time, location or site binding, and jurisdiction with its citing instrument.", "inputs": [ "Dependency assertion", "Temporal interval or required lead time", "Location or site code with code list version", "Jurisdiction code, reference frame and citing instrument identifier" ], "outputs": [ "Applicability qualifier set bound to the assertion", "Report of qualifiers that could not be resolved to a governed code" ], "preconditions": [ "Code lists and instrument identifiers resolve at a stated version", "Interval bounds are expressed with seconds and an explicit offset or Z" ], "effects": [ "Narrows the validity of the assertion to the bound qualifiers", "Marks the assertion expired when a bound window closes", "Does not alter the underlying arrangement, authorisation, site or schedule" ], "source_refs": [ "SRC-033", "SRC-037", "SRC-007", "SRC-043" ] }, { "id": "dep-soc-fn-compile-register-extract", "name": "Compile a third-party dependency register extract", "description": "Produce a read-only extract of conformant supplier and third-party assertions for one reporting scope, mapped to a target register schema.", "inputs": [ "Reporting scope key", "As-at instant with explicit offset", "Target register schema and field mapping" ], "outputs": [ "Register extract artifact with sequence number and content digest", "Unmapped or unavailable field report" ], "preconditions": [ "All in-scope assertions are conformant to their kind profiles", "Party identifiers required by the target schema are present or explicitly reported as absent" ], "effects": [ "Produces an immutable extract bound to the profile version used", "Does not submit the extract, notify any authority, or interpret the supervisory obligation the extract serves", "Leaves the underlying assertions unchanged" ], "source_refs": [ "SRC-035", "SRC-042", "SRC-040", "SRC-041" ] }, { "id": "dep-soc-fn-disposition-assertion", "name": "Disposition a withdrawn, refuted, expired or superseded assertion", "description": "Close out an assertion with an explicit disposition and reason while retaining a tombstone that records the kind and both endpoints.", "inputs": [ "Assertion reference", "Disposition code", "Reason text", "Effective instant", "Superseding assertion reference where applicable" ], "outputs": [ "Dispositioned assertion with retained tombstone", "Supersession link where a replacement exists" ], "preconditions": [ "The acting party holds the reviewer role for the scope", "A reason is supplied and the disposition code is valid for the current state" ], "effects": [ "Retains the record and marks it withdrawn, refuted, expired or superseded", "Never performs a hard delete, so consumers can distinguish never asserted from no longer asserted", "Leaves retention periods and any physical erasure to the adopting Dimension's records and privacy models" ], "source_refs": [ "SRC-035", "SRC-042", "SRC-007", "SRC-040" ] }, { "id": "dep-cond-fn-declare", "name": "Declare a typed dependency condition", "description": "Record a new dependency condition on a host subject in canonical dependent-to-prerequisite direction, with its typed kind, lifecycle scope, obligation level and target specification.", "inputs": [ "Dependent endpoint reference from the host model", "Prerequisite reference or abstract target selector", "Typed kind, provisioning mode and lifecycle scope codes", "Obligation level and optionality encoding", "Optional guard, predicate, alternative set and polarity" ], "outputs": [ "Dependency condition record with its own identifier", "Canonical direction marker", "Echo of the crosswalk profile versions applied" ], "preconditions": [ "Both endpoints are addressable in the host model or the target is an explicitly marked selector", "The typed kind and obligation level exist in the referenced crosswalk and scale profiles", "The declaration carries at least one lifecycle scope or an explicit statement that scope is unrestricted" ], "effects": [ "A new condition declaration exists and is addressable independently of both endpoints", "No graph edge, resolution result or satisfaction status is created or implied", "Guarded and scoped declarations remain conditional and are not materialised as unconditional edges" ], "source_refs": [ "SRC-018", "SRC-019", "SRC-046", "SRC-022" ] }, { "id": "dep-cond-fn-normalize-direction", "name": "Normalize a native or reverse-declared condition", "description": "Convert a condition authored in an external vocabulary, including prerequisite-side and inverse-named forms, into the canonical direction and neutral typed kind, recording the transformation.", "inputs": [ "Native condition expression with its source vocabulary and version", "Crosswalk profile reference" ], "outputs": [ "Canonical condition record", "Normalization provenance entry", "Unmapped residue list for terms with no neutral equivalent" ], "preconditions": [ "The source vocabulary is covered by a published crosswalk profile version", "Native terms that are prerequisite-side declarations are identified in that profile" ], "effects": [ "The condition is readable in canonical direction without loss of the native term", "Unmapped terms are surfaced rather than silently dropped or approximated", "No claim of conformance to the source standard is asserted" ], "source_refs": [ "SRC-018", "SRC-023", "SRC-047" ] }, { "id": "dep-cond-fn-bind-guard", "name": "Attach or amend a guard on a condition", "description": "Add, replace or withdraw the applicability predicate of an existing condition and set the outcome that applies when the guard is false.", "inputs": [ "Condition identifier", "Guard expression in neutral form and its native source", "Unmet-guard outcome code and evaluation scope" ], "outputs": [ "Updated condition with guard and outcome recorded", "Prohibition flag preventing unconditional projection", "Change provenance entry" ], "preconditions": [ "The condition exists and is not in a withdrawn state", "Guard variables are declared or resolvable as named environment dimensions", "The requested operator combination is admissible in the model's neutral grammar" ], "effects": [ "Applicability of the condition is explicitly bounded rather than assumed universal", "Withdrawal of a guard is recorded as a widening change requiring a new revision", "Guard evaluation is neither performed nor scheduled by this function" ], "source_refs": [ "SRC-023", "SRC-047", "SRC-048", "SRC-051" ] }, { "id": "dep-cond-fn-record-observation", "name": "Record an external satisfaction observation", "description": "Attach a status snapshot and a reference to an externally produced evaluation or validation result to a declared condition, with separate event and observation times.", "inputs": [ "Condition identifier", "Status code and optional severity qualifier", "Producer identity, version and result reference", "Event time and observation time in RFC 3339 with seconds and explicit offset or Z" ], "outputs": [ "Status snapshot attached to the condition", "Provenance record naming the external producer", "Staleness or validity note for the snapshot" ], "preconditions": [ "The condition exists and is in scope for the reported evaluation context", "The result is retained by the producing system and is referenceable", "Unknown and not-applicable are available in the status vocabulary and are not collapsed into satisfied" ], "effects": [ "The last known state is readable without re-evaluation", "Evaluation logic, re-evaluation triggers, report structure and report retention remain owned by the producing system", "No enforcement, gating or remediation is initiated" ], "source_refs": [ "SRC-048", "SRC-049" ] }, { "id": "dep-cond-fn-record-deviation", "name": "Record a deviation against a condition", "description": "Bind an externally decided waiver, concession, temporary exception or declared deactivation to a condition, with its subject scope and validity window.", "inputs": [ "Condition identifier", "Deviation type and reference to the external decision record", "Subject binding and declared validity window", "Optional stated conditions of the deviation" ], "outputs": [ "Deviation binding attached to the condition", "Reference to the owning authority model", "Expiry marker for the validity window" ], "preconditions": [ "An external decision record exists and is referenceable", "The deviation scope is expressible in terms of this condition's endpoints, kind and lifecycle scope" ], "effects": [ "The declared condition remains defined and visible while its deviation is disclosed", "Approval workflow, authority verification, evidence retention and revocation remain owned by the authority model", "No obligation level is silently downgraded as a side effect of the deviation" ], "source_refs": [ "SRC-049", "SRC-052" ] }, { "id": "dep-cond-fn-assert-completeness", "name": "Issue a completeness assertion over a declaration scope", "description": "Publish an attributed statement that the declared conditions for a subject and scope are exhaustive, non-exhaustive or carry no assertion, and supersede any earlier overlapping assertion.", "inputs": [ "Subject reference and assertion scope", "Completeness value", "Issuing actor, method and basis", "Reference to any assertion being superseded" ], "outputs": [ "Completeness assertion record", "Supersession link where applicable", "Explicit empty declaration where the scope contains no conditions" ], "preconditions": [ "The scope is expressed in terms of subject, condition kind, lifecycle phase and polarity", "The issuing actor is identified and is accountable for the claim" ], "effects": [ "Absence within the asserted scope acquires a defined reading instead of the open-world default", "Earlier overlapping assertions are marked superseded rather than deleted", "No inference of completeness is made from silence anywhere else" ], "source_refs": [ "SRC-014", "SRC-046", "SRC-050" ] }, { "id": "dep-cond-fn-project-vocabulary", "name": "Project a condition into a target vocabulary with a lossiness report", "description": "Emit the condition in an external vocabulary and report every distinction that the target cannot express, refusing projections that would misrepresent conditionality or strength.", "inputs": [ "Condition identifier", "Target vocabulary and version", "Crosswalk and scale profile references" ], "outputs": [ "Projected condition in the target vocabulary", "Lossiness report listing weakened, strengthened, dropped or refused elements", "Refusal record where a guarded condition cannot be represented conditionally" ], "preconditions": [ "A crosswalk profile version covering the target vocabulary is published", "The unconditional projection prohibition flag has been read for every guarded condition" ], "effects": [ "Conditional dependencies are never silently emitted as unconditional edges", "Strength loss is disclosed rather than absorbed", "Conformance to the target standard is not claimed by the act of projection" ], "source_refs": [ "SRC-018", "SRC-015", "SRC-046", "SRC-023" ] }, { "id": "dep-evd-fn-record-claim-origin", "name": "Record claim origin and epistemic mode", "description": "Attach an epistemic mode, primary-source indicator and derivation references to a dependency or impact claim asserted in the core partition.", "inputs": [ "Reference to the edge claim being qualified", "Epistemic mode code and vocabulary version pin", "Optional derived-from claim references and mode rationale" ], "outputs": [ "Claim provenance record with mode, vocabulary pin and derivation links", "Rejection with reason when the mode code is not in the pinned vocabulary" ], "preconditions": [ "The referenced edge claim resolves in the core partition", "The mode vocabulary version is registered and not withdrawn" ], "effects": [ "Creates an immutable mode assignment on the claim", "Makes the claim eligible for strength and completeness qualification", "Does not alter the edge, its type or its impact propagation" ], "source_refs": [ "SRC-001", "SRC-021", "SRC-020" ] }, { "id": "dep-evd-fn-register-method-profile", "name": "Register or version a method profile", "description": "Create or supersede a method profile descriptor covering technique class, tool identity, configuration and rule-set version pins, applicable subject classes and declared limitations.", "inputs": [ "Technique class code and tool identity set", "Configuration and rule-set version pins with configuration digest", "Declared limitations, applicable subject classes and emitted confidence scale reference" ], "outputs": [ "Registered method profile descriptor version", "Change classification indicating whether existing claims must be re-derived" ], "preconditions": [ "The technique class exists in the pinned technique vocabulary", "The referenced confidence scale is registered" ], "effects": [ "Adds a citable, versioned procedure description that claims can reference", "Retains superseded profile versions so historic claims stay interpretable", "Does not execute, configure or schedule any detector" ], "source_refs": [ "SRC-054", "SRC-055", "SRC-021" ] }, { "id": "dep-evd-fn-bind-evidence-reference", "name": "Bind an evidence reference to a claim", "description": "Attach one or more locator, digest, media-type and fragment-selector rows to a claim, or record an explicit no-evidence rationale, without importing any payload.", "inputs": [ "Claim reference", "Evidence locator, optional content digest and media type", "Fragment selector or explicit no-evidence rationale" ], "outputs": [ "Evidence reference rows attached to the claim", "Evidence reference manifest entry for the claim set", "Validation error when neither an evidence reference nor a no-evidence rationale is supplied" ], "preconditions": [ "The locator syntax is resolvable within the adopting Dimension", "The selector syntax matches the declared media type" ], "effects": [ "Creates a retrievable path back to external evidence", "Enforces the payload-exclusion rule at write time", "Does not fetch, cache, mirror, version or delete the referenced evidence" ], "source_refs": [ "SRC-057", "SRC-021", "SRC-058" ] }, { "id": "dep-evd-fn-record-observation", "name": "Record an observation event and its times", "description": "Record the observation act, its subject and environment, its coverage basis, and the distinct relation, result, ingestion and validity times together with the freshness mechanism used.", "inputs": [ "Subject edge and endpoint references, environment instance reference", "Observation run reference, coverage and sampling basis", "Relation start/end time, observation result time, declared validity boundary, freshness mechanism and challenge reference" ], "outputs": [ "Observation event record with all times stored in separate fields", "Freshness descriptor exposing recorded times and the validity boundary for external policy evaluation" ], "preconditions": [ "All supplied times are RFC 3339 values with seconds and an explicit offset or Z", "Observation result time is not later than ingestion time unless an explicit clock-skew note is supplied" ], "effects": [ "Stamps ingestion time from the recording system's clock", "Keeps relation time, observation time and ingestion time permanently distinguishable", "Emits freshness inputs only and makes no acceptability or staleness decision" ], "source_refs": [ "SRC-054", "SRC-056", "SRC-013" ] }, { "id": "dep-evd-fn-record-strength", "name": "Record confidence, conditions and applicability", "description": "Record a producer-asserted confidence value against a named scale, the measurement condition class, any uncertainty statement, and the applicability envelope that bounds generalisation of the claim.", "inputs": [ "Claim reference and confidence value", "Confidence scale reference and version, condition class code, uncertainty statement", "Applicability envelope and exclusions" ], "outputs": [ "Strength record attached to the claim", "Rejection when a confidence value is supplied without a registered scale reference" ], "preconditions": [ "The confidence scale is registered with a defined range and interpretation", "The applicability envelope uses registered platform and profile vocabularies" ], "effects": [ "Preserves producer-asserted strength verbatim with its scale", "Blocks cross-scale arithmetic unless a recorded comparability rule permits it", "Computes no derived score, threshold or ranking" ], "source_refs": [ "SRC-055", "SRC-021", "SRC-059" ] }, { "id": "dep-evd-fn-declare-completeness", "name": "Declare completeness or a known unknown", "description": "Record whether an enumerated dependency set for a stated scope is complete, incomplete or not asserted, distinguishing an affirmative no-further-dependencies statement from unknown enumeration and naming the reason.", "inputs": [ "Scope reference, declared depth and included dependency classes", "Completeness code and, where applicable, unknown reason code", "Affirmative no-further-dependencies assertion where it applies" ], "outputs": [ "Completeness declaration attached to the scope", "Consumer-facing warning where a scope has no declaration" ], "preconditions": [ "The scope reference resolves to a node, subgraph or release", "The declaring agent has an authority basis for the scope" ], "effects": [ "Makes unknown enumeration explicit rather than inferable", "Applies the default rule that an absent declaration is read as incomplete", "Does not enumerate, complete or infer missing dependencies" ], "source_refs": [ "SRC-013", "SRC-014", "SRC-060" ] }, { "id": "dep-evd-fn-register-contradiction", "name": "Register a contradiction between claims", "description": "Record that two claims about the same edge disagree after passing the overlap test on subject, applicability envelope and validity interval, and route the pair to an external adjudicator.", "inputs": [ "References to both claims and the contradiction kind", "Overlap test result covering subject, envelope and time interval", "Referral target reference" ], "outputs": [ "Contradiction pair record with kind and referral state", "Not-contradictory determination with the disjoint dimension named" ], "preconditions": [ "Both claims resolve and qualify the same edge", "Both claims carry applicability envelopes and times sufficient to run the overlap test" ], "effects": [ "Marks both claims as contradicted without changing their content", "Records a referral reference and referral state only", "Selects no winner, assigns no trust ranking and issues no verdict" ], "source_refs": [ "SRC-055", "SRC-056", "SRC-058" ] }, { "id": "dep-evd-fn-supersede-or-retract", "name": "Supersede or retract a claim", "description": "Transition a claim to superseded or retracted with an effective time, a mandatory reason and an issuing agent, and emit a revision notice to downstream consumers.", "inputs": [ "Target claim references and new state code", "Effective time, reason code and justification text", "Issuing agent reference and authority basis" ], "outputs": [ "Updated claim state with invalidation time and preserved original record", "Claim revision and retraction notice for downstream consumers" ], "preconditions": [ "The issuing agent is the original asserting agent, a delegated steward, or an agent named in the governing mandate", "A reason code is supplied; supersession additionally requires a recorded ordering basis" ], "effects": [ "Preserves the superseded or retracted record as inspectable history", "Never performs a hard delete of the claim or its evidence references", "Does not delete, alter or expire the external evidence the claim referenced" ], "source_refs": [ "SRC-001", "SRC-058" ] }, { "id": "dep-life-fn-propose-assertion", "name": "Propose dependency assertion", "description": "Record a new dependency assertion in the proposed state against a host record, establishing its weak identity key and its initial effective interval without claiming that the dependency has yet been reviewed or accepted.", "inputs": [ "Host record reference", "Dependent and provider endpoint references and dependency type from the typing area", "Proposed effective-from instant and optional lifecycle scope", "Proposing actor reference" ], "outputs": [ "Assertion record version 1 in the proposed state", "Composed assertion identity key", "Transition event recording the proposal" ], "preconditions": [ "The host record exists and admits the dependency mixin", "The endpoint references resolve in their owning master systems", "No active assertion already exists with the same identity key and an overlapping effective interval" ], "effects": [ "A new assertion identity is created with record version 1", "The proposal is readable and remains readable even if later rejected", "No endpoint state is read, changed or polled" ], "source_refs": [ "SRC-066", "SRC-068", "SRC-013" ] }, { "id": "dep-life-fn-apply-transition", "name": "Apply lifecycle transition", "description": "Move an assertion from one registration state to another where the transition table permits it, recording the transition event, the requesting and approving actors, and the externally returned guard evaluation outcome.", "inputs": [ "Assertion identity key", "Target registration state", "Guard evaluation outcome returned by the external rule or workflow service", "Requesting actor reference and, where required, approving actor reference", "Transition event time" ], "outputs": [ "New record version carrying the target state", "Transition event record", "Rejection outcome where the transition is refused" ], "preconditions": [ "The from-state and to-state pair appears as permitted in the governing transition table", "The declared guards for the transition have been evaluated externally and the outcome supplied", "The acting role is authorised for that transition" ], "effects": [ "The prior record version's record interval is closed and a new version opened", "No prior record version is edited or removed", "Transition guards are not evaluated here; only their supplied outcome is stored" ], "source_refs": [ "SRC-066", "SRC-068", "SRC-070" ] }, { "id": "dep-life-fn-record-condition", "name": "Record condition determination", "description": "Attach a condition value to an active assertion for a stated effective interval, citing the criteria applied, the evidence observations used with their phenomenon and result times, and the determining actor or procedure.", "inputs": [ "Assertion identity key", "Condition value from the governed vocabulary", "Criterion references and evidence observation references", "Condition effective-from instant and determination time", "Determining actor or procedure reference" ], "outputs": [ "Condition determination record with its own effective interval", "Prior condition value carried forward for degradation and restoration recognition", "Undetermined determination with a reason where evidence is insufficient or stale" ], "preconditions": [ "The assertion is in a state whose decision-usability class permits condition tracking", "Referenced evidence resolves and satisfies the declared maximum age and quality bar", "The condition value exists in the bound vocabulary version" ], "effects": [ "A condition determination is appended without altering earlier determinations", "Degradation, breakage and restoration become derivable from consecutive determinations", "No endpoint is probed, monitored or remediated by this function" ], "source_refs": [ "SRC-062", "SRC-064", "SRC-065" ] }, { "id": "dep-life-fn-close-effective-interval", "name": "Close effective interval", "description": "Set the exclusive right bound of an open effective interval on an assertion or condition determination, recording why it ceased, by appending a new record version rather than editing the open one.", "inputs": [ "Assertion identity key or condition determination reference", "Closing instant", "Interval closure reason code", "Acting party reference" ], "outputs": [ "New record version with a bounded effective interval", "Reference from the closing version to the version it closes" ], "preconditions": [ "The target interval is currently open", "The closing instant is not earlier than the effective-from instant", "Closing does not create an overlap with another interval on the same assertion and time dimension" ], "effects": [ "The effective dimension is bounded while the record dimension records when this became known", "The previously open version remains readable and citable", "Closure alone does not retire the assertion; retirement is a separate transition" ], "source_refs": [ "SRC-070", "SRC-033", "SRC-013" ] }, { "id": "dep-life-fn-supersede-assertion", "name": "Supersede assertion", "description": "Link a predecessor assertion to a successor now preferred for use, marking the predecessor superseded, stating whether the replacement is total or partial, and preserving both for reconstruction.", "inputs": [ "Predecessor assertion identity key", "Successor assertion identity key", "Supersession scope code", "Deciding authority reference and supersession event time" ], "outputs": [ "Replaced-by reference on the predecessor and replaces reference on the successor", "New record versions of both assertions", "Updated registration state of the predecessor" ], "preconditions": [ "The successor exists and is not itself superseded", "The resulting chain contains no cycle and respects any declared depth limit", "The deciding role is authorised to declare supersession" ], "effects": [ "Chain traversal in both directions becomes possible", "The predecessor stays readable and its historical intervals stay intact", "A retired predecessor's identity key is not released for reuse by this function" ], "source_refs": [ "SRC-067", "SRC-066", "SRC-068" ] }, { "id": "dep-life-fn-reconstruct-as-of", "name": "Reconstruct assertion set as of a chosen moment", "description": "Return the dependency assertions and condition determinations that were effective at a chosen effective time according to what was believed at a chosen record time, so that a past decision can be replayed exactly.", "inputs": [ "Host record reference or assertion identity key", "Effective-time parameter", "Record-time parameter, defaulting to the present", "Optional lifecycle scope filter" ], "outputs": [ "Assertion and condition record versions matching both time parameters", "Enumeration of the record versions consulted", "Explicit empty result where nothing was believed effective at that pair of times" ], "preconditions": [ "Both supplied instants carry seconds and an explicit offset or Z", "Record versions exist covering the requested record time", "Annulled versions are excluded from reasoning results unless explicitly requested" ], "effects": [ "No record is created or altered by reconstruction", "Later-arriving evidence does not change an earlier reconstruction at the same record time", "Cited versions remain immutable so the same query returns the same answer" ], "source_refs": [ "SRC-070", "SRC-061", "SRC-069" ] }, { "id": "dep-life-fn-issue-correction", "name": "Issue correction or annulment", "description": "Append a corrected record version for an assertion or condition determination, or annul a version as never having been true, always by adding to the series and never by editing or removing what was previously published.", "inputs": [ "Target record version address", "Change class of correction or annulment", "Correction reason code and supporting evidence references", "Authorised correcting actor reference and, for annulment, approver reference" ], "outputs": [ "New record version carrying the corrected content or the annulment marker", "Correction-of reference to the superseded record version", "Unchanged effective interval on the corrected version where only belief changed" ], "preconditions": [ "The target version exists and is addressable by assertion key and version number", "The acting role is authorised for correction, and for annulment a second approver is present where required", "A justification is supplied for every annulment" ], "effects": [ "The record dimension of the erroneous version is closed while its content stays byte-stable", "Annulled versions remain readable for reconstruction but are excluded from reasoning", "History is never rewritten, so an earlier citation continues to resolve to the same state" ], "source_refs": [ "SRC-065", "SRC-001", "SRC-070", "SRC-061" ] }, { "id": "dep-graph-assert-edge", "name": "Assert dependency edge", "description": "Record a new asserted dependency edge as an immutable primary fact with typed direction, lifecycle scope, validity window, provenance and confidence.", "inputs": [ "Source and target endpoint references resolvable in the owning inventory model", "Relation type code from a governed vocabulary", "Lifecycle scope codes, validity window, asserting agent, evidence references and confidence" ], "outputs": [ "Edge assertion record with an assigned identifier under the identity priority rule", "Rejection with reason where an endpoint reference does not resolve" ], "preconditions": [ "Endpoint references resolve, or the caller explicitly quarantines the edge as unresolved", "Relation type code exists in a bound vocabulary version", "Validity and assertion timestamps supplied as RFC 3339 values with an explicit offset or Z" ], "effects": [ "Creates one immutable edge assertion record in this model's fact base", "Invalidates by digest mismatch any projection whose input snapshot included the affected scope", "Does not create, modify or classify the endpoint entities, which remain owned by the inventory model" ], "source_refs": [ "SRC-013", "SRC-019", "SRC-075" ] }, { "id": "dep-graph-classify-modality", "name": "Classify relation modality", "description": "Assign exactly one modality (direct, transitive, inferred, hypothetical) to a dependency statement and attach the derivation basis for non-direct modalities.", "inputs": [ "Dependency statement reference", "Proposed modality and, where applicable, the property characteristic, property chain, rule or closure method reference with premise edge keys" ], "outputs": [ "Modality assignment with derivation basis and materialisation flag", "Validation error when a non-direct modality is proposed without a resolvable basis" ], "preconditions": [ "Any declared transitive property or property chain is resolvable and its global-restriction status is recorded", "Premise edges cited by a transitive statement are resolvable and within their validity window" ], "effects": [ "Sets the modality discriminator carried on the statement", "Blocks promotion of a derived statement to direct modality without a new agent assertion", "Does not perform entailment or invoke a reasoner; entailment computation remains with the external reasoner" ], "source_refs": [ "SRC-071", "SRC-072", "SRC-073" ] }, { "id": "dep-graph-declare-propagation-licence", "name": "Declare propagation licence profile", "description": "Publish or revise a versioned profile stating which relation types, lifecycle scopes, directions, temporal overlaps and confidence thresholds permit impact to traverse an edge for a named class of impact question.", "inputs": [ "Impact question class the profile serves", "Relation type codes, permitted directions, lifecycle scopes, temporal overlap predicate and confidence threshold", "Precedence rank and approving role" ], "outputs": [ "Versioned propagation licence profile artifact", "Change classification indicating whether the revision is breaking for existing projections" ], "preconditions": [ "Approving role holds authority over the profile's owner package", "Deny-by-default is stated explicitly and no implicit fallback is introduced" ], "effects": [ "Creates a new profile version; prior versions remain resolvable so historical projections stay interpretable", "Marks projections computed under a superseded profile version as requiring re-derivation", "Does not enforce traversal at query time; enforcement is performed by the consuming evaluator" ], "source_refs": [ "SRC-013", "SRC-019", "SRC-077" ] }, { "id": "dep-graph-record-propagation-exclusion", "name": "Record propagation exclusion", "description": "Record a typed, scoped and expiring statement that a present edge or edge class does not propagate impact for a stated and evidenced reason.", "inputs": [ "Target edge, relation-type class or subgraph, and the impact question class affected", "Justification code from the governed exclusion vocabulary", "Evidence references, reviewing role, effective-from and expiry timestamps" ], "outputs": [ "Exclusion statement artifact linked to the affected edges by reference", "Rejection where no justification code is supplied" ], "preconditions": [ "A justification code is present; free text alone is invalid", "Effective and expiry times are RFC 3339 values with an explicit offset or Z" ], "effects": [ "Creates an exclusion statement without mutating the underlying edge assertion", "Requires downstream results to report the edge as suppressed rather than absent", "Does not adjudicate the underlying vulnerability or exception; that remains with the referenced exception model" ], "source_refs": [ "SRC-014", "SRC-076" ] }, { "id": "dep-graph-declare-completeness", "name": "Declare completeness and enumeration frontier", "description": "Publish a scoped, time-bounded declaration of how exhaustively an edge set was enumerated, including declared known unknowns and the closed-world flag.", "inputs": [ "Node or subgraph scope, relation types enumerated and traversal depth reached", "Completeness value (complete, incomplete, noAssertion) and its basis", "Known-unknown records, validity interval and declaring role" ], "outputs": [ "Completeness declaration artifact citable by identifier from any projection", "Default noAssertion result where the declarant cannot substantiate exhaustiveness" ], "preconditions": [ "The declaring role is authorised to set the closed-world flag for the named scope", "Each known unknown names the affected node or edge class and the reason it is unresolved" ], "effects": [ "Creates a declaration version and supersedes any prior version by explicit pointer", "Licenses negative conclusions only within the declared frontier and validity interval", "Does not itself close the world for any scope it does not name" ], "source_refs": [ "SRC-014", "SRC-073", "SRC-075", "SRC-030" ] }, { "id": "dep-graph-register-analysis-projection", "name": "Register analysis projection", "description": "Record a derived graph result produced by an external evaluator as a projection, binding it to method identity and version, parameters, edge filter, input snapshot digest, run time and determinism class.", "inputs": [ "Registered method identifier and version, plus the full parameter set", "Edge selection filter including licence profile version, admitted modalities, applied exclusions and temporal reference", "Input snapshot digest, cited completeness declarations, run execution time and the result payload" ], "outputs": [ "Analysis run descriptor plus the associated result set artifact", "Rejection where the method identifier is unregistered or the snapshot digest does not resolve" ], "preconditions": [ "The input snapshot digest resolves to a canonicalised, retained edge set", "Cited completeness declarations are current for the analysed scope", "Result semantics are declared: path restrictor, bounds, selection mode or component identity strategy as applicable" ], "effects": [ "Creates an immutable projection record separate from the asserted edge set", "Never merges derived statements into the fact base", "Does not execute the algorithm and asserts no ownership of the evaluator's execution logs or audit records" ], "source_refs": [ "SRC-074", "SRC-077", "SRC-079" ] }, { "id": "dep-graph-validate-absence-claim", "name": "Validate absence or non-reachability claim", "description": "Check that a proposed negative claim - not reachable, not impacted, no dependency - cites a resolvable, current completeness declaration whose frontier covers the queried scope, and return a verdict.", "inputs": [ "Proposed negative claim with its queried scope and seed set", "Referenced projection and its run descriptor", "Referenced completeness declaration identifier" ], "outputs": [ "Verdict of licensed, downgraded or rejected, with the failing condition named", "Rewritten claim strength, for example 'not known to be reachable', where the declaration is absent, partial or stale" ], "preconditions": [ "The projection's snapshot digest still resolves and the projection is not superseded", "The completeness declaration is within its validity interval and its closed-world flag covers the queried scope" ], "effects": [ "Produces a validation verdict over this model's own records", "Prevents publication of an unsupported negative conclusion by downgrading its stated strength", "Does not enforce access, block delivery or write an audit record; enforcement and audit remain with the consuming service and the Dimension's audit model" ], "source_refs": [ "SRC-014", "SRC-073", "SRC-075" ] }, { "id": "dep-graph-supersede-stale-projection", "name": "Supersede stale projection", "description": "Mark a stored projection as stale and record its supersession when its input snapshot, licence profile version or completeness declaration has changed.", "inputs": [ "Projection or run descriptor reference", "Staleness trigger: snapshot digest mismatch, licence profile revision or completeness re-declaration", "Replacement run descriptor reference where one exists" ], "outputs": [ "Updated run descriptor carrying a staleness marker and supersession pointers", "List of downstream results that inherited the staleness" ], "preconditions": [ "The triggering change is itself recorded and resolvable", "The projection has not already been tombstoned" ], "effects": [ "Marks the projection stale and forbids its use as support for a negative or absence conclusion", "Propagates the staleness marker to derived results that consumed it", "Does not delete the projection or trigger re-computation; re-derivation is requested from the external evaluator" ], "source_refs": [ "SRC-071", "SRC-079" ] }, { "id": "dep-impact-fn-frame-scenario", "name": "Frame and version an impact scenario", "description": "Create a citable scenario version from a referenced trigger, seed entities, a cited dependency-graph snapshot, a baseline statement, a propagation profile and a declared analysis frame. The function fixes inputs; it produces no result and touches no referenced record.", "inputs": [ "Trigger record reference and trigger kind", "Seed entity references and alteration descriptors", "Dependency-graph snapshot reference with snapshot time", "Baseline statement reference and baseline kind", "Propagation profile reference and version", "Analysis mode, analysis time, effect horizon and horizon bands", "Declared assumptions and bound code-list versions" ], "outputs": [ "Versioned impact scenario specification", "Scenario identifier and version", "Resolved and recorded input citation block" ], "preconditions": [ "The trigger reference resolves in its owning system, or is recorded with an explicit unresolvable marker", "The cited graph snapshot is immutable and carries a snapshot time with an explicit offset", "A baseline kind is declared, including the explicit value none-declared", "A propagation profile version is cited before any traversal may be requested" ], "effects": [ "Creates a new scenario version and never mutates a released one", "Records analysis time separately from trigger time and from any observation time", "Leaves the referenced trigger record, its approval state and its schedule entirely unchanged", "Confers no authorisation to make, defer or reject the analysed change" ], "source_refs": [ "SRC-080", "SRC-012", "SRC-084", "SRC-083" ] }, { "id": "dep-impact-fn-derive-affected-set", "name": "Derive the candidate affected set by traversal", "description": "Traverse the cited dependency-graph snapshot from the seed entities under the cited propagation profile to produce a candidate affected set, the path to each member, the excluded edges with reasons and a traversal completeness code. The output asserts reachability only.", "inputs": [ "Scenario version reference", "Propagation profile version", "Dependency-graph snapshot reference" ], "outputs": [ "Candidate affected set with an exposure flag per member", "Ordered impact path per member, with all alternative paths retained", "Excluded edge and node list with reason codes", "Traversal completeness code and description of unreachable regions" ], "preconditions": [ "The propagation profile declares traversal direction, depth or stop conditions, non-propagating edge types and a cycle-handling rule", "Every conditional propagation predicate is recorded as holding, failing or unevaluated", "The snapshot content hash is recorded so the run can be reproduced" ], "effects": [ "Produces a derived record bound to exactly one scenario version and one snapshot", "Sets exposure flags only; assessed effect and status remain unset until an assessor acts", "Asserts no harm, no severity and no causation", "Creates, retypes and retracts no dependency edge in the source graph" ], "source_refs": [ "SRC-012", "SRC-082", "SRC-001", "SRC-080" ] }, { "id": "dep-impact-fn-assign-affected-status", "name": "Assign explicit status to each affected-set member", "description": "Turn a candidate set into an affected-set register by assigning each member an explicit status with justification and determination time, including negative, unknown, conditional and non-propagating outcomes.", "inputs": [ "Candidate affected set with paths", "Assessor determination per member", "Justification codes or narrative impact statements", "Determination time" ], "outputs": [ "Affected-set register with an explicit status per member", "Justification or impact statement per negative or non-propagating determination", "Report of members carried forward as under investigation" ], "preconditions": [ "Every member resolves to a registry identifier, or carries an unresolvable-reference marker", "A justification code or a narrative impact statement is present for every not-affected and reached-not-propagating determination", "The assessor agent and role are recorded" ], "effects": [ "Records negative and unknown results explicitly and never expresses not-affected by removing a member", "Retains prior determinations alongside the current one with their determination times", "Does not promote an exposure flag to an affected status without an assessor determination" ], "source_refs": [ "SRC-082", "SRC-012", "SRC-081", "SRC-086" ] }, { "id": "dep-impact-fn-characterize-effect", "name": "Characterise an asserted effect on a member", "description": "Attach effect kind, polarity, magnitude on a referenced scale, first-order or downstream ordering and declared accumulation links to an entry of the affected-set register.", "inputs": [ "Affected-set member entry", "Effect kind and affected property", "Polarity", "Magnitude value with referenced scale and unit", "Effect order and antecedent effect reference", "Declared accumulation links" ], "outputs": [ "Effect characterisation attached to the register entry", "Ordering chain from first-order to downstream effects" ], "preconditions": [ "The magnitude scale and unit are cited from a measurement model rather than defined locally", "Neutral and beneficial polarity values are permitted by the bound vocabulary", "A downstream effect cites the antecedent effect it arises from" ], "effects": [ "Distinguishes first-order from downstream effects explicitly rather than by path length alone", "Records accumulation as a declared relationship and performs no aggregation arithmetic", "Defines no severity scale and converts no units" ], "source_refs": [ "SRC-080", "SRC-081", "SRC-086", "SRC-083" ] }, { "id": "dep-impact-fn-qualify-uncertainty", "name": "Qualify outcomes and issue the limitation disclosure", "description": "Assign a claim status to every asserted outcome, attach likelihood and confidence qualifiers on a bound scale, and produce the signed limitation and uncertainty disclosure without which the result may not be released.", "inputs": [ "Affected-set register version and trace record version", "Claim status per outcome", "Likelihood and confidence qualifiers with bound scale references", "Causal evidence citations where an attributed-cause claim is made", "Accountable assessor, role and issuing mandate", "Limitation and difficulty narrative" ], "outputs": [ "Qualified result set", "Signed limitation and uncertainty disclosure", "Non-authorisation statement bound to the release" ], "preconditions": [ "Every asserted outcome carries a claim status before release", "An attributed-cause status cites evidence meeting the Dimension's declared minimum, otherwise the status is downgraded", "The completeness code from the trace record is available" ], "effects": [ "Blocks release of an unqualified outcome", "Downgrades an unsupported attributed-cause claim to modelled prediction or exposure inference", "Grants and withholds no approval; emits an audit payload for the release to the referenced audit model without storing or retaining the trail" ], "source_refs": [ "SRC-081", "SRC-080", "SRC-086", "SRC-001" ] }, { "id": "dep-impact-fn-record-observed-outcome", "name": "Record a retrospective observed outcome", "description": "Record an outcome that was actually seen on an entity, with observation time separate from event time and an observer, optionally bound to a scenario without asserting that the scenario's trigger caused it.", "inputs": [ "Observed entity reference", "Observed effect description, kind and magnitude", "Event or effect onset time", "Observation or ingestion time", "Observer agent reference", "Optional scenario reference" ], "outputs": [ "Retrospective observation record with claim status observed-outcome", "Optional non-causal binding to a scenario version" ], "preconditions": [ "Observation or ingestion time is recorded separately from event time, both with explicit offsets", "Any binding to a scenario is marked as co-reference, not causation", "The observer agent and the observing system are recorded" ], "effects": [ "Creates an observation available for later reconciliation with a prediction", "Never retro-edits the prospective scenario or its results", "Asserts no causal relationship between the trigger and the observation", "Performs no detection, alerting or monitoring, which remain with a monitoring model" ], "source_refs": [ "SRC-001", "SRC-007", "SRC-086", "SRC-081" ] }, { "id": "dep-impact-fn-reconcile-forecast-outcome", "name": "Reconcile a prospective result with observed outcomes", "description": "Compare a released prospective result set with retrospective observations over a stated comparison window, producing a reconciliation record of predicted-and-seen, predicted-and-not-seen and unforeseen outcomes, plus a calibration note.", "inputs": [ "Prospective result set version", "Observation record references", "Comparison window with explicit start and end", "Matching rule for entity and effect identity" ], "outputs": [ "Reconciliation record classifying each outcome", "Calibration note on the likelihood and confidence qualifiers used", "List of unforeseen outcomes not reachable under the cited propagation profile" ], "preconditions": [ "Both sides cite explicit versions and times", "The baseline for the prospective result is declared, since an unforeseen outcome is only meaningful against a baseline", "The comparison window is stated rather than inferred" ], "effects": [ "Produces a new reconciliation record and leaves both source records immutable", "Any causal statement arising from reconciliation must satisfy the evidence rule for attributed-cause status", "Identifies propagation-profile deficiencies as findings for the profile owner, and does not amend the dependency graph" ], "source_refs": [ "SRC-080", "SRC-081", "SRC-084", "SRC-012" ] }, { "id": "dep-impact-fn-supersede-scenario", "name": "Supersede a scenario or result version", "description": "Issue a superseding version when a trigger, baseline, snapshot, profile, horizon or code-list binding changes, linking the new version to its predecessor and stating the change reason, without deleting anything.", "inputs": [ "Prior scenario or result version reference", "Change reason code and narrative", "New or revised inputs", "Re-derivation decision" ], "outputs": [ "Superseding version with a supersession link", "Change reason record", "Invalidation or re-derivation flags on dependent results" ], "preconditions": [ "The prior version is retained and remains resolvable", "The change reason names the specific input that changed", "Dependent results are enumerated before the prior version is marked superseded" ], "effects": [ "Marks the prior version superseded without deleting it and without altering its content", "Never deletes trace records or disclosures", "Leaves retention periods, legal hold and destruction to the adopting Dimension's retention policy and the trigger-owning model", "Emits a supersession audit payload consumed by the referenced audit model" ], "source_refs": [ "SRC-012", "SRC-001", "SRC-080" ] }, { "id": "dep-res-fn-record-criticality-assignment", "name": "Record criticality assignment", "description": "Create or supersede a criticality assignment binding a dependency edge to a dependent purpose under a named scheme, authority and validity window.", "inputs": [ "Dependency edge reference", "Dependent purpose reference", "Scheme reference and version", "Scheme-native level value", "Deciding authority reference", "Validity window and operating state" ], "outputs": [ "Persisted assignment record with identifier", "Assertion timestamp", "Supersession link to any prior assignment" ], "preconditions": [ "The referenced dependency edge resolves in the dependency-fact core", "The scheme version is registered and not withdrawn", "The deciding authority reference resolves" ], "effects": [ "Creates a new assignment version; prior versions are retained as superseded rather than overwritten", "Leaves the dependency edge itself unmodified", "Sets the review-due timestamp from the validity window" ], "source_refs": [ "SRC-087", "SRC-090" ] }, { "id": "dep-res-fn-register-scheme-binding", "name": "Register scale scheme binding", "description": "Register a published rating, severity or likelihood scheme version so that stored values can be interpreted and validated against its declared value space.", "inputs": [ "Scheme identifier and publisher", "Version string and publication date", "Declared value space and notation form", "Authoritative specification URL and content digest" ], "outputs": [ "Scheme binding record", "Validation verdict for values claiming that scheme", "Supersession status of earlier versions" ], "preconditions": [ "The publisher reference is resolvable", "The version is distinct from an already-registered version" ], "effects": [ "Enables scheme-qualified storage and validation of values", "Marks superseded scheme versions read-only for new assertions while preserving existing values", "Records any declared cross-scheme mapping as lossy unless proven otherwise" ], "source_refs": [ "SRC-091", "SRC-092", "SRC-097" ] }, { "id": "dep-res-fn-project-downstream-impact", "name": "Project downstream impact and affected set", "description": "Derive an affected-set snapshot and its propagation order from a referenced dependency-graph snapshot under a declared traversal rule, and attach the impact estimate that applies to each reached tier.", "inputs": [ "Subject element reference", "Assumed loss scenario", "Dependency graph snapshot reference", "Traversal rule identifier and depth limit", "Declared exclusions" ], "outputs": [ "Affected-set snapshot with propagation order and path witnesses", "Boundary-crossing list", "Per-tier time-to-impact values" ], "preconditions": [ "Read access to a dependency graph snapshot owned by the dependency-fact core", "A traversal rule version is declared", "Cycle-handling behaviour is specified" ], "effects": [ "Records a reproducible derivation with its inputs and rule version", "Makes no modification to the dependency graph and triggers no operational action", "Marks prior snapshots superseded without deleting them" ], "source_refs": [ "SRC-087", "SRC-093" ] }, { "id": "dep-res-fn-qualify-estimate", "name": "Qualify estimate with likelihood and confidence", "description": "Attach likelihood, horizon, confidence, evidential basis and residual uncertainty to an existing criticality or impact estimate, and set the conditions that will mark it stale.", "inputs": [ "Estimate reference", "Likelihood value, scheme and horizon", "Confidence level and derivation basis", "Residual uncertainty statement", "Assessor and reviewer identities" ], "outputs": [ "Qualified estimate record", "Freshness state and review-due timestamp", "Recorded dissent where reviewers disagreed" ], "preconditions": [ "The estimate exists and is not already superseded", "The likelihood and confidence schemes are registered", "At least one assessor identity is supplied" ], "effects": [ "Stores likelihood and confidence as separate fields that cannot be collapsed into one value", "Sets invalidation triggers so that later fact changes mark the estimate stale", "Does not compute or assert any risk level" ], "source_refs": [ "SRC-088", "SRC-089" ] }, { "id": "dep-res-fn-derive-resilience-determination", "name": "Derive resilience determination", "description": "Compute this model's own single-point-of-failure verdict and concentration measures from locally recorded substitutes, redundancy configuration, capacity limits and common-cause conditions, with a full derivation trace.", "inputs": [ "Substitute option records", "Redundancy configuration record", "Capacity limits and retained-capacity values", "Common-cause condition list", "Derivation rule version and counting rule" ], "outputs": [ "Single-point-of-failure verdict per subject and dependent pair", "Concentration measures by level", "Derivation trace referencing every input record" ], "preconditions": [ "At least one redundancy or substitute record exists for the subject", "A derivation rule version is declared", "Counting and deduplication rules are declared for concentration measures" ], "effects": [ "Writes a derived determination that is regenerated rather than patched when inputs change", "Performs no failover, remediation, policy enforcement or supervisory designation", "Records contests and overrides alongside the verdict rather than replacing it" ], "source_refs": [ "SRC-094", "SRC-095", "SRC-078" ] }, { "id": "dep-res-fn-attach-mitigation-reference", "name": "Attach mitigation reference", "description": "Link an externally owned mitigation, control or continuity record to a local estimate, record the credited effect and compute the residual value, without touching the mitigation's own lifecycle.", "inputs": [ "Mitigation record identifier and owning system", "Target estimate reference", "Crediting rule", "In-force evidence reference and window" ], "outputs": [ "Mitigation reference link", "Pre-mitigation and post-mitigation value pair", "Residual value with its bound scheme" ], "preconditions": [ "The mitigation record reference resolves in the owning system", "The owning system and accountable owner are identified", "The in-force window is expressed with explicit timestamps" ], "effects": [ "Creates a pointer and a credited-effect record only", "Never creates, approves, executes, tests or audits the referenced mitigation", "Marks the credit unverified when in-force evidence is missing or stale, reducing the estimate's confidence" ], "source_refs": [ "SRC-089", "SRC-096", "SRC-038" ] }, { "id": "dep-govr-fn-bind-role", "name": "Bind role archetype to agent", "description": "Create a qualified attribution binding one role archetype from the register to an identified agent for a stated scope, validity window, purpose and jurisdiction, optionally recording a delegation chain.", "inputs": [ "Agent reference resolved in the referenced party/agent identity model", "Role archetype code from the archetype register", "Scope expression over dependency or impact assertions", "Valid-from and optional valid-until instants", "Purpose code and jurisdiction reference", "Optional delegating agent reference" ], "outputs": [ "Role binding record in state proposed or active", "Binding identifier", "Rejection reason where inputs are incomplete" ], "preconditions": [ "The archetype code exists and is not deprecated in the register", "The agent reference resolves in the referenced identity model", "Purpose and jurisdiction qualifiers are present", "Any declared delegation does not exceed the permitted depth" ], "effects": [ "A new binding exists with an explicit validity window and provenance", "The binding becomes available as an attribute to external decision points", "No access is granted and no privilege is provisioned by this function" ], "source_refs": [ "SRC-001", "SRC-100", "SRC-101" ] }, { "id": "dep-govr-fn-screen-duty-conflict", "name": "Screen proposed binding for duty conflict", "description": "Compare a proposed or existing set of bindings against the incompatible-duty matrix and return an advisory conflict finding with the matched rule, separation mode and aggregation window. Advisory only: the function reports, it does not block, revoke or enforce.", "inputs": [ "Candidate binding set for one agent", "Subject assertion or endpoint scope", "Incompatible-duty matrix version", "Aggregation window for history-based separation" ], "outputs": [ "Conflict finding with matched incompatible duty sets or an explicit no-conflict result", "Separation mode that triggered the match", "Referral pointer to the access and policy model that owns any resulting decision" ], "preconditions": [ "An effective incompatible-duty matrix version is available", "All candidate bindings resolve to archetype codes in the register" ], "effects": [ "A duty conflict observation record is created with observation time and observing agent or tool", "The finding is exposed as an attribute for external evaluation", "No binding is suspended, revoked or blocked by this function" ], "source_refs": [ "SRC-106", "SRC-103" ] }, { "id": "dep-govr-fn-record-decision", "name": "Record review or approval decision", "description": "Capture an immutable decision record stating the outcome, basis, effective time, conditions and acting agents for a review or approval act on a dependency or impact assertion.", "inputs": [ "Subject dependency or impact assertion reference", "Acting agent reference and its active binding", "Outcome code and decision basis narrative", "Decision effective time and record capture time", "Attached conditions with owners", "Purpose and jurisdiction qualifiers" ], "outputs": [ "Serial decision record", "Updated governance standing of the subject assertion", "Correlation identifier emitted to the referenced audit model" ], "preconditions": [ "The acting agent holds an active binding to a competent archetype", "Any applicable two-person condition is satisfied by distinct agents", "No unmitigated duty conflict is open without a covering exception grant", "The reviewer has not recused for a declared conflict of interest" ], "effects": [ "The subject assertion's governance standing changes to the recorded value", "The decision record is immutable; corrections require a superseding record", "An event is emitted for external audit capture; no audit trail is stored locally" ], "source_refs": [ "SRC-099", "SRC-102", "SRC-105" ] }, { "id": "dep-govr-fn-open-contest", "name": "Open contest against an assertion", "description": "Register a dispute over the existence, direction, scope, type, severity or timing of a dependency or impact assertion, set the assertion stance and interim treatment, and name the competent resolving authority.", "inputs": [ "Subject assertion reference", "Contesting agent reference", "Contested element codes and ground narrative", "Optional counter-assertion reference", "Proposed resolving authority and escalation tier" ], "outputs": [ "Serial contest record in open state", "Updated assertion stance and interim treatment code", "Escalation route where the contest crosses an organizational boundary" ], "preconditions": [ "The subject assertion exists and is not already tombstoned", "The contesting agent is identified, whether or not it holds a binding" ], "effects": [ "The subject assertion is marked contested without being deleted or overwritten", "Consumers are directed to the recorded interim treatment", "A target resolution time is set and its breach becomes reportable" ], "source_refs": [ "SRC-013", "SRC-102", "SRC-038" ] }, { "id": "dep-govr-fn-resolve-contest", "name": "Resolve or lapse a contest", "description": "Close an open contest with a recorded resolution by the competent authority, or mark it lapsed when the resolution window expires without a decision, in both cases preserving the full contest history.", "inputs": [ "Contest record reference", "Resolving authority reference and binding", "Resolution outcome and rationale", "Resolution or lapse timestamp" ], "outputs": [ "Closed or lapsed contest record", "Resulting assertion stance", "Referral to a higher escalation tier where resolution was not competent" ], "preconditions": [ "The contest is open", "The resolving agent is the competent authority for the recorded escalation tier, or the lapse condition is met" ], "effects": [ "The contest record is closed with an immutable outcome", "The assertion stance is updated, which may leave it asserted-none or no-assertion", "Cross-boundary contests that no single party may close remain open rather than defaulting" ], "source_refs": [ "SRC-102", "SRC-013" ] }, { "id": "dep-govr-fn-grant-exception", "name": "Grant or renew a time-bounded exception", "description": "Record that a competent exception authority waived a specific governance requirement for a bounded scope and period under stated compensating conditions, naming the agent accountable for the residual consequence.", "inputs": [ "Waived requirement reference", "Scope of assertions or endpoints affected", "Exception authority reference and binding", "Granted-from and expires-at instants", "Compensating conditions with owners", "Prior grant reference where this is a renewal" ], "outputs": [ "Serial exception grant record", "Effective waiver window applied to the named scope", "Renewal counter" ], "preconditions": [ "The requested waiver falls within the authority's declared competence ceiling", "The requirement is not on the never-exceptable list", "The exception authority is not the agent that requested it", "Maximum consecutive renewal count is not exceeded" ], "effects": [ "The named requirement is recorded as waived for the stated scope and window only", "A remediation reference in the referenced risk or change model becomes mandatory", "On expiry without renewal the affected assertions revert to their pre-exception standing" ], "source_refs": [ "SRC-105", "SRC-102", "SRC-106" ] }, { "id": "dep-govr-fn-set-record-markers", "name": "Set record-governance referral markers", "description": "Assign or update the sensitivity classification, retention-class reference, legal-hold marker and audit correlation identifier on a governance record so that owning models can apply the correct regime.", "inputs": [ "Governance record reference", "Sensitivity classification code and scheme", "Retention class reference and retention trigger event", "Optional hold identifier, issuing authority and applied timestamp", "Classifying agent reference" ], "outputs": [ "Updated marker set on the governance record", "Attribute payload published for external decision points", "Reclassification review date" ], "preconditions": [ "The classification scheme and retention schedule references resolve in the owning models", "A hold marker is accompanied by an issuing authority reference" ], "effects": [ "Markers become available to the access, privacy, records and audit models", "Local disposition proposals for the record are suspended while a hold marker is set", "No access decision is rendered and no record is destroyed by this function" ], "source_refs": [ "SRC-103", "SRC-107", "SRC-108", "SRC-104" ] }, { "id": "dep-govr-fn-resolve-accountable-party", "name": "Resolve accountable parties for an assertion", "description": "Given a dependency or impact assertion, a governance act, a purpose and a jurisdiction, return the currently bound agents competent for that act, their delegation chains and any unresolved accountability gaps. This is a lookup over declared bindings, not an authorization check.", "inputs": [ "Assertion reference", "Governance act code", "Purpose code", "Jurisdiction reference", "Evaluation instant" ], "outputs": [ "Ordered list of competent bound agents with binding identifiers", "Delegation chain for each", "Gap report where no competent binding exists or all bindings have lapsed" ], "preconditions": [ "Bindings exist and their validity windows are expressed with explicit offsets", "The archetype register version in force at the evaluation instant is resolvable" ], "effects": [ "A point-in-time accountability view is produced and can be cited by other models", "Gaps are surfaced as unstewarded or unbound conditions requiring escalation", "No permission is granted and no obligation is discharged by this function" ], "source_refs": [ "SRC-001", "SRC-105", "SRC-038", "SRC-101" ] }, { "id": "dep-govp-fn-mint-record-identifier", "name": "Mint or bind record identifier", "description": "Assign an identifier to a new dependency-edge or impact-assessment record by applying the identity priority: adopt an authoritative master-system identifier if one exists, otherwise a governed identifier under a delegated namespace, otherwise mint a UUIDv7 or ULID in the adopting Dimension's namespace.", "inputs": [ "Candidate master-system identifier, if any", "Namespace identifier and tenant partition key", "Record kind (dependency edge or impact assessment)" ], "outputs": [ "Record identifier with scheme and satisfied priority tier", "Namespace-qualified identifier form", "Rejection reason where no admissible identifier could be assigned" ], "preconditions": [ "A namespace and tenant partition are registered with a named owner package", "The candidate identifier contains no date-like component and is not a content digest" ], "effects": [ "A record identifier is bound and thereafter immutable", "Alias identifiers, if supplied, are recorded as non-authoritative" ], "source_refs": [ "SRC-114", "SRC-116" ] }, { "id": "dep-govp-fn-canonicalize-and-digest", "name": "Canonicalize record and compute digest", "description": "Produce the deterministic canonical byte stream for a record under the declared canonicalization profile for a named shape family, and compute the content digest over it.", "inputs": [ "Abstract record state", "Canonicalization profile reference and shape family", "Digest algorithm name" ], "outputs": [ "Canonical byte stream", "Content digest with algorithm, encoding and the profile it was computed under" ], "preconditions": [ "Numeric fields exceeding double precision are already encoded as strings", "The declared text normalization form has been applied or explicitly declared as none", "The record contains no duplicate property names in tree-shaped form" ], "effects": [ "The digest becomes the integrity anchor for patches, attestations and integrity manifests", "Cross-shape digest equality is not asserted and must not be inferred" ], "source_refs": [ "SRC-109", "SRC-110" ] }, { "id": "dep-govp-fn-resolve-namespace-binding", "name": "Resolve namespace and tenancy binding", "description": "Determine which namespace partition, adopting Dimension and owner package a given identifier belongs to, and whether a reference crosses partitions.", "inputs": [ "Identifier or reference to resolve", "Namespace and tenancy registration manifests in force" ], "outputs": [ "Namespace identifier, tenant partition key and owner package reference", "Cross-partition flag and applicable cross-partition reference rule" ], "preconditions": [ "The identifier is presented without resolution, query or fragment parameters, which are excluded from identity comparison" ], "effects": [ "A reference is classified as local, foreign-permitted or foreign-prohibited", "Unresolvable references are flagged as dangling rather than silently dropped" ], "source_refs": [ "SRC-116", "SRC-118" ] }, { "id": "dep-govp-fn-apply-change-set", "name": "Apply change set to record", "description": "Apply a patch document to a record atomically, verifying the expected pre-state digest and any test preconditions before any operation takes effect, and recording the resulting version and compatibility class.", "inputs": [ "Change set with patch grammar, operations or quad difference, and pre-state digest", "Current record state and its digest", "Requesting agent reference" ], "outputs": [ "New immutable record version with post-state digest and previous-version link", "Applied or rejected outcome with conflict detail", "Declared compatibility class for the change" ], "preconditions": [ "The presented pre-state digest matches the current canonical digest", "Merge-patch grammar is used only where the affected subtree is object-shaped, contains no explicit nulls and needs no partial array edit" ], "effects": [ "On failure of any operation or precondition the entire patch is rejected and the record is left unchanged", "On success the prior version is retained immutably in the lineage chain", "An audit event is emitted to the externally owned audit system" ], "source_refs": [ "SRC-111", "SRC-112" ] }, { "id": "dep-govp-fn-validate-record", "name": "Request validation of record against profile", "description": "Submit one or more records to a named validation profile and retain the resulting report of overall conformance and individual results with severities. Execution is performed by an external engine.", "inputs": [ "Record or record set with digests", "Validation profile reference, version and digest", "Target selection rule" ], "outputs": [ "Validation report with conformance flag, result entries and severities", "Engine and profile references bound into the report" ], "preconditions": [ "The validation profile is published, versioned and digest-bound", "Each submitted record has a computed canonical digest" ], "effects": [ "The report is retained as evidence and linked to the record versions it covers", "No permission, authorization or enforcement follows from the report within this model" ], "source_refs": [ "SRC-049", "SRC-015" ] }, { "id": "dep-govp-fn-project-with-loss-report", "name": "Project record to target with loss report", "description": "Render a record into a named projection target under its projection profile, emitting a loss report that lists every element carried, transformed or dropped and the round-trip status.", "inputs": [ "Record state and canonical digest", "Projection profile reference for the target", "Optional node-selection expression for partial projection" ], "outputs": [ "Projected representation in the target form", "Loss report with per-element disposition and reversibility", "Normalized paths of returned nodes and a completeness flag for partial projections" ], "preconditions": [ "A published projection profile exists for the target", "Absence semantics representation is declared for the target, or the collapse is disclosed" ], "effects": [ "No projection is treated as canonical", "Undisclosed silent degradation is a contract violation, not an acceptable fallback" ], "source_refs": [ "SRC-112", "SRC-013", "SRC-115" ] }, { "id": "dep-govp-fn-record-provenance", "name": "Record provenance, evidence and custody", "description": "Attach attribution, derivation lineage, generating activity, supporting evidence references with digests, and custody chain entries to a dependency or impact record.", "inputs": [ "Record identifier and version digest", "Responsible agent reference and role", "Derivation or revision references, generating activity reference, evidence references with digests" ], "outputs": [ "Provenance and custody record bound to the subject digest", "Assertion confidence qualifier where supplied" ], "preconditions": [ "Each evidence reference carries a digest and algorithm", "The generating activity has recorded start and, where complete, end times with explicit offsets" ], "effects": [ "The assertion becomes attributable and its lineage traversable", "No signature verification, trust evaluation or attestation service operation occurs within this model" ], "source_refs": [ "SRC-001", "SRC-117" ] }, { "id": "dep-govp-fn-issue-disposition-request", "name": "Retire record and issue disposition request", "description": "Move a record to a retired state, create its tombstone preserving identifier, final digest and disposition reason, and issue a disposition request to the party that owns execution under the governing retention policy.", "inputs": [ "Record identifier, final version and digest", "Governing retention policy reference and retention class", "Disposition reason and requesting agent reference" ], "outputs": [ "Tombstone record with retired identifier, final digest and disposition timestamp", "Disposition request addressed to the executing party", "Confirmation reference once execution is reported back" ], "preconditions": [ "The minimum retention period under the governing policy has elapsed or an explicit override authority reference is supplied", "Inbound references have been enumerated so they can resolve to the retired state" ], "effects": [ "The identifier is never reassigned and inbound references resolve to an explicit retired state", "Execution of erasure in downstream stores is performed by the adopting Dimension or referenced retention model, not here", "An audit event is emitted to the externally owned audit system" ], "source_refs": [ "SRC-116", "SRC-038", "SRC-118" ] }, { "id": "dep-govp-fn-assert-conformance", "name": "Assert bounded conformance claim", "description": "Publish a falsifiable statement that a named record set conforms to a named profile at a named version, bound to the validation run and the canonicalization profile that produced its digests.", "inputs": [ "Record set with digests", "Validation report reference and profile version", "Canonicalization and projection profile references" ], "outputs": [ "Bounded conformance claim naming profile, version, run and covered digests", "Explicit list of profiles the claim does not cover" ], "preconditions": [ "A validation report exists for the exact record versions covered", "No conformance is claimed to any standard for which alignment evidence has not been recorded" ], "effects": [ "Alignment to external standards is recorded as alignment, never as certified conformance", "A superseded claim is retained and marked superseded rather than deleted" ], "source_refs": [ "SRC-049", "SRC-015", "SRC-117" ] }, { "id": "dep-mut-fn-declare", "name": "Declare dependency or impact statement", "description": "Create a new dependency or impact statement in draft state from asserted inputs, without creating or altering the endpoint records it names.", "inputs": [ "Source and target endpoint references", "Relationship or impact type", "Lifecycle scope and completeness qualifier", "Assertion basis and supporting evidence references", "Actor reference and authorization decision reference", "Optional idempotency key and request fingerprint" ], "outputs": [ "Statement identifier and first version token", "Draft lifecycle state", "Created-or-matched replay outcome", "Declared event" ], "preconditions": [ "All named endpoint references resolve read-only in their owning models", "Actor reference resolves and the authorization decision reference is a permit", "No equivalent statement already exists under the declared uniqueness criterion, or the request is a valid replay" ], "effects": [ "Creates one immutable first version in draft state", "Records the producing command and provenance association", "Emits a declared event; performs no resolution, deployment or notification" ], "source_refs": [ "SRC-013", "SRC-019", "SRC-124", "SRC-001" ] }, { "id": "dep-mut-fn-validate", "name": "Validate statement or proposed change", "description": "Evaluate envelope completeness, reference resolvability, transition legality and externally owned statement invariants against a named version, and return a structured outcome.", "inputs": [ "Statement identifier and version token, or a proposed change payload", "Rule set or profile reference with version pin", "Actor reference" ], "outputs": [ "Validation outcome report with severities, issue codes and locations", "Blocking indicator for the intended transition" ], "preconditions": [ "The named statement version exists", "The referenced rule set resolves at the pinned version" ], "effects": [ "Produces or updates a validation outcome report bound to the evaluated version", "Changes no statement content and produces no new statement version", "Does not author or amend the invariants it evaluates" ], "source_refs": [ "SRC-126", "SRC-013", "SRC-120" ] }, { "id": "dep-mut-fn-review", "name": "Record review of a statement", "description": "Attach a reviewer's disposition to a named statement version as a separable assessment record, moving workflow state without changing asserted content.", "inputs": [ "Statement identifier and version token", "Reviewer party reference and role", "Disposition and comment", "Authorization decision reference" ], "outputs": [ "Review record identifier", "Updated workflow status", "Reviewed event" ], "preconditions": [ "The statement is in a state from which review is permitted", "The reviewer reference resolves and the authorization decision reference is a permit" ], "effects": [ "Creates a review record whose attribution is separate from the statement", "Updates workflow status only; no new statement version is produced", "Emits a reviewed event" ], "source_refs": [ "SRC-125", "SRC-103", "SRC-127" ] }, { "id": "dep-mut-fn-approve", "name": "Approve a statement version", "description": "Record an authority's approval of a named statement version, satisfying the gate that activation requires.", "inputs": [ "Statement identifier and version token", "Approver party reference and authority reference", "Authorization decision reference", "Optional exception grant for a break-glass approval" ], "outputs": [ "Approval record identifier", "Approved workflow status", "Approved event" ], "preconditions": [ "Blocking validation findings are absent or explicitly waived with a recorded exception", "Where separation of duties applies, the approver differs from the declarer", "The authority reference covers the scope of this statement" ], "effects": [ "Creates an approval record citing the exact version token", "Marks the version as approved without activating it", "Grants no authorization to deploy, remediate or otherwise act on the dependency" ], "source_refs": [ "SRC-125", "SRC-103", "SRC-001" ] }, { "id": "dep-mut-fn-activate", "name": "Activate an approved statement", "description": "Promote an approved statement version to the active state so that it is ready for normal use by downstream consumers.", "inputs": [ "Statement identifier and version token", "Expected current version token", "Effective-from value", "Actor reference and authorization decision reference" ], "outputs": [ "Active lifecycle state", "Current version token", "Activated event" ], "preconditions": [ "An approval record exists for exactly this version token", "The expected version token matches the current version", "The effective-from value is a complete RFC 3339 timestamp" ], "effects": [ "Sets the statement state to active and opens the asserted validity interval", "Is idempotent: repeating it on an already active version leaves state unchanged", "Emits an activated event as a signal only" ], "source_refs": [ "SRC-127", "SRC-124", "SRC-119" ] }, { "id": "dep-mut-fn-revise", "name": "Revise an active statement", "description": "Produce a new immutable version reflecting a legitimately changed dependency or impact, preserving the prior version and its derivation link.", "inputs": [ "Statement identifier and expected current version token", "Changed fields or an atomic patch with test preconditions", "Reason for change", "Actor reference and authorization decision reference" ], "outputs": [ "New version token", "Derivation link to the prior version", "Revised event" ], "preconditions": [ "The expected version token matches the current version", "The change is content-affecting rather than a workflow-only update", "The patch applies in full or not at all" ], "effects": [ "Creates a new version recorded as a revision of its predecessor", "Leaves the predecessor readable and unmodified", "May reset the statement to a state requiring re-approval where the contract declares it" ], "source_refs": [ "SRC-001", "SRC-124", "SRC-121" ] }, { "id": "dep-mut-fn-correct", "name": "Correct an erroneous version", "description": "Mark a version as one that should never have been asserted and record the corrected content, without denying that the erroneous version was recorded.", "inputs": [ "Statement identifier and the version token being corrected", "Correction reason and evidence reference", "Corrected content", "Actor reference and authorization decision reference" ], "outputs": [ "Corrected version token", "Entered-in-error marker on the affected version", "Corrected event" ], "preconditions": [ "The version being corrected exists and is not already marked erroneous", "The correction is distinguishable from a revision by an explicit change-nature value" ], "effects": [ "Adds a new version and an erroneous-record marker on the earlier one", "Never overwrites or obscures previously recorded content", "Does not alter the asserted validity interval of unaffected versions" ], "source_refs": [ "SRC-065", "SRC-001", "SRC-124" ] }, { "id": "dep-mut-fn-supersede", "name": "Supersede a statement with a successor", "description": "End the currency of one statement in favour of a named successor and record the link in both directions.", "inputs": [ "Predecessor statement identifier and current version token", "Successor statement reference", "Supersession reason", "Effective-to value for the predecessor", "Actor reference and authorization decision reference" ], "outputs": [ "Superseded lifecycle state on the predecessor", "Supersedes and superseded-by links", "Superseded event" ], "preconditions": [ "The successor statement exists and is at least approved", "The predecessor is currently active", "The effective-to value is not earlier than the predecessor's effective-from" ], "effects": [ "Closes the predecessor's asserted validity interval and marks it withdrawn in favour of the successor", "Preserves the full history of both statements", "Emits a superseded event without instructing any consumer to migrate" ], "source_refs": [ "SRC-127", "SRC-013", "SRC-001" ] }, { "id": "dep-mut-fn-retire", "name": "Retire a statement", "description": "End the applicability of a statement that is no longer to be used, without asserting that it was ever erroneous and without deleting anything.", "inputs": [ "Statement identifier and expected current version token", "Retirement reason", "Effective-to value", "Actor reference and authorization decision reference" ], "outputs": [ "Retired lifecycle state", "Terminal version token", "Retired event" ], "preconditions": [ "The expected version token matches the current version", "The statement is not already retired, or the repeat is treated as a no-change idempotent call" ], "effects": [ "Sets the statement to retired and closes its validity interval", "Succeeds on the local statement even when a referenced endpoint no longer exists, and never modifies that endpoint", "Triggers no destruction: disposition remains with the external retention policy" ], "source_refs": [ "SRC-127", "SRC-124", "SRC-001" ] }, { "id": "dep-mut-fn-observation-update", "name": "Apply an observation update", "description": "Refresh a statement from an automated observation, recording observer, presence value and both observation times, and applying it as a change only where the statement is registered as observation-managed.", "inputs": [ "Statement identifier or uniqueness criterion for a new observed statement", "Observer and procedure references", "Observed presence value and confidence", "Phenomenon time and result time", "Optional idempotency key" ], "outputs": [ "Observation record identifier", "Updated currency marker or a new statement version where permitted", "Competing-evidence marker where the statement is human-declared", "Observed event" ], "preconditions": [ "Observer reference resolves and the observation carries both phenomenon and result times", "The statement is observation-managed, or the update is attached as evidence only", "The observation is not a duplicate of one already recorded for the same source and observation identifier" ], "effects": [ "Records the observation and its times without overwriting earlier observations", "Updates statement currency only within the precedence rules declared by the contract", "Never bypasses an approval gate and never initiates a scan, resolution or remediation" ], "source_refs": [ "SRC-054", "SRC-065", "SRC-013", "SRC-123" ] }, { "id": "dep-qry-fn-resolve-query-scope", "name": "Resolve query scope", "description": "Turn a caller's request into a resolved scope descriptor: endpoints resolved under a named identifier authority, accepted and rejected filters, in-scope partitions, and the world-scope mode under which the answer will be interpreted.", "inputs": [ "Requested subject endpoint identifiers", "Requested edge-type and attribute filters", "Requested world-scope mode and any closed-world scope declaration reference" ], "outputs": [ "Resolved scope descriptor with accepted filters, enumerated in-scope partitions and world-scope mode", "Explicit rejection list for unsupported, ambiguous or unresolvable request elements" ], "preconditions": [ "Every endpoint identifier resolves under a named identifier authority, or is returned as unresolved", "A requested closed-world scope declaration exists, is currently valid and covers the requested partitions" ], "effects": [ "Fixes the population the read may examine, making later completeness and negative-result statements interpretable", "Unsupported filters are refused rather than ignored, because a silently dropped filter changes the meaning of an empty result", "No stored assertion is created, modified or evaluated" ], "source_refs": [ "SRC-129", "SRC-073", "SRC-014" ] }, { "id": "dep-qry-fn-bind-reference-point", "name": "Bind reference point", "description": "Resolve a requested as-of instant on a named temporal axis to an available reference point, and record requested versus resolved values so the caller can see what was actually read.", "inputs": [ "Requested as-of instant with explicit offset, or absence meaning current", "Requested temporal axis", "Resolved scope descriptor" ], "outputs": [ "Resolved reference point identifier with its instant and resolution rule", "As-of binding record stating requested instant, resolved instant, axis and retained horizon" ], "preconditions": [ "The requested axis is supported by every in-scope partition, or the unsupported partitions are disclosed", "The requested instant falls within the retained horizon" ], "effects": [ "Every subsequent operation in the invocation reads the same reference point", "A request outside the retained horizon fails explicitly instead of silently returning current state", "Retention of reference points is executed by the storage and lifecycle owners, not by this function" ], "source_refs": [ "SRC-131", "SRC-013", "SRC-001" ] }, { "id": "dep-qry-fn-read-assertions", "name": "Read stored assertions", "description": "Return the stored dependency assertions matching a resolved scope at a bound reference point, each marked with its derivation class and provenance references.", "inputs": [ "Resolved scope descriptor", "Bound reference point", "Paging request with ordering keys" ], "outputs": [ "Result set of edges with derivation class, orientation and provenance references", "Result-integrity block covering completeness, truncation and exclusions" ], "preconditions": [ "Scope is resolved and reference point is bound", "An authorization decision for the requested scope has been obtained from the external decision point" ], "effects": [ "Only stored assertions are returned; no inference is performed implicitly", "Edges withheld by the external decision are disclosed by count and decision reference rather than dropped silently", "Read-only: no assertion state changes" ], "source_refs": [ "SRC-129", "SRC-013", "SRC-132", "SRC-103" ] }, { "id": "dep-qry-fn-traverse-neighborhood", "name": "Traverse bounded neighborhood", "description": "Expand from one or more seed endpoints in an explicit direction under stated depth, breadth and budget bounds, returning the visited region with stop reasons and the unexpanded frontier.", "inputs": [ "Seed endpoint references and seed combination mode", "Explicit traversal direction and applied bounds", "Resolved scope descriptor and bound reference point" ], "outputs": [ "Neighborhood projection of visited endpoints and traversed edges with preserved orientation", "Stop reasons and unexpanded frontier endpoints" ], "preconditions": [ "Direction is stated explicitly or a published default applies", "At least one seed endpoint resolves" ], "effects": [ "A region halted by a bound is always accompanied by stop reasons, so it cannot be read as the full region", "Reverse expansion is applied only to edge types marked invertible", "Read-only: traversal produces a projection, never a stored edge" ], "source_refs": [ "SRC-129", "SRC-133", "SRC-132" ] }, { "id": "dep-qry-fn-find-paths", "name": "Find paths between endpoints", "description": "Answer whether and how a source endpoint reaches a target endpoint or target predicate under a declared path mode and result shape, returning either enumerated paths or endpoint-pair connectivity.", "inputs": [ "Source endpoint and target endpoint or target predicate", "Declared path mode, result shape, direction and inverse-traversal request", "Resolved scope descriptor and bound reference point" ], "outputs": [ "Path result carrying returned paths or connectivity determinations with per-edge orientation and cycle markers", "Unreachable determination qualified by scope, path mode, direction, completeness and truncation state" ], "preconditions": [ "A path mode and result shape are declared; an undeclared mode is refused rather than defaulted silently", "Inverse traversal is requested only for edge types marked invertible" ], "effects": [ "Cycle handling follows the declared path mode so results remain finite", "Absence of a path is recorded as scope-qualified non-discovery and never as independence unless a declared closed-world scope applies", "Read-only: no stored edge is created from a computed path" ], "source_refs": [ "SRC-129", "SRC-135", "SRC-073" ] }, { "id": "dep-qry-fn-compare-reads", "name": "Compare two bound reads", "description": "Produce a classified difference set between two bound reads, first testing whether they are comparable at all across scope, filters, direction, path mode and completeness.", "inputs": [ "References to exactly two bound reads with their scope descriptors and reference points" ], "outputs": [ "Comparison report with comparability verdict, classified differences and suppressed differences", "Incomparability reasons per suppressed difference" ], "preconditions": [ "Both reads carry a resolved scope, a bound reference point and a completeness declaration", "Both reads remain retrievable at comparison time" ], "effects": [ "Differences attributable to scope, filter, truncation or withheld edges are suppressed with a reason instead of being reported as change", "An empty difference set is reportable as 'no change' only when both bases are complete and untruncated", "Read-only: neither basis is altered" ], "source_refs": [ "SRC-130", "SRC-013", "SRC-001", "SRC-014" ] }, { "id": "dep-qry-fn-project-impact-scenario", "name": "Project scenario impact", "description": "Compute a hypothesis-bound impact set from a bound read using an externally owned propagation rule set, and issue it as a labelled derived result with a validity window.", "inputs": [ "Scenario hypothesis descriptor and seed endpoints", "Resolvable propagation rule-set reference with version and parameters", "Reference to the bound read supplying the underlying edges" ], "outputs": [ "Scenario impact result with per-endpoint impact qualifiers and referenced external statuses", "Derivation and validity metadata including generating activity, agent and validity window" ], "preconditions": [ "The hypothesis and the rule-set version are both stated and resolvable", "The input bound read carries a completeness declaration and truncation state" ], "effects": [ "The result is labelled scenario-derived and non-authoritative and is never written back as a stored assertion", "External status assertions are cited, not restated or re-derived; an absent external status is treated as no assertion, not as a negative status", "Rule-set authorship, versioning and validity remain with the referenced rule model" ], "source_refs": [ "SRC-001", "SRC-012", "SRC-129" ] }, { "id": "dep-qry-fn-disclose-result-integrity", "name": "Disclose result integrity", "description": "Attach the mandatory integrity disclosure to any result before it is released: completeness code, world-scope mode, truncation state, unavailable sources, withheld-edge disclosure and, where more results exist, an opaque continuation bound to the same scope and reference point.", "inputs": [ "Draft result with its resolved scope and bound reference point", "Applied budgets, limits and ordering keys", "Exclusion summary received from the external authorization decision point" ], "outputs": [ "Result-integrity block with completeness code, world-scope mode, truncation state, unavailable-source references and counts", "Page continuation envelope and exclusion notice where applicable" ], "preconditions": [ "A total ordering exists for any paged result", "The authorization exclusion summary has been received, or is explicitly marked unavailable" ], "effects": [ "No result is released without a completeness code and a truncation state", "Withheld content is disclosed by count and decision reference only; this function neither renders, re-evaluates nor enforces the decision", "A correlation reference is emitted for the external audit owner; no audit record is created or held by this model" ], "source_refs": [ "SRC-130", "SRC-006", "SRC-014", "SRC-132", "SRC-103", "SRC-134" ] }, { "id": "dep-rpt-fn-bind-snapshot", "name": "Bind report to graph snapshot", "description": "Fix the immutable graph snapshot a report will be computed against, recording its resolvable reference, digest, observation time and restated completeness.", "inputs": [ "snapshot reference in the owning source of record", "snapshot content digest", "snapshot observation time", "snapshot completeness aggregate as declared by its owner" ], "outputs": [ "snapshot binding record attached to a draft report instance", "restated snapshot completeness carried into the disclosure block" ], "preconditions": [ "a draft report instance exists", "the snapshot is retrievable and its digest verifies", "the owning source-of-record model is identified" ], "effects": [ "The report is bound to exactly one snapshot for the remainder of its revision; a different snapshot requires a new revision.", "No change is made to the snapshot or to the inventory that owns it." ], "source_refs": [ "SRC-015", "SRC-136", "SRC-013" ] }, { "id": "dep-rpt-fn-declare-scenario", "name": "Declare and freeze change scenario", "description": "Record the subject elements, proposed action, variants and declared assumptions, then freeze them so conclusions cannot be reattributed to a different scenario.", "inputs": [ "subject element references", "proposed action codes", "optional scenario variants", "declared assumptions with their sources" ], "outputs": [ "frozen scenario declaration attached to the draft report instance" ], "preconditions": [ "subject elements resolve in the host subject model", "a stable scenario identifier is available or can be minted" ], "effects": [ "Scenario content becomes immutable for the revision; amendment requires a new revision.", "No change is proposed, scheduled or requested in any external system." ], "source_refs": [ "SRC-140", "SRC-023" ] }, { "id": "dep-rpt-fn-traverse-impact", "name": "Traverse impact paths", "description": "Traverse the bound snapshot from the scenario subjects under a versioned propagation rule set, producing the reached-element set, the replayable path set and the excluded-edge register.", "inputs": [ "frozen scenario declaration", "snapshot binding record", "traversal direction, edge-type filter and depth or fan-out bounds", "propagation rule set version" ], "outputs": [ "reached-element set with per-element impact class", "impact path set of ordered edge steps", "excluded-edge register with typed reason codes" ], "preconditions": [ "snapshot binding and scenario are frozen", "the named propagation rule set version is published and resolvable" ], "effects": [ "Produces derived analysis content within the draft revision only.", "Records every bound that was reached, so a truncated traversal cannot be mistaken for an exhausted one." ], "source_refs": [ "SRC-137", "SRC-013", "SRC-023", "SRC-015" ] }, { "id": "dep-rpt-fn-detect-degradation", "name": "Detect and record degraded conditions", "description": "Identify contradictions, stale assertions, unresolvable endpoints, cycles, alternative satisfiers and partial-coverage regions encountered during traversal, and record each with its effect on affected conclusions.", "inputs": [ "impact path set", "traversal input assertions with their sources and assertion times", "declared staleness threshold", "versioned cycle cut rule" ], "outputs": [ "degradation and known-unknowns register", "per-conclusion degradation effect notes" ], "preconditions": [ "traversal has produced a path set", "staleness threshold and cut rule versions are declared" ], "effects": [ "Both sides of each contradiction are retained; no assertion is deleted or overwritten by this function.", "Cycle cuts are recorded as reporting devices and never written back to the graph." ], "source_refs": [ "SRC-138", "SRC-058", "SRC-023", "SRC-014" ] }, { "id": "dep-rpt-fn-compute-disclosure", "name": "Compute confidence, completeness and coverage disclosures", "description": "Derive and attach the disclosure block: per-set completeness assertions, coverage measurement, and confidence values expressed on a named scale, capped by degradation and evidence conditions.", "inputs": [ "reached-element set and path set", "excluded-edge register", "degradation register", "evidence register", "named confidence scale definition and disclosure method version" ], "outputs": [ "disclosure block attached to the report and to each conclusion anchor", "unreached-region characterisation" ], "preconditions": [ "traversal, degradation detection and evidence citation have completed", "the confidence scale and disclosure method are published and versioned" ], "effects": [ "Confidence is capped where completeness is incomplete or no-assertion, or where cited evidence is stale or withdrawn.", "Absence of a computed value is recorded as an explicit no-assertion rather than defaulting to complete." ], "source_refs": [ "SRC-014", "SRC-136", "SRC-138", "SRC-055" ] }, { "id": "dep-rpt-fn-compose-report", "name": "Compose report instance of a declared kind", "description": "Assemble a report revision of one declared kind from the frozen frame, path set, exclusion and degradation registers, evidence register and disclosure block, and open it in draft status.", "inputs": [ "report kind code", "frozen scenario and snapshot binding", "path set, excluded-edge register and degradation register", "evidence register and disclosure block" ], "outputs": [ "draft report revision with a minted identifier and revision number", "kind-specific content core populated" ], "preconditions": [ "all referenced components exist and belong to the same revision", "the kind's mandatory content core is satisfiable from the available components" ], "effects": [ "Creates an immutable draft revision under the model's identity priority.", "Confers no approval, dispatches no notification and asserts no operational completion." ], "source_refs": [ "SRC-012", "SRC-058", "SRC-140" ] }, { "id": "dep-rpt-fn-validate-disclosure-contract", "name": "Validate report against the disclosure contract", "description": "Check a report revision against the published minimum disclosure set and the confidence-consistency rules, and return a conformance verdict with the specific deficiencies found.", "inputs": [ "report revision", "minimum disclosure set reference", "confidence consistency rules" ], "outputs": [ "conformance verdict with pass or fail and an itemised deficiency list" ], "preconditions": [ "the report revision is complete enough to evaluate", "the minimum disclosure set is published and versioned" ], "effects": [ "Produces a verdict record only; it does not block, publish, quarantine or remediate anything.", "Enforcement of the verdict, including any gate on status change, is executed by the adopting Dimension's governance process, not by this function." ], "source_refs": [ "SRC-014", "SRC-012", "SRC-055" ] }, { "id": "dep-rpt-fn-render-equivalent", "name": "Produce anchored renditions", "description": "Generate the machine-readable and human-readable renditions of one report revision, anchored to the same conclusion identifiers and evidence citations, and record an equivalence attestation.", "inputs": [ "report revision and its digest", "conclusion anchors and evidence register", "non-droppable disclosure list", "handling marking" ], "outputs": [ "machine-readable rendition", "human-readable rendition", "rendition equivalence attestation" ], "preconditions": [ "the revision has passed the disclosure-contract check", "a handling marking has been determined from the incorporated evidence" ], "effects": [ "Both renditions share the revision digest; a rendition whose digest chain breaks is marked unusable rather than silently regenerated.", "Renditions are produced but not transmitted, published to an audience or distributed by this function." ], "source_refs": [ "SRC-137", "SRC-139", "SRC-012" ] }, { "id": "dep-rpt-fn-supersede-report", "name": "Supersede a report revision", "description": "Issue a superseding revision of an existing report and mark the prior revision superseded, preserving its content and citation resolvability.", "inputs": [ "prior report revision identifier", "reason for supersession", "new frozen frame and recomputed components" ], "outputs": [ "new revision with a supersedes pointer", "superseded-by pointer written on the prior revision" ], "preconditions": [ "the prior revision exists and is not hard-deleted", "the new revision satisfies the minimum disclosure set" ], "effects": [ "The prior revision's content is never rewritten; only its status pointer is updated.", "Existing citations of the prior revision continue to resolve and return the supersession pointer." ], "source_refs": [ "SRC-012", "SRC-138" ] }, { "id": "dep-proj-fn-resolve-profile", "name": "Resolve projection profile", "description": "Select the projection profile for a requested target format and consumer audience, resolving the applicable capability matrix revision, binding map revision and canonicalization rule set, and predicting the loss set before any bytes are produced.", "inputs": [ "Target format code", "Consumer audience or purpose code", "Assertion selection criteria", "Requested profile version" ], "outputs": [ "Resolved projection profile reference", "Predicted loss entry list", "Applicable capability verdicts", "Resolved binding map revision" ], "preconditions": [ "A capability matrix revision exists for the requested target format", "The requested profile version is present in the supported version list", "A binding map revision is bound to the profile" ], "effects": [ "Produces a projection plan with a predicted loss set", "Records the resolved revision triple for later run correlation", "Raises an unsupported-version condition and returns the supported version list when no profile matches" ], "source_refs": [ "SRC-146", "SRC-151", "SRC-145" ] }, { "id": "dep-proj-fn-canonicalize", "name": "Canonicalize projection payload", "description": "Apply the profile's canonicalization rule set to an assembled projection payload - recursive key ordering, whitespace suppression, number and string normalisation, declared collection collation - and compute the algorithm-qualified content digest over the resulting bytes.", "inputs": [ "Assembled projection payload", "Canonicalization algorithm binding", "Ordering key and collation", "Encoding and byte-stability policy" ], "outputs": [ "Canonical byte sequence", "Algorithm-qualified content digest", "Deviation list where the algorithm could not be applied" ], "preconditions": [ "The payload contains no duplicate object keys and no values outside the declared value space", "The ordering key yields a total order over every projected collection", "The encoding policy is pinned for the profile" ], "effects": [ "Produces a reproducible byte sequence for identical input", "Binds an integrity digest to the payload", "Fails the run rather than emitting a non-deterministic serialization when the payload violates the declared value space" ], "source_refs": [ "SRC-122", "SRC-154" ] }, { "id": "dep-proj-fn-render-projection", "name": "Render assertion set into target format", "description": "Transform a selected set of dependency and impact assertions into the target carrier per the resolved profile, applying the mandated workaround pattern wherever the format lacks native support for n-ary, conditional, temporal or uncertain semantics, and recording every degradation as it occurs.", "inputs": [ "Resolved projection profile reference", "Selected assertion revisions", "Identity binding map", "Namespace and term binding map" ], "outputs": [ "Candidate projection payload", "Observed loss entry list", "Endpoint role binding record", "Unmapped term list" ], "preconditions": [ "Every assertion in the set carries a resolvable identifier, a direction and at least one target endpoint", "A workaround pattern is declared for every non-native capability verdict in scope", "The completeness qualifier has a declared carrier or a declared loss entry" ], "effects": [ "Produces a candidate payload held in generation storage only", "Appends one loss entry for every dropped, flattened, coerced or sentinel-substituted element", "Performs no write to any assertion endpoint and no publication" ], "source_refs": [ "SRC-013", "SRC-014", "SRC-144", "SRC-143" ] }, { "id": "dep-proj-fn-emit-loss-report", "name": "Emit projection loss report", "description": "Assemble the observed and predicted loss entries into a machine-readable report with stable problem-type identifiers, severity, recovery locators and a correlation key to the projection digest, and evaluate the blocking-loss threshold.", "inputs": [ "Observed loss entry list", "Predicted loss entry list", "Canonical content digest", "Blocking loss class list" ], "outputs": [ "Projection loss report", "Lossless claim flag", "Blocking condition verdict" ], "preconditions": [ "Each loss entry resolves to a registered problem-type identifier", "A recovery locator exists or is explicitly declared unavailable for each dropped element", "The canonical digest of the described projection is available" ], "effects": [ "Sets the lossless claim flag to false whenever any loss entry exists", "Blocks emission when a loss falls into a blocking class, pending an override decided outside this model", "Correlates the report to the run and to the projection digest" ], "source_refs": [ "SRC-120", "SRC-142", "SRC-153" ] }, { "id": "dep-proj-fn-verify-roundtrip", "name": "Verify round-trip conformance", "description": "Parse a candidate projection back into the assertion structure, compare it against the source using the profile's declared comparator, execute the conformance corpus, and issue a verdict that either substantiates or downgrades the declared round-trip class.", "inputs": [ "Candidate projection payload", "Source assertion revisions", "Round-trip comparator", "Conformance corpus revision" ], "outputs": [ "Round-trip conformance verdict", "Per-case outcome list", "Filter idempotence result", "Claim downgrade recommendation" ], "preconditions": [ "A parser exists for the target format in the profile", "The comparator and its pre-comparison canonicalization are declared", "The corpus covers multi-target, conditional, open-interval and non-asserted cases or records the coverage gap" ], "effects": [ "Substantiates or refutes the declared round-trip class with evidence", "Recommends a claim downgrade when a previously lossless profile fails", "Does not itself alter the published claim; the downgrade decision is executed by the profile owner" ], "source_refs": [ "SRC-141", "SRC-147", "SRC-154" ] }, { "id": "dep-proj-fn-record-run", "name": "Record projection run", "description": "Write the immutable run record binding source assertion revisions, profile and binding revisions, executing agent, validity time, observation time and generation time, produced candidate digests, loss report and round-trip verdict.", "inputs": [ "Projection run identifier", "Derived-from references", "Executing agent identifier", "Produced artifact digests", "Loss report and verdict references" ], "outputs": [ "Projection run record", "Derivation link set", "Write-target allowlist evidence" ], "preconditions": [ "A run identifier has been issued by the authoritative run register", "Generation time and, where different, observation time are available with an explicit offset", "The produced digests match the canonical byte sequences" ], "effects": [ "Creates an append-only, immutable run record", "Establishes derivation links from projection to source assertion revision", "Records that no publication and no endpoint mutation occurred during the run" ], "source_refs": [ "SRC-001", "SRC-155", "SRC-119" ] }, { "id": "dep-proj-fn-classify-compatibility", "name": "Classify profile change compatibility", "description": "Compare two projection profile revisions, express the difference as an ordered all-or-nothing operation list with precondition tests, and assign a compatibility class based on whether existing consumer behaviour would break.", "inputs": [ "Prior profile revision", "Proposed profile revision", "Known consumer behaviour list" ], "outputs": [ "Compatibility class", "Profile change set", "Breaking change description", "Updated supported version list" ], "preconditions": [ "Both revisions are retrievable in canonical form", "The consumer behaviour list identifies which fields and orderings consumers rely on", "The prior revision's declared round-trip class and loss set are known" ], "effects": [ "Assigns a backward-incompatible class whenever a consumer-visible removal, rename, reordering or semantic narrowing is detected", "Produces a mechanically applicable change set with precondition tests", "Yields a candidate compatibility declaration; the release decision remains with the profile owner" ], "source_refs": [ "SRC-156", "SRC-121", "SRC-150" ] }, { "id": "dep-proj-fn-package-candidate", "name": "Package candidate projection for handoff", "description": "Bundle the canonical serialization, published-form rendering, loss report, round-trip verdict, run record and compatibility declaration into a single candidate package and hand it to the publication owner, without exposing it to consumers.", "inputs": [ "Canonical byte sequence", "Published-form rendering", "Loss report", "Round-trip verdict", "Compatibility declaration" ], "outputs": [ "Candidate projection package", "Package manifest with component digests", "Handoff reference to the publication owner" ], "preconditions": [ "No unresolved blocking loss condition exists", "A round-trip verdict exists for the profile revision", "A compatibility declaration exists for the profile version" ], "effects": [ "Stores the package in candidate storage with restricted access", "Transfers the publication decision to the owner named by the adopting Dimension", "Performs no serving, no endpoint mutation and no consumer notification" ], "source_refs": [ "SRC-119", "SRC-152", "SRC-156" ] } ], "composition": [ { "target": "Endpoint / resource model of the adopting Dimension (dependent and prerequisite subjects)", "relation": "REFERENCE", "purpose": "Supply the endpoints that this mixin points at. This model carries role bindings, locators, pins and reported states only; endpoint creation, naming, custody, configuration, deployment, invocation, monitoring and disposition remain entirely with the target model.", "required": true, "source_refs": [ "SRC-005", "SRC-011" ] }, { "target": "Dependency relation-type vocabulary or classifier registry", "relation": "REFERENCE", "purpose": "Bind exactly one typed relation term per assertion. Term definition, native direction, versioning, deprecation and publication stay with the registry; this model records the term reference, the registry version and any reversal applied at import.", "required": true, "source_refs": [ "SRC-006", "SRC-012", "SRC-013" ] }, { "target": "Identifier, namespace and scheme registry authorities", "relation": "REFERENCE", "purpose": "Govern the schemes and namespaces under which assertion identifiers and endpoint locators are minted, including persistence and uniqueness guarantees. This model records the scheme and locator; assignment, registration and resolution services stay with the authority.", "required": true, "source_refs": [ "SRC-005", "SRC-008", "SRC-009" ] }, { "target": "RFC 3339 timestamp profile of the adopting Dimension", "relation": "ALIGN", "purpose": "Fix the representation of declared-at, observed-at, recorded-at, effective interval and last-verified values. The alignment supplies representation only; the separation of event time from observation and ingestion time is stated locally because RFC 3339 does not define it.", "required": true, "source_refs": [ "SRC-007" ] }, { "target": "Graph traversal, closure and impact-computation model", "relation": "REFERENCE", "purpose": "Consume assertions as edges and perform reachability, cycle detection, depth and blast-radius computation. This model supplies edge assertions, completeness qualifiers and declared propagation parameters only; it never computes, caches or scores a result.", "required": false, "source_refs": [ "SRC-013", "SRC-014", "SRC-016" ] }, { "target": "W3C PROV provenance model", "relation": "ALIGN", "purpose": "Align the assertion envelope with the qualified-influence pattern and with bundles as identified, attributable sets of descriptions, so that provenance of the assertion itself is expressible. Activity, agent and plan lifecycles remain PROV's and are not re-implemented here.", "required": false, "source_refs": [ "SRC-001", "SRC-002" ] }, { "target": "Change, release and version model of the endpoint owner", "relation": "REFERENCE", "purpose": "Own creation, promotion and withdrawal of endpoint versions and snapshots. This model records the pin and the declared compatibility range and marks a reference withdrawn when told so; it never creates, promotes, migrates or remediates a version.", "required": false, "source_refs": [ "SRC-010", "SRC-016" ] }, { "target": "Policy and authorization model of the adopting Dimension", "relation": "REFERENCE", "purpose": "Decide and enforce who may read or write assertion records. This model declares access scopes and default visibility for its own records; evaluation, enforcement and any runtime decision belong wholly to the target and are never carried out here.", "required": false, "source_refs": [ "SRC-002", "SRC-005" ] }, { "target": "Audit and event-record model of the adopting Dimension", "relation": "REFERENCE", "purpose": "Capture and retain audit trails for reads, writes, supersessions and retractions of assertion records. This model states which facts an audit record should contain; capture, storage, tamper-evidence and retention of that trail are owned by the target.", "required": false, "source_refs": [ "SRC-002", "SRC-013" ] }, { "target": "Bill-of-materials and relationship exchange formats (SPDX 3.0, CycloneDX / ECMA-424, CSAF 2.0)", "relation": "ALIGN", "purpose": "Interoperate with published relationship encodings for direction, arity, completeness and absence, and record where their conventions conflict. Alignment is claimed only where a mapping has been evidenced against a named version; no conformance to any of these formats is asserted.", "required": false, "source_refs": [ "SRC-012", "SRC-013", "SRC-015", "SRC-016" ] }, { "target": "Discovery, scanning and requirement-matching services", "relation": "REFERENCE", "purpose": "Determine which concrete endpoint satisfies an abstract requirement and report resolution outcomes. This model records the resulting bound reference and the reported state; the matching algorithm, node filters and scan schedules belong to the target.", "required": false, "source_refs": [ "SRC-011" ] }, { "target": "Generic assertion / statement mixin of the adopting Dimension", "relation": "EXTEND", "purpose": "Specialize a generic identified, attributed, time-bounded statement into a dependency assertion by adding dependent and prerequisite roles, canonical direction, pins, arity and prerequisite completeness. Generic identity, attribution and disagreement machinery is inherited from the target, not restated here.", "required": false, "source_refs": [ "SRC-002", "SRC-004" ] }, { "target": "Host subject models that adopt the WM-XCT-037 mixin", "relation": "MIX-IN", "purpose": "Any subject model may attach the edge grammar, nature and qualifier vocabulary, phase scoping and propagation licence to its own entities. The host keeps ownership of its entity identity, state and lifecycle; this mixin contributes only the relation surface.", "required": true, "source_refs": [ "SRC-018", "SRC-022" ] }, { "target": "Software component, service and package inventory model of the adopting Dimension", "relation": "REFERENCE", "purpose": "Endpoints are referenced by master-system identifier or governed global identifier. This model does not master component existence, versions, licences or inventory completeness, and does not assemble or sign bill-of-materials documents.", "required": true, "source_refs": [ "SRC-021", "SRC-015", "SRC-029" ] }, { "target": "SPDX Specification relationship and lifecycle-scope vocabularies (2.3 and 3.0.1)", "relation": "ALIGN", "purpose": "Bind local kinds and phase codes to SPDX relationship types and LifecycleScopeType values with recorded mapping strength, direction normalisation and residue. SPDX retains ownership of its vocabulary semantics, versioning and conformance criteria.", "required": false, "source_refs": [ "SRC-018", "SRC-019", "SRC-020" ] }, { "target": "CycloneDX dependency graph and compositions (ECMA-424)", "relation": "ALIGN", "purpose": "Bind to dependsOn and provides and to the compositions completeness concept, pinned by edition. Document assembly, signing, vulnerability sections and BOM lifecycle remain with that specification and its tooling.", "required": false, "source_refs": [ "SRC-021", "SRC-015" ] }, { "target": "OASIS TOSCA Version 2.0 requirement and capability model", "relation": "ALIGN", "purpose": "Reuse the requirement/capability shape, source-target directionality and occurrences as cardinality for hosting, connection, attachment and routing kinds. Node-filter matching, instantiation, sequencing and orchestration execution remain with TOSCA processors.", "required": false, "source_refs": [ "SRC-022" ] }, { "target": "W3C PROV-O influence, usage and derivation vocabulary", "relation": "ALIGN", "purpose": "Express discovered and inferred relations as qualified influence where that is the honest reading. PROV retains ownership of activity, agent and derivation provenance semantics; lineage is evidence for an edge, never an edge itself.", "required": false, "source_refs": [ "SRC-001" ] }, { "target": "Package-URL identifier standard and its type definitions (ECMA-427)", "relation": "ALIGN", "purpose": "Use purl as the governed global identifier tier for package-class endpoints and normalise to its canonical form before comparison. Type definitions and their ecosystem semantics are owned outside this model.", "required": false, "source_refs": [ "SRC-029" ] }, { "target": "Semantic Versioning 2.0.0 precedence rules", "relation": "ALIGN", "purpose": "Apply SemVer precedence only where the endpoint's ecosystem declares SemVer, and use SemVer discipline for the kind register's own published compatibility. Never treat it as a cross-ecosystem default for constraint comparison.", "required": false, "source_refs": [ "SRC-025" ] }, { "target": "Interface contract catalogue holding OpenAPI and AsyncAPI documents", "relation": "REFERENCE", "purpose": "Carry the contract URI, the referenced operation, channel or server, and the compatibility constraint. Contract content, $ref resolution, versioning and contract validation belong to the catalogue.", "required": false, "source_refs": [ "SRC-027", "SRC-028" ] }, { "target": "Build and release provenance attestation model", "relation": "REFERENCE", "purpose": "Cite attested resolved build inputs as evidence for build-time edges, including the best-effort completeness caveat. Build execution, attestation generation, signing and verification remain entirely with that model.", "required": false, "source_refs": [ "SRC-026" ] }, { "target": "Vulnerability, exploitability and reachability analysis model", "relation": "REFERENCE", "purpose": "Supply typed edges, qualifiers and propagation licences as inputs. Detection, severity scoring, reachability determination, exploitability statements and remediation tracking are owned there and are never asserted here.", "required": false, "source_refs": [ "SRC-021", "SRC-030" ] }, { "target": "Change, incident and impact-response model of the adopting Dimension", "relation": "REFERENCE", "purpose": "Provide declarative per-kind propagation licences, traversal directions and stop conditions. Graph traversal, closure computation, blast-radius ranking, owner notification, gate enforcement and retention of the durable audit trail belong to that model.", "required": true, "source_refs": [ "SRC-022", "SRC-030" ] }, { "target": "Secrets, credentials and trust-material management model", "relation": "REFERENCE", "purpose": "Reference secret and trust-anchor endpoints by opaque identifier only. Issuance, storage, rotation, revocation, value custody and any erasure execution remain entirely with that model.", "required": true, "source_refs": [ "SRC-018", "SRC-021" ] }, { "target": "Runtime observability, telemetry and inventory collection systems", "relation": "REFERENCE", "purpose": "Cite observation records as evidence for discovered edges through a resource-descriptor style reference. Traffic observation, call-graph extraction, tracing, sampling and telemetry retention are performed and owned there.", "required": false, "source_refs": [ "SRC-001", "SRC-026" ] }, { "target": "Host subject record of the adopting Dimension (any world-model entry that can carry dependencies)", "relation": "MIX-IN", "purpose": "Attach typed socio-operational dependency assertions to a host subject without altering the host's own identity, lifecycle or semantics, following the pattern of qualified relations attached to an entity.", "required": true, "source_refs": [ "SRC-001", "SRC-034" ] }, { "target": "Generic typed-relationship mixin of the adopting Dimension", "relation": "EXTEND", "purpose": "Specialize a general non-causal influence relation into named socio-operational kinds. Only the kind semantics, endpoint constraints and discrimination tests are specialized here; generic edge identity, versioning and conflict machinery remain in the general mixin.", "required": false, "source_refs": [ "SRC-001" ] }, { "target": "Technical and system dependency taxonomy (adjacent split of WM-XCT-037)", "relation": "REFERENCE", "purpose": "Cross-reference component, interface and data-flow dependency edges so that a socio-operational assertion about a provider can be linked to, without absorbing, the technical dependency graph.", "required": false, "source_refs": [ "SRC-038", "SRC-035" ] }, { "target": "Organization and party register model (W3C ORG aligned, LEI-backed)", "relation": "REFERENCE", "purpose": "Resolve actor endpoints and read structural, membership and consolidation facts used by the ownership discrimination test. Structural mastering, post lifecycle and ownership records stay with the register.", "required": true, "source_refs": [ "SRC-032", "SRC-041", "SRC-045" ] }, { "target": "Process model repository and procedure model", "relation": "REFERENCE", "purpose": "Resolve activity endpoints and read modelled flows used as evidence for process reliance. Process authoring, versioning and execution stay with the repository.", "required": true, "source_refs": [ "SRC-031" ] }, { "target": "Contract and legal-instrument model", "relation": "REFERENCE", "purpose": "Carry citations to duties, clauses and legal acts and record the asserted deontic class, without holding rule text, fulfilment state, remedies or interpretation.", "required": false, "source_refs": [ "SRC-034", "SRC-037" ] }, { "target": "Third-party arrangement and outsourcing register model", "relation": "REFERENCE", "purpose": "Resolve arrangement endpoints and receive the register extract produced here. Arrangement mastering, supervisory obligation and any submission stay with that model.", "required": false, "source_refs": [ "SRC-035", "SRC-042" ] }, { "target": "Business impact analysis, continuity and risk models", "relation": "REFERENCE", "purpose": "Supply declared dependencies and their evidence as inputs to impact and risk work. Severity, criticality scoring, recovery objectives, risk evaluation and treatment remain owned there.", "required": false, "source_refs": [ "SRC-039", "SRC-040" ] }, { "target": "Records management, privacy and audit models of the adopting Dimension", "relation": "REFERENCE", "purpose": "Receive retention periods and erasure instructions and hand over attribution entries. Retention setting, erasure execution and audit-trail integrity and review are owned there, not here.", "required": true, "source_refs": [ "SRC-035", "SRC-007" ] }, { "target": "UN/CEFACT Buy-Ship-Pay Reference Data Model vocabulary", "relation": "ALIGN", "purpose": "Align resource and counterparty strands so that a payment or settlement reliance is distinguishable from a delivery reliance and from a contractual reliance on the same party. Alignment is by mapping only; no conformance is claimed.", "required": false, "source_refs": [ "SRC-043" ] }, { "target": "Time Ontology in OWL interval relations", "relation": "ALIGN", "purpose": "Map temporal reliance codes to the standard interval relations for topology only. The alignment target asserts no causation, so no causal reading is inherited. Cited as a Candidate Recommendation Draft, so conformance is not claimed.", "required": false, "source_refs": [ "SRC-033" ] }, { "target": "ESCO occupations, skills and competences classification (ISCO-mapped)", "relation": "ALIGN", "purpose": "Bind capability and competence endpoints to governed concept identifiers instead of free-text role names, with a local extension path where no governed concept exists.", "required": false, "source_refs": [ "SRC-044" ] }, { "target": "Host subject model designated by the adopting Dimension, supplying the dependent and prerequisite entities", "relation": "MIX-IN", "purpose": "This model contributes dependency conditions to entities it does not define. The host model owns entity identity, description, classification and lifecycle; this model owns only the condition declaration and its endpoint references.", "required": true, "source_refs": [ "SRC-018", "SRC-046", "SRC-022" ] }, { "target": "SPDX 3.0.1 Core relationship, relationship-completeness and lifecycle-scope vocabularies", "relation": "ALIGN", "purpose": "Crosswalk the neutral typed kinds, completeness values and lifecycle scopes to SPDX terms for interchange. Alignment only; no conformance is claimed and unmapped terms are surfaced in the crosswalk profile.", "required": false, "source_refs": [ "SRC-018", "SRC-014", "SRC-019" ] }, { "target": "ECMA-424 CycloneDX bill-of-materials dependency-graph representation", "relation": "ALIGN", "purpose": "Crosswalk conditions to the ref and dependsOn graph form, carrying the explicit empty-declaration and opacity rules so that projection does not imply completeness.", "required": false, "source_refs": [ "SRC-015", "SRC-046" ] }, { "target": "Operating-system package relationship grammars, including Debian Policy relationship fields and RPM boolean dependencies", "relation": "ALIGN", "purpose": "Crosswalk graded strength fields, alternative and boolean operators, guards, version relations and negative relations, and record the grammar restrictions that make some neutral expressions unprojectable.", "required": false, "source_refs": [ "SRC-023", "SRC-047" ] }, { "target": "Version identity and ordering-scheme registry model for prerequisite targets", "relation": "REFERENCE", "purpose": "Supply the ordering scheme under which range endpoints are comparable. This model carries only the scheme reference and the operands; version precedence, identifier syntax and enumeration of admissible versions belong to the target.", "required": true, "source_refs": [ "SRC-053" ] }, { "target": "Dependency resolution, scheduling or constraint-evaluation engine model owned by the adopting Dimension", "relation": "REFERENCE", "purpose": "Consume declarations and produce satisfaction results. This model carries the evaluator reference, the evaluation context binding and a status snapshot; evaluation, resolution, selection among alternatives, execution and the evaluator's audit trail remain owned by the target.", "required": false, "source_refs": [ "SRC-049", "SRC-022" ] }, { "target": "Authority and decision-record model for waivers, concessions and exceptions", "relation": "REFERENCE", "purpose": "Carry the deviation decision reference, subject binding and declared validity window. Approval workflow, authority verification, revocation and decision-record retention remain owned by the target.", "required": false, "source_refs": [ "SRC-049", "SRC-052" ] }, { "target": "W3C SHACL constraint-expression and severity vocabulary", "relation": "ALIGN", "purpose": "Align the predicate and severity vocabulary and adopt the shapes-versus-report separation as the boundary pattern between declared conditions and externally produced results. No SHACL processing behaviour is imported.", "required": false, "source_refs": [ "SRC-049" ] }, { "target": "WM-XCT-037 core partition: typed dependency edge and downstream impact propagation", "relation": "MIX-IN", "purpose": "This partition attaches provenance, observation and claim-state qualification to edges asserted in the core partition. Edge typing, direction, conditionality, weighting and impact propagation remain entirely in the core; a record here is invalid without a resolvable edge reference.", "required": true, "source_refs": [ "SRC-013", "SRC-020" ] }, { "target": "Endpoint subject registries (component, service, asset and system-of-record models)", "relation": "REFERENCE", "purpose": "Claims cite endpoints by their authoritative identifiers, and artifacts additionally by content digest in the in-toto subject style. Endpoint identity, classification and lifecycle are not restated or maintained here.", "required": true, "source_refs": [ "SRC-057", "SRC-021" ] }, { "target": "Evidence artifact repository or document store owned by the adopting Dimension", "relation": "REFERENCE", "purpose": "Carries locator, digest, media type and fragment selector for supporting evidence. Payload storage, versioning, access control at the payload level, retention scheduling and deletion of evidence artifacts are owned by the repository; this partition only records reference resolvability state.", "required": true, "source_refs": [ "SRC-057", "SRC-021", "SRC-058" ] }, { "target": "W3C PROV-O provenance vocabulary", "relation": "ALIGN", "purpose": "Map claim records to Entity, Activity and Agent, and map derivation, attribution, revision and invalidation to wasDerivedFrom, wasAttributedTo, qualifiedAttribution, wasRevisionOf, wasInvalidatedBy and invalidatedAtTime. Alignment is a recorded mapping with a version pin, not a conformance claim.", "required": false, "source_refs": [ "SRC-001" ] }, { "target": "W3C SOSA/SSN observation vocabulary", "relation": "ALIGN", "purpose": "Map the observation event, feature of interest, used procedure, sampling and the phenomenonTime/resultTime distinction. Sensor and platform management remain outside this partition.", "required": false, "source_refs": [ "SRC-054" ] }, { "target": "Attestation appraisal service under RFC 9334 (Verifier, Appraisal Policy, Reference Values)", "relation": "REFERENCE", "purpose": "Supplies Evidence-side references and freshness inputs to appraisal. Appraisal policy, Attestation Results, verdicts, trust-anchor management and any enforcement action are owned by the appraisal service and are explicitly not modelled here.", "required": false, "source_refs": [ "SRC-056" ] }, { "target": "SBOM, VEX and attestation interchange bindings (SPDX 3.0.1, CycloneDX 1.6, in-toto Statement v1, OpenVEX 0.2.0)", "relation": "ALIGN", "purpose": "Version-pinned field mappings for import and export of evidence metadata: technique and completeness vocabularies, occurrence selectors, subject digests, document identity and supersession sequences. Mappings are recorded with known lossy edges rather than asserted as conformance.", "required": false, "source_refs": [ "SRC-057", "SRC-021", "SRC-013", "SRC-014", "SRC-058" ] }, { "target": "Party and agent registry (organizations, tools, individuals) of the adopting Dimension", "relation": "REFERENCE", "purpose": "Resolves asserting, observing and publishing agents and their delegation chains. Agent identity, credentialing and organisational lifecycle are owned by the registry.", "required": true, "source_refs": [ "SRC-001", "SRC-058", "SRC-060" ] }, { "target": "Adopting-Dimension retention, disposition and audit-record models", "relation": "REFERENCE", "purpose": "Owns retention schedules, legal hold, erasure execution and audit-trail semantics. This partition records the disposition instruction reference and the resulting tombstone, and emits access and change events to the audit model without defining, storing or querying audit records.", "required": true, "source_refs": [ "SRC-001", "SRC-058" ] }, { "target": "Governed vocabularies for epistemic mode, confidence scales and completeness codes", "relation": "REFERENCE", "purpose": "Holds the registered code lists and scale definitions that give recorded codes and confidence values their meaning, with version pins so historic claims stay interpretable. Vocabulary governance and publication are owned by the registry, not by this partition.", "required": true, "source_refs": [ "SRC-055", "SRC-021", "SRC-014" ] }, { "target": "Host subject model adopting the Dependency / Impact mixin", "relation": "MIX-IN", "purpose": "The mixin attaches to a host record and derives its weak identity from it; the host owns its own identity, ownership and lifecycle, and this model adds only assertion state, condition and time qualifiers over that host.", "required": true, "source_refs": [ "SRC-001", "SRC-066", "SRC-013" ] }, { "target": "Dependency typing and endpoint structure (sibling area of WM-XCT-037)", "relation": "COMPOSE", "purpose": "The sibling area supplies the dependency type vocabulary, endpoint role structure, criticality and impact propagation; this area supplies state, condition and temporal semantics over those typed assertions. Neither restates the other.", "required": true, "source_refs": [ "SRC-013", "SRC-019", "SRC-015" ] }, { "target": "Endpoint asset or service master model owning administrative and operational state", "relation": "REFERENCE", "purpose": "Carry a reference to the endpoint and to the system that authoritatively owns its administrative and operational state, plus an explicitly non-authoritative snapshot and read time. Endpoint state transitions and endpoint lifecycle remain owned by the target.", "required": true, "source_refs": [ "SRC-062", "SRC-063" ] }, { "target": "Observation and measurement model aligned to OGC OMS / ISO 19156:2023", "relation": "REFERENCE", "purpose": "Cite observations as evidence for condition determinations and copy their phenomenon time and result time. Observation production, procedure definition, sampling and monitoring remain owned by the target and are not reproduced here.", "required": false, "source_refs": [ "SRC-064", "SRC-065" ] }, { "target": "Rule evaluation and workflow enforcement service of the adopting Dimension", "relation": "REFERENCE", "purpose": "Bind declared transition guards and condition criteria to an external evaluator and store the outcome it returns. Runtime evaluation, enforcement and blocking decisions belong to the target; this model declares and records only.", "required": false, "source_refs": [ "SRC-068", "SRC-066" ] }, { "target": "Incident, change and remediation process model", "relation": "REFERENCE", "purpose": "Expose a broken or degraded condition as an input to repair and change processes and accept a back-reference to the resulting work item. Remediation, restoration action and ticketing remain owned by the target.", "required": false, "source_refs": [ "SRC-062", "SRC-065" ] }, { "target": "W3C PROV-O provenance vocabulary", "relation": "ALIGN", "purpose": "Map correction to wasRevisionOf, host scoping to specializationOf, and interval bounds to generatedAtTime and invalidatedAtTime. Alignment only; no conformance claim is made and PROV bundles are not adopted as the record model.", "required": false, "source_refs": [ "SRC-001" ] }, { "target": "SPDX 3.0.1 Core Relationship profile", "relation": "ALIGN", "purpose": "Map the assertion to a Relationship with from, to, relationshipType, startTime, endTime and completeness for exchange. Alignment is lossy: SPDX carries one validity interval and no record-time dimension, so bitemporal state cannot be projected without loss.", "required": false, "source_refs": [ "SRC-013", "SRC-019" ] }, { "target": "ISO/IEC 11179-6 registration status model", "relation": "ALIGN", "purpose": "Align the assertion state ladder with registration authority practice, including superseded and retired semantics and a named change controller. Alignment only; the ISO statuses govern registered metadata items, not assertions about running systems.", "required": false, "source_refs": [ "SRC-066", "SRC-068" ] }, { "target": "Adopting Dimension retention, disposition and erasure policy", "relation": "REFERENCE", "purpose": "Delegate retention periods, disposition schedules and any lawful erasure execution for this model's records. This model declares tombstone and readability requirements; it does not execute deletion or own retention law.", "required": true, "source_refs": [ "SRC-068", "SRC-067" ] }, { "target": "Component, asset or subject inventory model (SPDX 3.0.1 and CycloneDX 1.6 aligned)", "relation": "REFERENCE", "purpose": "Edge endpoints are carried only as resolvable references. Identity, versioning, classification and inventory completeness of the depended-on subjects stay with the inventory model; this model carries the reference, the resolution scheme binding and the failure behaviour when a reference does not resolve, and reproduces none of the inventory's lifecycle or curation functions.", "required": true, "source_refs": [ "SRC-013", "SRC-075" ] }, { "target": "Provenance model (W3C PROV aligned)", "relation": "ALIGN", "purpose": "Align assertion provenance and derivation vocabulary for edges and projections so they are exportable as PROV descriptions. The alignment is deliberately partial: PROV's non-transitivity of derivation is honoured as a constraint, while PROV's activity, agent and delegation lifecycle is not imported.", "required": false, "source_refs": [ "SRC-071", "SRC-073" ] }, { "target": "ISO/IEC 39075 GQL path-pattern semantics", "relation": "ALIGN", "purpose": "Bind the declared path restrictor and selection mode on a path result to the standard's walk, trail, acyclic and simple vocabulary so results are interpretable across engines. Query syntax, evaluation and execution planning remain in the engine.", "required": false, "source_refs": [ "SRC-074" ] }, { "target": "OWL 2 property-characteristic declarations", "relation": "ALIGN", "purpose": "Reference a declared transitive property or object property chain as the derivation basis for an inferred edge, including whether the OWL 2 global restrictions on composite properties are satisfied. Entailment computation and reasoner materialisation stay outside.", "required": false, "source_refs": [ "SRC-072" ] }, { "target": "Reliability and risk analysis model (IEC 61025 fault tree analysis and IEC 61078 reliability block diagrams aligned)", "relation": "REFERENCE", "purpose": "Cut-set and success-path results are recorded here as method-declared projections with their stated assumptions and event boundaries. Probability quantification, importance factors, risk acceptance and dependability verdicts belong to the risk model and are referenced, not reproduced.", "required": false, "source_refs": [ "SRC-077", "SRC-078" ] }, { "target": "Exception and exploitability statement model (VEX / OpenVEX aligned)", "relation": "REFERENCE", "purpose": "A propagation exclusion may cite an external exploitability or exception statement as its evidence and may carry the justification code and its scope binding. Vulnerability status determination, remediation and disclosure remain with that model.", "required": false, "source_refs": [ "SRC-076" ] }, { "target": "Snapshot and dataset versioning model", "relation": "COMPOSE", "purpose": "The immutable input snapshot that gives a projection its falsifiable identity is composed from a shared snapshot and digest facility: canonicalisation, content digest and retention of the selected edge set. This model supplies the edge-set selection and consumes the digest as the snapshot's identifier.", "required": true, "source_refs": [ "SRC-075", "SRC-079" ] }, { "target": "Validity-period mixin", "relation": "MIX-IN", "purpose": "Edge validity windows, exclusion effective and expiry times and completeness declaration intervals reuse the shared validity-period mixin rather than redefining interval semantics locally.", "required": false, "source_refs": [ "SRC-013" ] }, { "target": "Change, release and remediation execution model", "relation": "REFERENCE", "purpose": "An impact projection is delivered as an input to change planning, carrying its completeness declaration and assumptions. Deciding, approving, scheduling and executing a change, and recording that execution, belong entirely to the change model.", "required": false, "source_refs": [ "SRC-019", "SRC-030" ] }, { "target": "Host subject model applying this mixin", "relation": "EXTEND", "purpose": "The mixin specialises only the dependency and impact surface of its host subject: edge typing bound to the host's vocabulary and licence profiles written for the host's impact questions. Generic identity, authority, record lifecycle and conflict resolution remain with the host and are not duplicated here.", "required": true, "source_refs": [ "SRC-013", "SRC-019" ] }, { "target": "Dependency-assertion structure of WM-XCT-037 (typed dependency edges, edge criticality, direction and graph snapshots) - adjacent split area of the same model", "relation": "REFERENCE", "purpose": "Impact scenarios traverse dependency edges but never define, type, version, repair or retract them. This area carries only the snapshot reference with its snapshot time and hash, selectors over existing edge-type codes, and traversal parameters. Edge semantics, edge lifecycle and graph maintenance stay entirely with the dependency-assertion area; a data-quality objection raised here is a finding for that owner, not a local edit.", "required": true, "source_refs": [ "SRC-012", "SRC-001" ] }, { "target": "Change / change request model (proposal, approval authority, scheduling, implementation, rollback)", "relation": "REFERENCE", "purpose": "Carry the change reference, trigger kind and impact-specific seed parameters only. Approval, authorisation, scheduling, freeze windows, execution and rollback remain with the change model and may never be inferred from, or granted by, an impact result however severe.", "required": true, "source_refs": [ "SRC-083", "SRC-081" ] }, { "target": "Event / incident occurrence model", "relation": "REFERENCE", "purpose": "Occurred-event triggers and disruption records are referenced as trigger inputs and as subjects of retrospective observation. Detection, escalation, resolution, post-incident review and incident lifecycle remain with that model.", "required": false, "source_refs": [ "SRC-083", "SRC-081" ] }, { "target": "Risk assessment and treatment model", "relation": "ALIGN", "purpose": "Level of impact and likelihood produced here can feed a risk determination that separates threat source, threat event, vulnerability and predisposing condition. Risk appetite, tolerance thresholds, acceptance, residual-risk tracking and control selection are not modelled here, and no impact record constitutes a risk decision.", "required": false, "source_refs": [ "SRC-081", "SRC-083" ] }, { "target": "W3C PROV provenance model (PROV-O)", "relation": "ALIGN", "purpose": "Shape the scenario, the traversal run and the result as PROV Entity, Activity and Agent with qualified derivation, so that a result's dependence on its inputs is expressible in a standard vocabulary. PROV supplies no propagation, magnitude or impact semantics, and prov:wasInfluencedBy must never be read as a causal claim produced by this model. The binding version is recorded; conformance is not claimed.", "required": true, "source_refs": [ "SRC-001" ] }, { "target": "W3C Time Ontology in OWL temporal model", "relation": "ALIGN", "purpose": "Optional expression of effect horizons and the ordering of trigger, effect and observation intervals using Instant, Interval, hasBeginning, hasEnd and the Allen relations. Instant serialisation still follows RFC 3339 with seconds and an explicit offset; this model prescribes no ontology storage.", "required": false, "source_refs": [ "SRC-033", "SRC-007" ] }, { "target": "Vulnerability exploitability statement exchange (CISA VEX minimum requirements and OASIS CSAF 2.0)", "relation": "ALIGN", "purpose": "Map this model's affected-status codes and its negative-determination justification requirement onto VEX statuses and CSAF product_status and flags for the security subject, as a recorded partial mapping. Advisory document lifecycle, product-tree maintenance, remediation guidance and distribution remain with CSAF and VEX; no conformance is claimed.", "required": false, "source_refs": [ "SRC-082", "SRC-012" ] }, { "target": "Asset / configuration-item registry of the adopting Dimension", "relation": "REFERENCE", "purpose": "Seed entities and affected-set members must resolve to registry identifiers. The registry owns entity identity, ownership, classification and decommissioning; this model records an unresolvable-reference marker rather than minting or repairing an entity record.", "required": true, "source_refs": [ "SRC-083", "SRC-012" ] }, { "target": "Measurement, unit and scale model", "relation": "REFERENCE", "purpose": "Effect magnitude, trigger magnitude and likelihood or confidence qualifiers cite external scales, bands and units by identifier and version. Scale definitions, band boundaries and unit conversions are not stored, defined or converted here, and cross-Dimension comparability is not asserted.", "required": false, "source_refs": [ "SRC-081", "SRC-086" ] }, { "target": "Audit trail and evidence record model", "relation": "REFERENCE", "purpose": "Emit audit payloads for release, supersession, status change, redaction and access exception, with actor, role, time and artifact version. Audit capture, ordering, tamper-evidence, storage, retention and replay are owned there; referencing an audit record grants this model no audit-trail semantics.", "required": false, "source_refs": [ "SRC-083", "SRC-081" ] }, { "target": "Stakeholder notification and communication model", "relation": "REFERENCE", "purpose": "An affected-set register is an input to notification. Recipient selection, issuing notices, escalation paths and acknowledgement tracking are outside this model, which produces no distribution list and sends nothing.", "required": false, "source_refs": [ "SRC-083", "SRC-080" ] }, { "target": "Observation, telemetry and monitoring model", "relation": "REFERENCE", "purpose": "Retrospective outcome records may cite monitoring observations, always with observation or ingestion time held separately from event time. Signal collection, thresholds, alerting and monitor health remain with that model.", "required": false, "source_refs": [ "SRC-086", "SRC-007" ] }, { "target": "WM-XCT-037 Dependency / Impact - typed dependency edge and graph facts (adjacent split area of the same model)", "relation": "COMPOSE", "purpose": "Every criticality, impact, substitute and redundancy record attaches to a dependency edge owned there; this part stores no edge identity, direction, dependency type or topology and cites graph snapshots rather than reproducing them.", "required": true, "source_refs": [ "SRC-087", "SRC-097" ] }, { "target": "Host risk register and risk assessment model (ISO 31000 or NIST SP 800-30 style risk records)", "relation": "REFERENCE", "purpose": "Carry the reference to the risk record that consumes an impact or likelihood estimate. Risk determination, appetite, acceptance and treatment decisions remain with the host; this model contributes inputs only.", "required": false, "source_refs": [ "SRC-088", "SRC-096" ] }, { "target": "Control, treatment and mitigation record model", "relation": "REFERENCE", "purpose": "Point to mitigations that modify a local estimate and record the credited effect and residual value. Approval, execution, effectiveness testing and audit-trail semantics stay entirely with the owning system.", "required": false, "source_refs": [ "SRC-089", "SRC-096" ] }, { "target": "Business continuity and operational resilience model (impact tolerance, maximum tolerable downtime, recovery time and recovery point objectives)", "relation": "REFERENCE", "purpose": "Cite externally set tolerance and recovery thresholds when expressing duration sensitivity and time-to-impact. This model neither authors, approves nor tests those objectives.", "required": false, "source_refs": [ "SRC-039", "SRC-096" ] }, { "target": "Severity, criticality and prioritisation scheme registry (CVSS, SSVC, FMECA ranking, sector-specific scales)", "relation": "ALIGN", "purpose": "Bind every stored value to a published scheme version and its notation, without adopting any scheme as this model's canonical doctrine or asserting conformance to it.", "required": true, "source_refs": [ "SRC-091", "SRC-092", "SRC-095" ] }, { "target": "Asset, service, facility and supplier registry", "relation": "REFERENCE", "purpose": "Resolve the identity of depended-on elements, suppliers, jurisdictions and facilities used in substitution and concentration measures. Master data and its lifecycle stay in the registry.", "required": true, "source_refs": [ "SRC-094", "SRC-038" ] }, { "target": "Incident and event record model", "relation": "REFERENCE", "purpose": "Link realised disruptions back to the estimates that preceded them so estimates can be calibrated and marked stale. Incident detection, response and closure remain outside this model.", "required": false, "source_refs": [ "SRC-088", "SRC-093" ] }, { "target": "Dependability analysis method alignment (failure modes and criticality analysis, reliability block diagrams, fault trees)", "relation": "ALIGN", "purpose": "Record which published analysis method and model version produced a redundancy, independence or single-point-of-failure claim, so the claim can be reproduced or challenged on the method's own terms.", "required": false, "source_refs": [ "SRC-095", "SRC-078" ] }, { "target": "WM-XCT-037 core dependency and impact assertion structure (typed edges, traversal, impact propagation)", "relation": "MIX-IN", "purpose": "Attach governance-role semantics to each dependency or impact assertion without owning edge typing, graph construction, transitive closure or blast-radius computation, which remain in the host structure and follow patterns such as the SPDX Relationship from/to/relationshipType/completeness shape and CycloneDX dependency graphs.", "required": true, "source_refs": [ "SRC-013", "SRC-015" ] }, { "target": "Party, organization and agent identity model", "relation": "REFERENCE", "purpose": "Resolve the agent identifiers that role bindings, decisions, contests and exception grants point at. This model carries only the reference and the role qualification; minting, merging and retiring agent identities stay in the identity model.", "required": true, "source_refs": [ "SRC-001", "SRC-098", "SRC-100" ] }, { "target": "Access-control and authorization policy model (policy administration, decision, enforcement and information points)", "relation": "REFERENCE", "purpose": "Publish role bindings, incompatible-duty declarations, sensitivity classifications and purpose or jurisdiction qualifiers as attributes for external policy evaluation. Rendering permit or deny decisions, enforcing them and discharging obligations or advice are owned entirely by that model; nothing here grants or denies access.", "required": true, "source_refs": [ "SRC-103", "SRC-104" ] }, { "target": "Audit trail and evidence record model", "relation": "REFERENCE", "purpose": "Emit correlation identifiers and governance events for capture in the audit trail. Log integrity, tamper-evidence, non-repudiation, audit retention and audit reporting are owned by that model; this model stores governance outcomes, not audit records.", "required": true, "source_refs": [ "SRC-104", "SRC-099" ] }, { "target": "Records retention, disposition and legal-hold model", "relation": "REFERENCE", "purpose": "Carry a retention-class reference and a legal-hold marker on this model's governance records. Schedule approval, disposition execution, retention extension for litigation, hold release and unauthorized-disposition reporting are owned by that model and the adopting Dimension's records authority.", "required": true, "source_refs": [ "SRC-107", "SRC-108" ] }, { "target": "Privacy and personal-data processing model", "relation": "REFERENCE", "purpose": "Refer purpose-limitation compatibility assessment, lawful-basis determination, controller and processor allocation, and records of processing activities outward, while requiring a purpose qualifier and a personal-data presence flag on every governance act recorded here.", "required": true, "source_refs": [ "SRC-107", "SRC-101" ] }, { "target": "Jurisdiction and territorial-scope registry", "relation": "REFERENCE", "purpose": "Supply the coded jurisdiction values used as mandatory qualifiers, so that the model can require a jurisdiction without defining jurisdictions, asserting precedence between them or embedding polity doctrine.", "required": true, "source_refs": [ "SRC-101", "SRC-107" ] }, { "target": "Risk management, change and release management models", "relation": "REFERENCE", "purpose": "Hold the remediation plans, conditions with due dates and risk-treatment decisions that exception grants and conditional approvals point at. This model records the governance outcome and its accountable authority, not the treatment methodology or its tracking.", "required": true, "source_refs": [ "SRC-105", "SRC-038" ] }, { "target": "W3C PROV-O qualified attribution and delegation pattern", "relation": "ALIGN", "purpose": "Align role binding on the qualified-attribution pattern (agent, role, influence) and delegation on acted-on-behalf-of, so governance provenance is exchangeable. Alignment only: no conformance to PROV-O is claimed without a published mapping and validation evidence.", "required": false, "source_refs": [ "SRC-001" ] }, { "target": "SPDX 3.0.1 Core model (Element, CreationInfo, Annotation, Relationship stance semantics)", "relation": "ALIGN", "purpose": "Align issuer attribution on CreationInfo, independently attributed review commentary on Annotation, and the asserted-none versus no-assertion distinction on the SPDX none and no-assertion element semantics. Alignment only; no SPDX conformance is claimed.", "required": false, "source_refs": [ "SRC-013", "SRC-098", "SRC-099" ] }, { "target": "W3C ODRL Vocabulary and Expression 2.2 party functions and constraint operands", "relation": "ALIGN", "purpose": "Align observer and informed-party archetypes on ODRL party functions and align purpose and jurisdiction qualifiers on the purpose and spatial constraint left operands, for exchange with policy expression tooling. Alignment only; this model expresses no permissions, prohibitions or duties.", "required": false, "source_refs": [ "SRC-101" ] }, { "target": "Adopting Dimension governance role archetype extension package", "relation": "EXTEND", "purpose": "Allow a Dimension to specialise the seven generic archetypes with local roles under a declared parent archetype and its own registration policy, without duplicating the generic identity, delegation, contest or exception machinery defined here.", "required": false, "source_refs": [ "SRC-102", "SRC-038" ] }, { "target": "Adjacent WM-XCT-037 split: typed dependency vocabulary and impact classification semantics", "relation": "COMPOSE", "purpose": "The governance contract binds a vocabulary version by reference so that canonicalization, validation and change classes operate over typed edges without this split defining or owning any dependency type or impact scale.", "required": true, "source_refs": [ "SRC-013", "SRC-015" ] }, { "target": "SPDX 3.0.1 Core Relationship model and RelationshipType vocabulary", "relation": "ALIGN", "purpose": "Align the first-class edge structure (from, to, relationship type, start and end time, completeness, explicit none versus no-assertion) so dependency records can be exchanged with SPDX documents; alignment only, with no claim of certified conformance and no adoption of SPDX document lifecycle.", "required": false, "source_refs": [ "SRC-013" ] }, { "target": "ECMA-424 CycloneDX Bill of Materials Specification (CycloneDX v1.7)", "relation": "ALIGN", "purpose": "Align dependency-graph and evidence structures for supply-chain interchange and carry BOM references as evidence; BOM generation, vulnerability analysis and composition semantics remain external.", "required": false, "source_refs": [ "SRC-015" ] }, { "target": "W3C PROV-O provenance ontology", "relation": "MIX-IN", "purpose": "Reuse Entity, Activity and Agent with attribution, derivation and revision properties to express who asserted an edge and from what, instead of inventing a local provenance vocabulary.", "required": true, "source_refs": [ "SRC-001" ] }, { "target": "External shapes or schema validation engine and its shapes graph (SHACL-style)", "relation": "REFERENCE", "purpose": "Carry the validation profile reference, its digest and the resulting report; execution of validation, and any decision taken on its outcome, remains entirely with the external engine and its consumers.", "required": true, "source_refs": [ "SRC-049" ] }, { "target": "SLSA build provenance and in-toto style attestations", "relation": "REFERENCE", "purpose": "Reference build attestations by subject digest as supporting evidence for asserted dependency edges; build execution, builder trust evaluation and signature verification are not performed here.", "required": false, "source_refs": [ "SRC-117" ] }, { "target": "Adopting-Dimension retention, disposition and erasure policy model", "relation": "REFERENCE", "purpose": "Bind each record to a retention class and governing policy reference and issue disposition requests; the policy definition and the execution of erasure in downstream stores are owned by that model and the adopting Dimension.", "required": true, "source_refs": [ "SRC-038", "SRC-118" ] }, { "target": "Adopting-Dimension authorization policy and decision point", "relation": "REFERENCE", "purpose": "Expose decision inputs such as tenant partition, owner package and sensitivity label to an external decision point; this model never evaluates policy, issues decisions or enforces them.", "required": true, "source_refs": [ "SRC-038" ] }, { "target": "Adopting-Dimension audit and event-log model", "relation": "REFERENCE", "purpose": "Emit audit events for governed operations with a declared minimum field set; the audit record structure, immutability guarantees, storage and retention of the trail are owned by that model.", "required": true, "source_refs": [ "SRC-038", "SRC-001" ] }, { "target": "W3C DCAT-3 catalogue record and versioning vocabulary", "relation": "ALIGN", "purpose": "Align version-lineage properties and the separation of resource dates from catalogue registration dates so external catalogues can index dependency and impact record versions without this model implementing a registry.", "required": false, "source_refs": [ "SRC-118" ] }, { "target": "Namespace assignment authority under URN or IRI governance", "relation": "REFERENCE", "purpose": "Carry the delegated namespace binding and persistence commitment used for governed identifiers; identifier allocation services and resolution infrastructure are operated externally.", "required": true, "source_refs": [ "SRC-116" ] }, { "target": "NIST SP 800-161 Rev. 1 cybersecurity supply-chain risk management practices", "relation": "ALIGN", "purpose": "Position governed dependency and downstream-impact records as traceable inputs to supplier and component criticality analysis; risk assessment, mitigation selection and organisational control implementation stay outside this model.", "required": false, "source_refs": [ "SRC-038" ] }, { "target": "WM-XCT-037 dependency edge and impact-assessment structure (companion split area)", "relation": "COMPOSE", "purpose": "Commands take their subject payload - endpoints, relationship or impact type, lifecycle scope, completeness and impact fields - from the structural area. This area contributes only command, transition, history and effect semantics and restates none of that structure.", "required": true, "source_refs": [ "SRC-013", "SRC-019" ] }, { "target": "Adopting-Dimension authorization and policy-decision model (PDP/PEP separation)", "relation": "REFERENCE", "purpose": "Carry an authorization decision reference, the deciding authority and the policy identifier on each state-changing command, and fail closed on anything other than a permit. Decision rendering, attribute resolution, obligations and enforcement remain owned by the policy model.", "required": true, "source_refs": [ "SRC-103" ] }, { "target": "Audit-trail and evidence record model of the adopting Dimension", "relation": "REFERENCE", "purpose": "Emit an audit hook carrying command identifier, actor reference, prior and resulting version tokens and correlation identifier. Audit record content, immutability, storage and retention of audit evidence belong entirely to that model.", "required": true, "source_refs": [ "SRC-001", "SRC-123" ] }, { "target": "W3C PROV-O provenance vocabulary", "relation": "ALIGN", "purpose": "Map a command to an activity associated with responsible agents, the produced version to generation, revision to derivation, and retirement or correction to invalidation, so provenance is exportable. PROV-O owns its vocabulary; no conformance is claimed.", "required": false, "source_refs": [ "SRC-001" ] }, { "target": "CloudEvents v1.0.2 event envelope", "relation": "ALIGN", "purpose": "Bind emitted change signals to the context attributes id, source, type, subject and time, honouring the uniqueness of source plus id. Transport bindings, subscription, delivery guarantees, ordering and retry stay outside.", "required": false, "source_refs": [ "SRC-123" ] }, { "target": "SPDX 3.0.1 Core Relationship vocabulary and lifecycle scopes", "relation": "ALIGN", "purpose": "Project declared dependency statements to and from relationship elements with relationship type, completeness and lifecycle scope, including the asserted-none versus no-assertion distinction. SPDX owns that vocabulary and has no approval lifecycle of its own.", "required": false, "source_refs": [ "SRC-013", "SRC-019" ] }, { "target": "HTTP interface binding based on RFC 9110 conditional requests", "relation": "REFERENCE", "purpose": "Where the model is exposed over HTTP, the expected-version token binds to a validator supplied in a precondition header and conflict outcomes bind to the corresponding status signals. The binding is declared by the interface layer; the model stays protocol-neutral.", "required": false, "source_refs": [ "SRC-119", "SRC-124" ] }, { "target": "Adopting-Dimension retention, disposition and records-management policy", "relation": "REFERENCE", "purpose": "This area declares what must survive as immutable history and the shape of a tombstone; scheduling and executing destruction, legal holds and their release are owned and performed by the retention policy.", "required": true, "source_refs": [ "SRC-124", "SRC-001" ] }, { "target": "Party, actor and observing-agent identity model", "relation": "REFERENCE", "purpose": "Declarers, reviewers, approvers and automated observers are identified by reference only; authentication, credential issuance and organizational mastering are owned by the party model.", "required": true, "source_refs": [ "SRC-001", "SRC-054", "SRC-103" ] }, { "target": "Endpoint models for the source and target of a dependency (systems, components, packages, assets)", "relation": "REFERENCE", "purpose": "Endpoint references are resolved read-only to check existence at admission time. No command in this area may create, modify, retire or delete an endpoint record, and endpoint lifecycles are never mirrored here.", "required": true, "source_refs": [ "SRC-013", "SRC-103" ] }, { "target": "Host subject model adopting the Dependency / Impact mixin", "relation": "MIX-IN", "purpose": "Attach the query-operation contract to any adopting subject model so its entities can be used as endpoints of dependency reads. The host owns entity identity, lifecycle and domain semantics; this mixin adds only the read surface and result-integrity obligations.", "required": true, "source_refs": [ "SRC-013", "SRC-132" ] }, { "target": "Dependency assertion authoring and lifecycle area of WM-XCT-037 (adjacent split area)", "relation": "REFERENCE", "purpose": "Consume asserted edges read-only. This pass carries assertion references, derivation class and provenance pointers, but does not define edge-type taxonomy, assertion creation, supersession, retirement or conflict resolution.", "required": true, "source_refs": [ "SRC-013", "SRC-014" ] }, { "target": "Adopting Dimension graph storage and query-engine model", "relation": "REFERENCE", "purpose": "Bind the contract to an executing engine and dialect. Carries the engine reference, dialect binding and the mapping of declared path modes and scopes onto engine features; owns no storage, indexing, planning or execution semantics.", "required": true, "source_refs": [ "SRC-129", "SRC-135" ] }, { "target": "Adopting Dimension authorization and policy-decision model (XACML-style PDP)", "relation": "REFERENCE", "purpose": "Carry the authorization decision reference and the exclusion summary that shapes a result. Policy evaluation, obligation handling and enforcement remain entirely with the decision and enforcement points.", "required": true, "source_refs": [ "SRC-103", "SRC-034" ] }, { "target": "Adopting Dimension audit and access-log model", "relation": "REFERENCE", "purpose": "Emit a correlation reference joining an issued result to the external audit record, and declare the minimum fields that record needs. Audit structure, retention and tamper-evidence are owned there.", "required": true, "source_refs": [ "SRC-103", "SRC-001" ] }, { "target": "External dependency-health assessment services (deps.dev API and the OpenSSF Scorecard results it surfaces)", "relation": "REFERENCE", "purpose": "Carry typed references to externally published health indicators with assessor, method version, observation time and binding target. No indicator is recomputed, thresholded or converted into a verdict here.", "required": false, "source_refs": [ "SRC-133" ] }, { "target": "Vulnerability and exploitability assertion model (CSAF v2.0 documents)", "relation": "REFERENCE", "purpose": "Let impact reads cite product status assertions and their justifications. Status determination is owned by the advisory producer; an entity absent from every status group is treated as no assertion, never as not-affected.", "required": false, "source_refs": [ "SRC-012" ] }, { "target": "SPARQL 1.1 Query Language dataset-scope and property-path semantics", "relation": "ALIGN", "purpose": "Align scope resolution, path traversal, inverse traversal and the ordering prerequisite for paging with an existing normative read semantics. Alignment only: no conformance is claimed, and the fact that arbitrary-length matching returns connectivity without enumerating paths must be reconciled in the projection.", "required": false, "source_refs": [ "SRC-129" ] }, { "target": "ISO/IEC 39075:2024 GQL path patterns and path modes", "relation": "ALIGN", "purpose": "Align the path-mode vocabulary (walk, trail, simple, acyclic) and the notion of explicit path finding. Marked as an alignment claim rather than verified conformance, because the standard text is paywalled and was checked only through an ISO/IEC JTC 1 information article.", "required": false, "source_refs": [ "SRC-135" ] }, { "target": "SPDX 3.0.1 Relationship and RelationshipCompleteness vocabulary", "relation": "ALIGN", "purpose": "Align directed edge shape (from, to, relationshipType, startTime, endTime) and the completeness code system (complete, incomplete, noAssertion) used by this model's completeness declaration.", "required": false, "source_refs": [ "SRC-013", "SRC-014" ] }, { "target": "CycloneDX 1.6 (ECMA-424) dependencies and compositions aggregate", "relation": "ALIGN", "purpose": "Align typed asymmetric dependency edges and partition-qualified completeness disclosure, including the explicit unknown value for best-effort results whose completeness is inconclusive.", "required": false, "source_refs": [ "SRC-132" ] }, { "target": "OGC API - Features Part 1: Core paging conventions and IETF RFC 8288 Web Linking", "relation": "ALIGN", "purpose": "Align returned-count and matched-count disclosure including the permission to omit an unknown matched count, server-imposed limits, and registered link relation types for continuation and supersession links.", "required": false, "source_refs": [ "SRC-130", "SRC-006" ] }, { "target": "IETF RFC 7089 Memento datetime negotiation", "relation": "ALIGN", "purpose": "Align as-of read behaviour: a requested datetime is resolved by best match to an available prior state and the response states the datetime actually returned. Header syntax and HTTP-date formats belong to the interface projection, not to this model.", "required": false, "source_refs": [ "SRC-131" ] }, { "target": "Host subject model adopting the WM-XCT-037 mixin", "relation": "MIX-IN", "purpose": "The reporting surface attaches to a host model that supplies the subject entities, their identifiers and their read scopes. This surface never defines the subject entities it reports on.", "required": true, "source_refs": [ "SRC-013", "SRC-140" ] }, { "target": "Adjacent dependency-graph assertion surface of WM-XCT-037 (typed edges, strengths, edge lifecycle)", "relation": "COMPOSE", "purpose": "Reports consume typed edges, dependency strengths and edge assertion metadata from that surface and add only traversal filters, propagation mappings and reporting obligations. Edge typing and assertion lifecycle are not restated here.", "required": true, "source_refs": [ "SRC-013", "SRC-023", "SRC-015" ] }, { "target": "Adopting-Dimension component or asset inventory model (snapshot source of record)", "relation": "REFERENCE", "purpose": "Supplies the immutable graph snapshot a report binds to, together with the snapshot's own completeness aggregate. This surface carries only a resolvable reference, a corroborating digest, separated time values and the restated completeness.", "required": true, "source_refs": [ "SRC-015", "SRC-136" ] }, { "target": "Adopting-Dimension change approval / change enablement model", "relation": "REFERENCE", "purpose": "Receives readiness and impact reports as inputs and owns the decision to permit a change, the approving authority and the decision record. No approval field, approver or outcome is stored here.", "required": true, "source_refs": [ "SRC-140" ] }, { "target": "Adopting-Dimension audit and event-record model", "relation": "REFERENCE", "purpose": "Receives the issuance, supersession, tombstone and disclosure-recomputation records this surface is required to emit, and owns their storage, protection, retention and evaluation.", "required": true, "source_refs": [ "SRC-001", "SRC-012" ] }, { "target": "Adopting-Dimension records-retention and disposition model", "relation": "REFERENCE", "purpose": "Owns retention periods, legal holds and physical erasure for report records. This surface owns only the tombstone contract and the requirement that a disposition be recorded.", "required": true, "source_refs": [ "SRC-012" ] }, { "target": "Adopting-Dimension remediation / corrective action model", "relation": "REFERENCE", "purpose": "Owns selection, application, restart handling and verification of mitigations. A mitigation-reference report carries citations and applicability conditions into this model and stops there.", "required": false, "source_refs": [ "SRC-012", "SRC-058" ] }, { "target": "Adopting-Dimension notification delivery / messaging transport model", "relation": "REFERENCE", "purpose": "Owns addressing, transmission, delivery confirmation and receipt tracking for notification-content drafts produced here. No transport identifier, endpoint or delivery state is modelled in this surface.", "required": false, "source_refs": [ "SRC-139", "SRC-012" ] }, { "target": "Adopting-Dimension risk scoring / severity model", "relation": "REFERENCE", "purpose": "Owns scoring algorithms and published severity values. Scores enter a report by reference with their scoring system named and are never recomputed here.", "required": false, "source_refs": [ "SRC-012" ] }, { "target": "Adopting-Dimension access control and identity model", "relation": "REFERENCE", "purpose": "Executes read-scope grants, revocations and emergency time-boxed access for report renditions. This surface states the default rule and the exceptions but performs no grant.", "required": true, "source_refs": [ "SRC-139" ] }, { "target": "PROV-O: The PROV Ontology (W3C Recommendation)", "relation": "ALIGN", "purpose": "Alignment target for evidence attribution and derivation using Entity, Activity, Agent, wasGeneratedBy, wasDerivedFrom and wasAttributedTo. Alignment only; no conformance is claimed without recorded mapping evidence.", "required": false, "source_refs": [ "SRC-001" ] }, { "target": "SPDX 3.0.1 Relationship class and RelationshipCompleteness vocabulary", "relation": "ALIGN", "purpose": "Alignment target for edge citation and for per-relationship completeness assertions of complete, incomplete and no-assertion.", "required": false, "source_refs": [ "SRC-013", "SRC-014" ] }, { "target": "ECMA-424 CycloneDX Bill of Materials Specification (compositions and dependency graph)", "relation": "ALIGN", "purpose": "Alignment target for scoped coverage aggregates and for dependency graph edges including provided or virtual capabilities. Granularity differences with SPDX completeness are recorded as a conflict.", "required": false, "source_refs": [ "SRC-015", "SRC-136" ] }, { "target": "OASIS CSAF 2.0 and the OpenVEX Specification", "relation": "ALIGN", "purpose": "Alignment targets for revisioned advisory tracking, under-investigation status, and the requirement that a reassuring conclusion carry an explicit justification or impact statement.", "required": false, "source_refs": [ "SRC-012", "SRC-058" ] }, { "target": "OASIS SARIF 2.1.0 graph, graphTraversal and edgeTraversal objects", "relation": "ALIGN", "purpose": "Alignment target for representing a replayable path through a graph and for pairing a human-readable message with machine-readable result properties.", "required": false, "source_refs": [ "SRC-137" ] }, { "target": "OASIS STIX 2.1 confidence, Opinion, revoked and validity properties", "relation": "ALIGN", "purpose": "Alignment target for named confidence scales, retention of divergent assessments, and expression of assertion withdrawal and validity windows.", "required": false, "source_refs": [ "SRC-138" ] }, { "target": "FIRST Traffic Light Protocol 2.0", "relation": "ALIGN", "purpose": "Alignment target for the handling markings carried on report renditions and notification-content drafts, including marking placement requirements.", "required": false, "source_refs": [ "SRC-139" ] }, { "target": "W3C Data Quality Vocabulary", "relation": "ALIGN", "purpose": "Alignment target for expressing coverage and completeness as quality measurements against named metrics. It is a Working Group Note, so this is an expression alignment and not a conformance claim.", "required": false, "source_refs": [ "SRC-055" ] }, { "target": "Dependency / Impact assertion-core (typed relation, endpoint roles, conditions, confidence, lifecycle)", "relation": "REFERENCE", "purpose": "Obtain the assertion identifier, revision, relation type, direction, endpoint roles, completeness qualifier and validity interval to be projected. This area carries only the reference, the carrier binding and the projection-specific parameters; the assertion's own admission, retraction and state transitions remain in the core area.", "required": true, "source_refs": [ "SRC-013", "SRC-014" ] }, { "target": "Host domain models that record dependency or impact assertions about their own subjects", "relation": "MIX-IN", "purpose": "Supply projection-operation contracts to any host model that must render its dependency or impact assertions into an external carrier, without the host redefining canonicalization, loss reporting or compatibility classification.", "required": false, "source_refs": [ "SRC-119", "SRC-146" ] }, { "target": "SPDX 3.0.1 Core profile Relationship and RelationshipCompleteness vocabularies", "relation": "ALIGN", "purpose": "Bind local relation types, direction and completeness semantics to an externally governed relationship vocabulary as an alignment. Term definitions, versioning and change control stay with the issuing body; no conformance is claimed without cited test evidence.", "required": false, "source_refs": [ "SRC-013", "SRC-014", "SRC-141" ] }, { "target": "ECMA-424 CycloneDX Bill of Materials Standard", "relation": "ALIGN", "purpose": "Provide a second, independently governed domain carrier for component dependency information so that no single consortium format is treated as canonical. Only the mapping and its gaps are carried locally.", "required": false, "source_refs": [ "SRC-015" ] }, { "target": "Provenance and derivation model aligned to PROV-O", "relation": "ALIGN", "purpose": "Express that a projection was derived from a source assertion revision by an activity attributed to an agent, using established derivation and generation predicates. Qualified-influence machinery, agent responsibility and provenance lifecycle remain with the provenance model.", "required": false, "source_refs": [ "SRC-001" ] }, { "target": "Publication and release-approval model of the adopting Dimension", "relation": "REFERENCE", "purpose": "Hand a candidate projection package to the owner who decides publication. This model carries the handoff reference and the compatibility declaration only; approval decisions, approver identity, release records and any resulting audit trail are owned by the target.", "required": true, "source_refs": [ "SRC-119", "SRC-156" ] }, { "target": "Access-control and authorization model of the adopting Dimension", "relation": "REFERENCE", "purpose": "Carry the sensitivity marking, audience code and redaction flag that a downstream authoriser needs. Evaluating authorisation, enforcing it at an interface and recording the access event are owned by the target model.", "required": true, "source_refs": [ "SRC-152", "SRC-119" ] }, { "target": "Namespace and identifier governance registry of the adopting Dimension", "relation": "REFERENCE", "purpose": "Resolve prefixes, namespace IRIs and the authoritative identifier scheme used to identify assertions, profiles and binding maps. Namespace allocation and retirement remain with the registry.", "required": true, "source_refs": [ "SRC-145", "SRC-149" ] }, { "target": "Generic serialization and canonicalization contract for Vercy artifacts", "relation": "EXTEND", "purpose": "Specialize a generic artifact serialization contract with the dependency-specific concerns of direction, endpoint roles, completeness qualifiers and n-ary or conditional degradation. Generic identity precedence, timestamp rules and conflict handling are not duplicated here.", "required": false, "source_refs": [ "SRC-122", "SRC-121" ] }, { "target": "Storage and interface projections (Git repository, document store, HTTP API, MCP server)", "relation": "REFERENCE", "purpose": "Name the concrete carriers whose native addressing, type fidelity, validator and versioning rules a projection must respect. Transport, connection lifecycle, indexing and administration are owned by those models and are not modelled here.", "required": false, "source_refs": [ "SRC-154", "SRC-153", "SRC-152", "SRC-119" ] } ], "serviceLayers": { "dimension": { "owner_package_requirements": [ "Each namespace partition of dependency and impact records must have exactly one accountable owner package inside the adopting Dimension, named in a namespace and tenancy registration manifest together with the delegated assignment authority and its persistence and non-reassignment commitment.", "The owner package must publish and version a canonicalization profile and a projection profile with loss disclosure for every projection target it exposes, and must not declare any storage format or interface as canonical.", "The owner package must bind, by reference, an external retention and disposition policy owner, an external authorization decision point and an external audit system before any record is created, and must record those references in the operating-surface capability descriptor.", "The owner package must name the validation profiles in force, their versions and digests, and must state which external engine executes validation; it may not assert conformance to any external standard without a retained validation report or alignment evidence.", "The owner package must maintain the register of accepted deviations for warning-severity and informational validation results, with a named accountable role and a review interval." ], "namespace_guidance": "Governed identifiers are assigned under either a URN namespace identifier or an HTTP base IRI whose assignment authority is formally delegated and committed to persistence and non-reassignment. Namespace-specific strings are assigned and managed consistently within the partition and may use hierarchical separators; resolution, service and fragment parameters are held separately and are excluded from identifier equality comparison. Every identifier is namespace-qualified before cross-partition exchange, and reserved or prohibited prefixes are declared in the namespace manifest. Identifiers are opaque: they must contain no date, version, status or content-digest component, since all four change independently of the thing identified. Tenancy is a partition of the identifier and canonicalization space only and confers no access rights.", "registry_links": [ "Catalogue alignment for version lineage and registration metadata: W3C DCAT-3 dcat:previousVersion, dcat:hasCurrentVersion, dcat:version and dcat:CatalogRecord with dcterms:issued and dcterms:modified (https://www.w3.org/TR/vocab-dcat-3/).", "Identifier namespace governance: RFC 8141 Uniform Resource Names, namespace identifiers and delegated assignment authority (https://www.rfc-editor.org/info/rfc8141).", "Supply-chain interchange identifier spaces for endpoint references: SPDX 3.0.1 Element identifiers (https://spdx.github.io/spdx-spec/v3.0.1/model/Core/Classes/Relationship/) and ECMA-424 CycloneDX component and dependency references (https://ecma-international.org/publications-and-standards/standards/ecma-424/)." ] }, "canon_and_patch": { "canonicalization_rules": [ "Canonical semantics live in the abstract record. Canonicalization is defined per shape family: tree-shaped projections use the JSON Canonicalization Scheme (RFC 8785) with lexicographic property sorting, whitespace removal, ECMAScript number serialization and UTF-8 output; graph-shaped projections use RDFC-1.0 (W3C Recommendation, 21 May 2024) for deterministic blank-node labelling.", "Tree-shaped canonical input must satisfy the I-JSON constraints the scheme requires: no duplicate property names, no NaN or Infinity, and numbers within IEEE 754 double precision. Any quantity requiring greater precision or longer integers, including high-precision impact scores, must be carried as a string, and the numeric encoding must be declared per field.", "The canonicalization scheme performs no Unicode normalization and preserves strings as received. Each canonicalization profile must therefore declare the normalization form applied upstream, or state explicitly that none is applied, and must record the resulting false-difference risk for text comparison.", "Digest equality is asserted only within a single shape family under a single named canonicalization profile. Cross-shape or cross-profile digest equality is never claimed, and every digest is carried together with the algorithm, encoding and profile reference that produced it.", "Every projection target has a published projection profile containing a complete loss inventory (carried, transformed, dropped), a reversibility flag per transformation, a round-trip status with an evidencing test reference, and the representation chosen for explicit no-relationship versus no-assertion. Silent degradation without disclosure is a contract violation." ], "patch_rules": [ "The default change grammar is the operation-sequence patch of RFC 6902 (add, remove, replace, move, copy, test) with pointer-addressed targets; if any operation or normative requirement fails, the whole patch is rejected and the record is left unchanged.", "Merge-patch grammar (RFC 7396) is admissible only for object-shaped subtrees that contain no explicit null values and require no partial array modification, because in that grammar null means removal and arrays are always replaced wholesale. Its use must be justified per change set.", "Graph-shaped records change by a canonicalized add and remove quad set computed under RDFC-1.0, so that blank-node relabelling is not mistaken for substantive change.", "Every change set carries the expected pre-state digest and the resulting post-state digest. The pre-state digest, or an equivalent test-operation assertion, is a hard precondition; a mismatch is a conflict, never an occasion for a best-effort merge.", "A change set is a proposal. Commitment is a separate mutation operation that produces a new immutable version linked to its predecessor, emits an audit event to the externally owned audit system, and records the declared compatibility class.", "Concurrent-edit reconciliation beyond digest-precondition conflict detection is out of scope and is declared a gap; no automatic merge semantics are defined." ], "compatibility_rules": [ "Every change declares one compatibility class: additive (new optional elements or new edges, existing consumers unaffected), corrective (a previously asserted value is replaced because it was wrong, lineage preserved), or restrictive (elements removed or narrowed, endpoint semantics changed, or an edge retracted) which is breaking for consumers.", "Restrictive changes require a consumer notification flag, retention of the superseded version, and an explicit statement of the affected element list; they must not be issued silently as corrective changes.", "Version lineage is expressed with previous-version and current-version links so that catalogues and consumers can traverse the chain; the record's registration timestamps are kept distinct from the dates of the facts the record asserts.", "Profile artifacts (canonicalization, projection, validation) are immutable once published and digest-bound; a change to any of them produces a new profile version, and records validated or canonicalized under the old version keep their reference to that version.", "A conformance claim is bounded to a named profile, a named version and a named validation run; it does not extend to other profiles, other versions or other record sets, and alignment to an external standard is recorded as alignment rather than certified conformance." ] }, "artifact_rules": { "identity_priority": [ "Authoritative master-system identifier: the identifier assigned by the system of record that owns the dependency endpoint or the impact assessment, adopted unchanged where one exists.", "Governed global identifier or IRI: a URN or HTTP IRI assigned under a formally delegated namespace authority committed to persistence and non-reassignment (RFC 8141).", "Locally minted surrogate: a UUID assigned by the adopting Dimension, with UUIDv7 preferred per RFC 9562 for time-ordered sorting, or a ULID where the adopting Dimension has standardised on it; used only when neither higher tier is available.", "Never an identifier: a date or timestamp, a version tag, a status value, a content digest, or a concatenation of endpoint identifiers. Content digests bind integrity, not identity, and endpoint pairs are not unique because two elements may be related more than once." ], "timestamp_rule": "All time values use RFC 3339 date-time with mandatory seconds and an explicit numeric offset or the Z designator; a bare local time with no offset is invalid. Event time (when the asserted dependency or impact fact holds, including the edge validity start and end) and observation or ingestion time (when this model captured or last confirmed the assertion) are recorded in separate fields and are never collapsed, because a dependency asserted today may have held for years. Observation or ingestion time is mandatory on every governed record; event time is optional but must be present whenever the two differ or the difference is material. Where the instant is known in UTC but the true local offset is unknown, use the -00:00 unknown-local-offset convention rather than falsely asserting Z. Leap-second value 60 is accepted on input; any normalization of it, or of a recorded offset to UTC, must be disclosed in the relevant projection profile.", "serial_naming_rule": "Serial artifacts (change sets, validation reports, provenance records, integrity manifests, tombstone and disposition records) are identified by a minted UUIDv7 or an authoritative master-system serial, never by a name containing a date, sequence-of-the-day or status word. Ordering is derived from the artifact's recorded timestamp field plus, where relevant, the pre-state digest chain; human-facing labels may display a date but the identifier must not embed one. Each serial artifact names its subject by record identifier and content digest so that it remains resolvable after the subject changes or is retired.", "integrity_rule": "Every artifact carries a content digest over its canonical form, together with the digest algorithm, encoding and the canonicalization profile reference used. Serial artifacts additionally bind the digests of their subjects (the record versions they cover), so a report or attestation cannot be silently re-pointed at different content. Published profile artifacts are immutable: correction produces a new version with a previous-version link, never an in-place edit. Digest verification within this model is limited to comparing recorded digests against recomputed canonical forms; signature verification, trust-root evaluation and attestation validation are external and must not be inferred from a digest match." }, "policies": [ "Format and interface neutrality: no serialization, database or protocol is canonical. Any concrete form is a projection governed by a published projection profile with a complete loss inventory, and a consumer must be able to obtain the loss report alongside the projection.", "Falsifiability over assertion: conformance is claimed only against a named profile, version and validation run; alignment to an external standard is recorded as alignment with evidence, and unresolved boundaries are recorded as gaps rather than presented as settled.", "Non-authority: this model exposes decision inputs, policy references and evidence references, but never evaluates policy, issues authorization decisions, enforces outcomes, executes erasure in downstream stores or stores the audit trail. Referencing an evaluator, enforcement engine or audit system confers no ownership of its semantics.", "Immutable lineage: every record version, profile version and serial artifact is retained and superseded by link rather than overwritten, so that a past assertion and the basis on which it was made remain reconstructible.", "Disclosure of degradation: where a store, format or interface cannot carry an element, the loss is declared in the projection profile before use; undeclared silent coercion of offsets, nulls, absence semantics or numeric precision is a contract violation.", "Endpoint non-ownership: dependency endpoints are referenced, never copied. This model does not mirror the lifecycle, state or attributes of the elements it relates." ], "crud": { "read": [ "Reads are expressed as capability-declared selection expressions in a named expression language and version; results are returned as a nodelist whose members carry their normalized path or canonical location so a consumer can tell exactly which nodes were returned.", "Every read result carries a completeness flag and, where truncated, the truncation rule applied; a partial projection must never be presentable as a complete one.", "Every read of a projected form is accompanied by, or resolvably linked to, the projection profile reference and its loss disclosure for the target.", "Read results include the record version identifier and content digest so a consumer can detect drift without re-reading; retired records resolve to their tombstone state rather than to a not-found response.", "Access decisions on reads are made by the external decision point; this model supplies only the decision inputs (tenant partition, owner package, sensitivity label) and records the decision reference it was given." ], "create": [ "Creation binds an identifier under the identity priority, records the mandatory observation or ingestion timestamp with an explicit offset, and computes the initial canonical digest before the record is exposed to any consumer.", "Creation requires a resolved namespace and tenant partition with a named owner package; records may not be created in an unregistered namespace.", "Both endpoint references must be present with their identifier scheme and resolution status; an unresolved endpoint is recorded as an explicit dangling reference, never as a silent omission or an invented placeholder identifier.", "Provenance attribution (responsible agent and role) is mandatory at creation; an unattributed dependency assertion is rejected.", "Creation triggers validation against the profiles in force; a violation-severity result blocks publication unless an explicitly recorded accepted deviation with a named approver reference exists." ], "update": [ "Updates are applied only through committed change sets carrying the expected pre-state digest; a digest mismatch is a conflict that must be resolved by the requester, not auto-merged.", "Patch application is all-or-nothing: if any operation or precondition fails, no part of the change takes effect and the record retains its prior state and digest.", "Identifier, namespace and tenant partition are immutable after creation. A record that must move partitions is retired with a tombstone and successor reference, not silently re-keyed.", "Every committed update creates a new immutable version linked to its predecessor, declares its compatibility class, and re-runs validation against the profiles in force.", "Corrections to previously asserted facts are recorded as corrective versions with lineage preserved; the erroneous prior assertion is retained, since downstream impact conclusions may have been drawn from it." ], "delete": [ "Hard deletion of a governed record is not performed by this model. Retirement produces a tombstone that preserves the record identifier, the final version reference and content digest, the disposition reason, the disposition timestamp with an explicit offset, and an optional successor reference, so that inbound references resolve to an explicit retired state instead of vanishing.", "Retired identifiers are never reassigned, consistent with the persistence and non-reassignment commitment of the delegated namespace authority.", "Each record carries a retention class and a reference to the governing retention and disposition policy. That policy is defined and owned by the referenced retention model and the adopting Dimension, not here; this model records the class, the reference and the outcome it is told.", "Where erasure of record content is required (for example under a legal or regulatory obligation determined by the adopting Dimension), this model issues a disposition request to the executing party and records the confirmation reference returned. Execution of erasure in this model's own store and in every downstream store is performed by the adopting Dimension or the referenced retention model; this model neither decides that erasure is due nor performs it in systems it does not own.", "Even after content erasure, the tombstone retains the identifier, the final digest, the disposition reason and the governing policy reference, unless the governing policy explicitly requires removal of those fields too, in which case the erasure decision and its execution record remain with the policy owner and the audit system, not with this model.", "Serial artifacts (validation reports, provenance records, change sets, integrity manifests) follow their own retention class; they are not cascade-deleted with their subject, because they are the evidence of how the subject was governed." ] }, "roles": [ { "name": "Dependency Record Steward", "responsibilities": [ "Create, correct and retire dependency-edge and impact-assessment records within one namespace partition", "Ensure endpoint references, attribution and observation timestamps are complete and accurate at creation", "Declare the compatibility class of every change set and notify consumers of restrictive changes" ] }, { "name": "Namespace and Tenancy Registrar", "responsibilities": [ "Maintain namespace and tenancy registration manifests, including the delegated assignment authority and persistence commitment", "Enforce identifier opacity rules and reject identifiers containing date, version, status or digest components", "Rule on cross-partition reference requests against the declared cross-partition rule" ] }, { "name": "Canonicalization and Projection Authority", "responsibilities": [ "Publish and version canonicalization profiles per shape family and projection profiles per target", "Maintain the loss inventory, round-trip test evidence and absence-semantics mapping for every projection target", "Reject any proposal to declare a storage format or interface canonical" ] }, { "name": "Validation and Conformance Officer", "responsibilities": [ "Maintain the validation profiles in force, their versions and digests, and the named external engine used", "Retain validation reports as evidence and administer the accepted-deviation register for non-blocking severities", "Ensure conformance claims are bounded to a named profile, version and run, and that external standards are recorded as alignments" ] }, { "name": "Provenance and Evidence Custodian", "responsibilities": [ "Ensure every assertion carries a responsible agent, derivation lineage and evidence references with digests", "Maintain the custody chain across system transfers and record the current custodian", "Record explicitly which verification was and was not performed, so that trust is never implied by a digest match" ] }, { "name": "Retention and Disposition Delegate", "responsibilities": [ "Bind each record to a retention class and the externally owned governing policy reference", "Issue disposition requests to the executing party and record confirmation references", "Escalate rather than execute where erasure is required in stores this model does not own" ] } ], "access": { "default_rule": "Access is deny-by-default and is decided by the adopting Dimension's external authorization decision point. This model neither grants nor denies: it exposes decision inputs (tenant partition, owner package, sensitivity label, record kind and lifecycle state) and records the decision reference it was supplied. Where no decision reference is supplied, the operation is treated as unauthorised by the calling system, not as permitted by omission.", "scopes": [ "bundle", "layer", "finding", "artifact" ], "exceptions": [ "Endpoint and namespace metadata sufficient to resolve a dangling reference may be exposed at a lower sensitivity than the dependency assertion itself, because an unresolvable reference is itself an integrity defect; the split must be declared in the capability descriptor.", "Tombstone stubs (identifier, retired state, disposition timestamp and successor reference) remain readable to holders of inbound references even where the retired record's content is not, so references resolve rather than fail ambiguously.", "Validation reports and provenance records may be scoped more tightly than the records they cover, because they can disclose internal control weaknesses or supplier evidence not shared with all record readers.", "Break-glass or incident access is granted, logged and revoked by the external decision point and audit system; this model records only the decision reference and never widens its own exposure in response to an incident.", "Cross-partition reads of a foreign-partition record are refused by default and, where permitted, return only the namespace-qualified identifier and resolution status unless the foreign owner package has declared broader exposure." ], "audit_requirements": [ "Every create, update commit, retirement, disposition request, profile publication and conformance claim must emit an audit event to the externally owned audit system; the event carries at minimum the operation, record identifier, pre-state and post-state digests, acting agent reference, decision reference and observation timestamp with an explicit offset.", "Read operations that return records above a declared sensitivity threshold must emit an access event carrying the selection expression, result completeness flag and decision reference.", "Audit events are emitted, not stored, by this model: the structure, immutability guarantees, retention and querying of the audit trail are owned by the referenced audit model and the adopting Dimension, and no audit event is treated here as evidence of authorisation.", "Failure to emit a required audit event must fail the governed operation rather than allow it to proceed unrecorded, and the failure itself must be surfaced to the owner package." ] }, "agents_bootstrap": { "filename": "AGENTS.md", "required_fields": [ "Name", "Type", "Specification URL", "Storage type URL", "Interface URL", "Processes URL", "Namespace and tenancy manifest URL", "Canonicalization and projection profile URL", "Validation profile URL", "Retention, authorization and audit delegation references" ], "read_order": [ "AGENTS.md - resolve Name, Type and the six mandatory URLs before any other action; if any is unresolvable, stop and report rather than infer a default.", "Specification URL - read the model scope, boundaries and out-of-scope statements, so that no target-owned concept (policy evaluation, enforcement, audit-trail ownership, erasure execution) is attempted locally.", "Namespace and tenancy manifest - establish the partition, owner package and identifier rules in force before minting or resolving any identifier.", "Canonicalization and projection profile - determine the shape family, digest algorithm and loss disclosure for the intended projection before reading or writing any concrete form.", "Storage type URL - learn how the abstract record is projected into the deployed store, treating it as a projection with disclosed loss rather than as canonical semantics.", "Interface URL and the operating-surface capability descriptor - determine which query, mutation, projection and retirement capabilities exist, their expression languages and preconditions.", "Validation profile - identify the profiles in force and the external engine used before asserting any conformance.", "Processes URL - follow the governed change, validation, attestation and disposition procedures, including the delegation references for retention, authorization and audit." ] } }, "coverage": { "claim": "The single active Claude result covers the dependency-assertion relationship for WM-XCT-037 to a reviewable-draft standard: assertion envelope and identity, canonical direction and endpoint-role binding, typed kind and referent-class registers, conditions and guards, evidence and epistemic state, lifecycle and bitemporal reconstruction, graph and impact semantics, criticality and resilience posture, governance roles, record and service contracts, mutation, query, reporting and projection surfaces. Coverage is bounded by 156 source pins that have not been re-verified live in this audit, three gaps the result itself declares (deploy-phase vocabulary with no SPDX LifecycleScopeType counterpart, no bridge from opaque tool confidence to metrological uncertainty, no primary source for graded dependency health), an internally contradictory impact/traversal boundary, and the owner-authorized absence of independent second-provider review. No universal or domain-complete coverage is claimed.", "confidence": "medium", "checklist": [ { "dimension": "identity", "status": "covered", "notes": "Three-tier identity priority with the authoritative master-system identifier first; assertion identity kept disjoint from endpoint identity; weak host-dependent identity evidenced by PROV's optional qualified-relation identifier, RDF blank nodes being explicitly non-persistent and non-portable, and CycloneDX bom-ref uniqueness being enforced only within the root bom element." }, { "dimension": "temporal", "status": "covered", "notes": "Declared-at, observed-at and recorded-at kept distinct; RFC 3339 with seconds and explicit offset; -00:00 preserved as a distinct meaning; effective interval carried on the assertion following SPDX startTime and endTime; staleness horizons applied to verification." }, { "dimension": "provenance", "status": "covered", "notes": "Issuer and observing agent recorded separately, authority basis referenced, parallel assertions from different issuers coexist without adjudication following PROV's multiple-accounts model, and content digests make revisions verifiable." }, { "dimension": "ownership", "status": "covered", "notes": "Adopting Dimension and tenant own the record; both endpoints are externally owned throughout. Steward, issuer, custodian, verification operator and liaison roles separate record stewardship from endpoint custody." }, { "dimension": "validation", "status": "covered", "notes": "Locator equivalence uses the RFC 3986 comparison ladder with the applied rung recorded, URN components excluded from equivalence are dropped, self-reference and duplicate shapes must be recorded rather than dropped, and relations with undocumented native direction are rejected." }, { "dimension": "access", "status": "covered", "notes": "Default rule requires read access to both endpoints; scopes cover bundle, layer, finding and artifact; redaction must preserve the visible existence of the assertion. Evaluation and enforcement are explicitly owned by the referenced policy model." }, { "dimension": "interoperability", "status": "covered", "notes": "Mappings evidenced against SPDX 3.0.1, CycloneDX 1.6 / ECMA-424, CSAF 2.0, TOSCA 1.3 and RFC 8288, with the absence-encoding conflict normalized reversibly on import. Alignment is claimed per standard version; no conformance is asserted." }, { "dimension": "direction and role assignment", "status": "covered", "notes": "A single canonical direction is fixed locally because no consulted source establishes a universal one; CSAF categories such as installed_on and the RFC 8288 deprecation of rev are the counterexamples that force normalization plus verbatim preservation of the source term." }, { "dimension": "phase vocabulary alignment", "status": "gap", "notes": "Deploy-time is a genuine and widely used phase, but SPDX LifecycleScopeType offers no corresponding value and CycloneDX carries no phase facet at all. Deploy is therefore defined locally with a local-extension marker and recorded as unmapped residue rather than presented as aligned." }, { "dimension": "classification and taxonomy", "status": "covered", "notes": "Ten reliance kinds grouped into work and capability, actor and agreement, and resource and situation, each with its own endpoint rules rather than a single untyped edge." }, { "dimension": "conditionality and guards", "status": "covered", "notes": "Guards, unmet-guard outcome (inapplicable versus failure, from the systemd condition-versus-assertion distinction), evaluation timing and an explicit prohibition on unconditional projection are modelled, grounded in RPM boolean operators and Debian architecture and build-profile restrictions." }, { "dimension": "confidence and uncertainty", "status": "gap", "notes": "Confidence is preserved with its scale, and VIM supplies the vocabulary for uncertainty and repeatability/reproducibility conditions, but no primary standard bridges opaque tool confidence values (CycloneDX 0-1) to a metrological uncertainty statement. Cross-scale arithmetic is therefore blocked rather than defined." }, { "dimension": "health and degradation grading", "status": "gap", "notes": "The satisfied / degraded / broken / restored ordering is a synthesis. Verified primary sources define state on managed entities (RFC 4268 operational state is enabled, disabled, testing; alarm severity gives gradation) and status on records (FHIR status), but none assigns a graded health value to a dependency relationship itself. The threshold between degraded and broken is therefore left to declared, Dimension-owned criteria and is flagged as lacking direct primary support." }, { "dimension": "cycles and termination", "status": "covered", "notes": "Cycle witnesses, strongly connected group membership, condensation and an explicit closure-safety marker constrain transitive, ordering and depth claims; unbounded closure over cyclic subgraphs is prohibited." }, { "dimension": "counterfactual baseline", "status": "covered", "notes": "Baseline kind, source, observation or projection time, effect expression mode and revision handling are mandatory, with none-declared as an explicit recorded value that forces a limitation note. Grounded in the statutory requirement for a baseline scenario and its likely evolution without the project, corroborated by the European Commission impact assessment method." }, { "dimension": "correlation and concentration", "status": "covered", "notes": "Common-cause conditions, effective independence, load-sharing degradation and multi-level concentration measures are modelled, with DORA and IEC 61078 as anchors." }, { "dimension": "segregation of duties", "status": "covered", "notes": "Static, dynamic and history-based separation modes, incompatible duty sets, two-person conditions and privilege-aggregation windows are declared as constraint data, following the NIST definition in SRC-106. Evaluation and blocking are explicitly external, consistent with SRC-103." }, { "dimension": "canonicalization and deterministic serialization", "status": "covered", "notes": "Per-shape-family canonicalization (RFC 8785 for tree, RDFC-1.0 for graph) with I-JSON constraints, string-encoded high-precision numbers, declared Unicode normalization, and an explicit refusal to claim cross-shape digest equality." }, { "dimension": "side-effect containment", "status": "covered", "notes": "Explicit prohibitions on mutating endpoint, policy or audit records and on triggering resolution, deployment, remediation or notification, reinforced by patch path restrictions and a policy statement that emitted events are signals, not instructions." }, { "dimension": "closed-world scope and negative results", "status": "covered", "notes": "Open-world default derived from the monotonicity requirement in RDF 1.1 Semantics; independence claims permitted only under a declared, evidenced, complete and untruncated closed-world scope with a re-verification trigger." }, { "dimension": "evidence and quality disclosure", "status": "covered", "notes": "Every conclusion carries resolvable evidence citations plus completeness, coverage and confidence values, and a minimum disclosure set gates release from draft." }, { "dimension": "expressivity and loss", "status": "covered", "notes": "Mandatory machine-readable loss reports with stable problem-type identifiers, severity, recovery locators and blocking thresholds (SRC-120). Grounded in cited expressivity ceilings: indirect-only n-ary in RDF (SRC-143), atomic-or-list cells in tabular data (SRC-146), presentation-detail discard in YAML (SRC-147), relaxed-mode type loss in document stores (SRC-153)." } ], "known_omissions": [ "The evidence-grading and confidence vocabulary attached to an assertion is referenced but not enumerated; no primary source was found that grades dependency evidence, so no scale is proposed.", "Hardware and firmware dependency kinds are not enumerated; alignment to hardware bills of materials is deferred and would require a separate referent family with its own endpoint identity scheme.", "No dependency-strength or criticality scale is defined; the model deliberately stops at declaring reliance and its evidence, leaving severity and criticality to the impact and risk models.", "Impact propagation, blast radius, criticality scoring and downstream effect, which belong to the impact split of WM-XCT-037 and are referenced only through boundary notes.", "Signature validity, key management and trust-anchor policy, deliberately delegated to an external verification service.", "No quantitative availability or reliability calculus: mean time between failures, uptime percentages and service-level objective arithmetic are deliberately absent, since they belong to a measurement model and would imply monitoring ownership.", "Weighted and probabilistic propagation (impact strength decay over hops, Bayesian propagation) is not modelled. It was rejected for this pass because no cited primary source supports a general weighting semantics, and quantification belongs to the referenced risk model.", "Quantitative propagation computation: cascading-failure, queueing, network-reliability and percolation models. This pass records propagation assumptions, paths and exclusions but prescribes no algorithm and no attenuation function.", "No units-of-measure registry is bound for capacity, throughput or monetary consequence values, so cross-record quantitative comparison is not yet safe.", "Notification transport, subscription and delivery guarantees for the observer archetype are not modelled; only the standing and the fact of a notified-party relationship are captured.", "Typed dependency vocabulary, impact severity scales and aggregation semantics (adjacent split).", "No verified alignment to formal change-control frameworks (NIST SP 800-53 CM-3 and CM-4, ISO/IEC 20000, ITIL) - the source text could not be retrieved live in this pass, so the approval gate rests on an analogous assessment pattern rather than a change-management standard.", "Concrete wire syntax and dialect bindings (SPARQL, GQL, SQL/PGQ, GraphQL, REST, MCP tool shapes) are deliberately absent; they are projections of this contract.", "No quantitative impact scoring, severity algorithm or business-criticality weighting is specified; scores enter by reference from a risk or severity model with their scoring system named.", "Signing, key management and revocation for canonical serializations are not modelled; only digest-based integrity is specified." ], "conflicts": [ "Direction is not universal across sources. TOSCA DependsOn, SPDX from/to and CycloneDX dependsOn all read dependent-to-prerequisite, but CSAF categories such as installed_on invert the intuitive reading, and RFC 8288 deprecated the reversed rev parameter in favour of defining separate relation types. A single canonical direction is therefore a local normalization rule, and the source term must be preserved.", "Absence and ignorance are encoded inversely. SPDX marks explicit absence with a NoneElement in the to property and ignorance with a NoAssertionElement, while CycloneDX marks absence by declaring an empty dependency element and ignorance by omitting the component from the graph. Round-tripping between them without an explicit normalized state silently converts one into the other.", "The CycloneDX absence rule has drifted in strength across versions: the 1.6 XSD documentation uses SHOULD for declaring components without dependencies as empty elements, while widely quoted earlier-version wording uses MUST, and the project has recorded inconsistency between its JSON and XSD dependency definitions. Any conformance claim must name a specific schema version.", "Endpoint reference portability differs by source. A CycloneDX bom-ref is unique only within the root bom element, SPDX uses IRI-based element identifiers, and RDF blank node identifiers are explicitly not persistent or portable. Imported references cannot be treated as globally meaningful without rebinding.", "Statement-level identity is optional in the standards that come closest. PROV allows but does not require an identifier on a qualified influence, and RDF reification provides no identity guarantee at all, so a dependency assertion has no strong identity unless one is minted - which conflicts with any downstream assumption that assertions are globally addressable.", "RFC 3339 is updated by RFC 9557, which adds extensions beyond the base offset representation. Records carrying extended forms may not compare equal under a strict RFC 3339 profile, so the profile version in force must be stated by the adopting Dimension.", "SPDX 2.3 encodes phase into the relationship type (BUILD_DEPENDENCY_OF, TEST_DEPENDENCY_OF, RUNTIME_DEPENDENCY_OF) while SPDX 3.0.1 uses a single dependsOn qualified by LifecycleScopeType. The two generations do not map one-to-one, and SPDX 2.3 additionally supplies inverse-direction pairs (DEPENDS_ON versus DEPENDENCY_OF) that must be normalised on intake.", "CycloneDX dependsOn carries no lifecycle phase, nature or conditionality facet, so any projection from this model into a CycloneDX dependency graph drops phase, nature and qualifier information; the reverse projection cannot recover them and must not invent them.", "CycloneDX provides is a capability or specification implementation statement, not a dependency; treating it as an inverse dependsOn reverses meaning. Debian Provides is a comparable but not identical virtual-package mechanism, and neither maps cleanly onto the SPDX relationship set.", "Debian Recommends, Suggests and Enhances have no counterpart in SPDX or CycloneDX, and Enhances is the inverse direction of Suggests. Breaks and Conflicts are negative relations that no dependsOn-shaped vocabulary can express, so a negative relation exported to such a vocabulary is silently lost.", "npm peerDependencies constrains the host rather than declaring a requirement the package will itself install; mapping it to SPDX dependsOn both reverses the practical direction and misstates the nature as functional requirement instead of compatibility constraint.", "TOSCA 2.0 removed the bundled Simple Profile types, so HostedOn, ConnectsTo, AttachesTo and RoutesTo are profile-defined rather than normative in the standard itself. They are recorded as alignment candidates carrying a profile identifier, not as normative anchors.", "W3C PROV used and wasDerivedFrom are past-tense, instance-level statements about activities and entities, whereas a declared dependency is a forward-looking, type-level requirement. Treating lineage as dependency manufactures edges that were never required to exist.", "The CycloneDX schema instructs consumers to treat an object absent from the dependency graph as opaque rather than dependency-free, while common tooling practice reads an empty dependsOn as an assertion of no dependencies. CISA guidance resolves this in favour of explicit known unknowns, and this model follows the specification and the guidance against the practice.", "SemVer precedence, Debian version relation operators and other ecosystem range grammars order pre-release and metadata differently and are not mutually comparable; no consulted primary source defines a cross-grammar comparison, so none is asserted.", "Scope conflict: the CSDDD chain of activities excludes product disposal and, for regulated financial undertakings, downstream activities, while DORA's ICT third-party scope carries no equivalent carve-out. A single 'supply chain dependency' kind cannot satisfy both, so chain scope must be declared per assertion with its citing instrument.", "Definitional conflict: EBA/GL/2019/02 separates outsourcing from other third-party arrangements such as purchase of goods, whereas DORA's register covers ICT services more broadly. The same arrangement can be inside one register and outside the other, so arrangement type and target register are recorded independently.", "Structural conflict: W3C ORG explicitly removed the informative claim that org:reportsTo is acyclic, while many escalation and approval kinds are designed on an acyclicity assumption. Cycle behaviour is therefore declared per kind and never assumed.", "Semantic conflict: PROV models influence rather than causation, while operational practice routinely reads a dependency edge as causal. This model does not license the causal reading and requires a separate blocking-mode statement instead.", "Status conflict: the current /TR/ version of the Time Ontology in OWL is a Candidate Recommendation Draft rather than a Recommendation, so its interval relations are used as an alignment target and no conformance is claimed.", "Granularity conflict: DORA's critical-or-important-function test is function-scoped and materiality-based, whereas supplier registers are arrangement-scoped. An assertion must therefore carry both the supported function and the arrangement, and neither may be inferred from the other.", "Where strength lives differs by authority: SPDX encodes optionality as a distinct relationship type, Debian and RPM as distinct field names with graded meaning, TOSCA as a cardinality lower bound of zero, and Kubernetes as a required-versus-preferred flag with a numeric weight. No single encoding can round-trip all four without annotation.", "CycloneDX dependsOn carries no strength axis at all, so projecting an optional or recommended condition into a CycloneDX dependency edge either loses the distinction or misrepresents it as mandatory; the model requires a lossiness report or refusal rather than a silent choice.", "Direction is not uniform: Debian Enhances and RPM Supplements and Enhances are declared by the prerequisite side, and older SPDX vocabularies used inverse relationship names, so ingest must invert while retaining the native term.", "Default epistemics conflict: CycloneDX states that absence from the graph is opaque and requires an explicit empty element to assert no dependencies, SPDX offers an explicit noAssertion value, while package archives are conventionally interpreted closed-world within a resolution context. The model adopts the open-world default and records the divergence.", "Grammar expressiveness conflicts: RPM forbids combining if with or and unless with and, whereas Kubernetes match expressions and SHACL constraint components permit different nesting, so a neutral expression that is valid here may be unprojectable into RPM.", "Ordering and existence are orthogonal in systemd but deliberately coupled in Debian Pre-Depends, which conflates a strength grade with a staged ordering guarantee; the model records both axes separately and preserves the native coupling as provenance.", "Severity scales are not obligation scales: the SHACL Violation, Warning and Info scale qualifies results, while Debian field grades and RFC 2119 keywords qualify requirements. Conflating them would misreport a warning-severity result on an absolute requirement as a weak condition.", "CycloneDX expresses confidence as a bare 0-1 number per identity conclusion and per contributing method with no defined statistical meaning, whereas VIM requires uncertainty to be expressed as a dispersion parameter tied to stated conditions. The two are not interconvertible and are recorded side by side rather than merged.", "SPDX 3.0.1 attaches completeness to an individual relationship (complete, incomplete, noAssertion) while CycloneDX attaches an aggregate to a composition scope with a richer enumeration including unknown and not-specified. Mapping noAssertion to either unknown or not-specified loses information, so both source values are retained.", "OpenVEX orders statements by author document version and timestamp within a single author's stream; PROV wasRevisionOf carries no ordering guarantee. Cross-author ordering cannot be inferred from timestamps alone because of clock skew, so this partition records an explicit not-ordered marker instead.", "SOSA phenomenonTime/resultTime and SPDX Relationship startTime/endTime describe different things: the first pair concerns the observation act, the second the validity of the asserted relation. Tools that map one onto the other silently lose the distinction, which is why four separate time fields are mandated here.", "CISA and NTIA framing sets the default reading of unstated completeness to incomplete, while many producing tools omit completeness entirely and are read downstream as complete. This partition adopts the authority reading and emits a consumer-facing warning on absent declarations.", "RFC 9334 assigns appraisal to the Verifier, while several SBOM toolchains embed verdicts directly in evidence documents. Imported verdicts are stored only as references to an external decision, never as native fields.", "SPDX 3.0.1 makes a Relationship a first-class Element with its own SpdxId, implying strong independent identity, whereas this model asserts weak host-dependent identity. Resolution: the SpdxId is a projection surrogate minted at export and is not the identity key; round-tripping through SPDX cannot be assumed to preserve assertion identity.", "SPDX Relationship carries a single startTime and endTime, with no record-time dimension and no annulment marker, so bitemporal state and corrections cannot be projected to SPDX without loss. Conformance to SPDX is therefore not claimed, only a declared lossy alignment.", "ISO/IEC 11179-6 registration statuses govern registered metadata items maintained by a registration authority, not empirical assertions about running systems. Borrowing Superseded and Retired is an alignment; treating this model as an ISO/IEC 11179 conformant registry would be unsupported.", "SQL:2011 system-versioned tables have the DBMS maintain system time automatically. Where the chosen storage projection is not a temporal DBMS, the record-time dimension must be maintained by the application, which weakens the guarantee that record time is tamper-resistant; the model states the requirement but cannot enforce the mechanism.", "Memento's Memento-Datetime is a promise that a dated state will no longer change, which conflicts with any implementation that repairs or re-normalises historical rows. The model resolves this by forbidding in-place normalisation, including of timestamps, on published versions.", "HL7 FHIR treats entered-in-error as a resource status value, mixing annulment into the same field as workflow state. This model deliberately separates the annulment marker from the registration state field, so a direct field-level mapping to FHIR status is not available.", "W3C PROV-CONSTRAINTS states there is no inference making derivation transitive, while OWL 2 permits declaring a property transitive and composing property chains. These are not reconcilable by default, so this model requires transitivity to be explicitly declared per relation type with a recorded basis, and treats any unmarked transitive claim as invalid.", "SPDX attaches completeness to an individual relationship assertion, whereas CycloneDX makes a document-level statement that absence from the graph is opaque. This model uses a scoped declaration covering a frontier, which is broader than the SPDX per-relationship marker and narrower than a blanket document-level assumption; neither source is fully satisfied and the divergence is recorded rather than hidden.", "RDF 1.1 Semantics establishes that a valid inference need not be materialised, while graph analytics practice routinely writes derived properties back into the graph. This model permits materialisation but forbids merging derived statements into the asserted edge set, which is stricter than common practice.", "IEC 61025 and IEC 61078 use cut set and path set in a coherent-system reliability sense with defined failure semantics, whereas software dependency analysis borrows the terms structurally without failure logic. The model records the method reference and assumptions to keep the borrowed usage honest, but the terminological overlap remains a source of misreading.", "Graph engines differ in default path semantics: some default to trail or simple, others to walk. ISO/IEC 39075 makes the restrictor explicit, so this model mandates declaring it, which will produce results that differ from engine defaults.", "The statutory vocabulary of indirect, secondary and cumulative effects is domain-causal, whereas indirect in dependency traversal means graph distance greater than one. The two do not coincide. This model requires the traversal basis to be declared explicitly and does not assert equivalence, so a result labelled indirect must not be read as satisfying a statutory indirect-effect requirement.", "NIST SP 800-30 frames impact as adverse harm arising from a threat event, while change-impact analysis must also represent neutral and beneficial effects. The polarity field departs from that framing deliberately; consumers mapping to a NIST-style risk model will find positive-polarity effects have no target.", "VEX and CSAF status justifications are vulnerability- and code-path-specific, for example vulnerable code not in execute path. They map only partially onto general non-propagating dependency reasons, so the alignment is an explicitly partial mapping and not a conformance claim; a general non-propagation reason has no VEX equivalent and vice versa.", "PROV-O's wasInfluencedBy is intentionally weaker than causation. Consumers that read PROV edges emitted by this model as causal claims will misread every exposure inference; the alignment therefore carries an explicit non-causal caveat.", "CSAF permits both integer and semantic document versions and uses release dates prominently in tracking. This model is stricter: versions are monotonic and never encode a date, and dates are never identity. Records exchanged with CSAF-shaped systems require a mapping note.", "Statutory impact assessment expects a described set of reasonable alternatives evaluated within one assessment, whereas this model represents alternatives as sibling scenario versions linked by comparator role. This is a structural divergence that must be reconciled at export time.", "IFRS S2 requires short, medium and long term horizons but does not fix their boundaries, and the environmental impact assessment regime uses the same terms with different implied durations. Horizon bands are therefore Dimension-declared and are not comparable across Dimensions without an explicit mapping.", "The NIST glossary records four non-identical definitions of criticality - consequence of incorrect behaviour (CNSSI 4009-2022), degree of mission dependence (SP 800-30 Rev. 1), relative importance to stated goals (SP 800-160 Vol. 2 Rev. 1) and degree of impact on development or operation (SP 800-160v1r1). No single definition is adopted; the scheme binding requirement exists because of this conflict.", "CVSS v4.0 yields a numeric score and a None-to-Critical band, while CISA's SSVC yields a Track / Track* / Attend / Act decision from decision points. These outputs are not interconvertible and no mapping between them is asserted here.", "Recovery terminology diverges: NIST SP 800-34 Rev. 1 uses maximum tolerable downtime while business continuity practice under ISO 22301 uses maximum acceptable outage and maximum tolerable period of disruption. This model references whichever value the owning system holds and does not reconcile the vocabularies.", "IEC 60812:2018 notes alternative means of calculating risk priority numbers, reflecting a long-standing objection to multiplying ordinal severity, occurrence and detection ranks. This model therefore never computes a composite score of its own.", "'Blast radius' is widely used in practice but has no normative definition in any source consulted; it is modelled as an affected-set snapshot with an explicit traversal rule instead.", "RFC 8126 vests approval of future modification in a single Change Controller, while NIST SP 800-37 Rev. 2 separates the system owner from the authorizing official who accepts risk. This model does not merge them: it keeps endpoint steward and approving authority distinct and lets the adopting Dimension collapse them only by an explicit, recorded mapping.", "SPDX CreationInfo treats created as the time of last modification of the described thing (supporting reproducible builds), whereas governance practice needs the time the governance act took effect. The model resolves this by recording effective time, record time and reporting time separately rather than reusing a single created field.", "ODRL models parties inside enforceable rules with permissions, prohibitions and duties; this model borrows only the party-function and constraint-operand vocabulary and expresses no rule, because expressing a permission here would breach the non-enforcement boundary.", "GDPR storage limitation requires erasure once the purpose is exhausted, while records and litigation-hold regimes require preservation. This model carries both markers and refuses to arbitrate, routing the conflict to the referenced privacy and records models.", "NIST separation-of-duty guidance anticipates enforcement at access time (dynamic separation), whereas this model can only declare the constraint. A Dimension that adopts this model without a functioning external decision point will have declared but unenforced separation - a real and reportable weakness, not a modelling artefact.", "The registry entry lists factor_overlap at 0.06 and no aligned model identifiers, yet this slice necessarily depends on access, audit, identity, retention and privacy models. Either those siblings exist and the relation ledger is incomplete, or they do not and the required composition links are unsatisfiable gaps.", "RFC 8785 constrains numbers to IEEE 754 double precision and forbids duplicate property names, while supply-chain formats and scoring systems may carry higher-precision or long-integer values. Resolved by requiring string encoding beyond double precision and declaring the encoding per field; this makes cross-format numeric comparison non-trivial.", "RFC 8785 performs no Unicode normalization while RDFC-1.0 canonicalizes RDF terms in a different data model, so byte-identical human text can yield different canonical forms. Cross-shape digest equality is therefore explicitly not claimed, which limits single-digest integrity strategies.", "RFC 7396 assigns null the meaning of deletion, which conflicts with any dependency record that legitimately carries an explicit null-valued field. Resolved by restricting merge patch to null-free object subtrees rather than by banning nulls in the model.", "SPDX 3.0.1 distinguishes an explicit no-relationship assertion (NoneElement) from a no-assertion statement (NoAssertionElement); CycloneDX and most tabular or document stores express absence differently or not at all, so absence semantics do not round-trip. Each projection profile must declare the collapse.", "RFC 3339 permits leap-second value 60 and the -00:00 unknown-offset convention, but many stores and libraries normalize to UTC and discard the offset. This is a real fidelity loss that must be disclosed rather than assumed harmless.", "DCAT-3 provides version-lineage properties but no formal compatibility-class vocabulary, so the additive/corrective/restrictive classification defined here is a local construct aligned to DCAT lineage rather than adopted from it, and is marked as such.", "SLSA build provenance v1.0 is retired in favour of v1.2, so evidence references must record the predicate type and version used; a stored attestation may reference a retired predicate that consumers no longer recognise.", "Client-supplied idempotency keys are widespread practice but have no stable normative basis: the IETF draft that would standardize the header expired at revision 07 without becoming an RFC. The model therefore treats the key as a local contract parameter and takes its binding guarantees from RFC 9110 idempotency and conditional requests instead.", "Version-conflict signalling is not uniform: FHIR permits both 409 Conflict and 412 Precondition Failed for the same class of failure, so any interface binding must choose one and declare it; the model keeps stale-version and illegal-transition as distinct semantic outcomes regardless of the chosen status code.", "SPDX models a relationship as an asserted element with creation metadata but has no state machine, no approval gate and no supersession semantics. The lifecycle defined here is an addition layered on top of that vocabulary, not SPDX conformance, and round-tripping loses the workflow states.", "PROV-O's wasRevisionOf does not distinguish a correction of an erroneous record from a legitimate revision. The distinction is imported from a clinical status vocabulary (amended, corrected, entered-in-error) and is therefore not interoperable by default; exporters must carry the change-nature code explicitly.", "CloudEvents allows a producer to set the time attribute either to the actual occurrence time or by a consistent algorithm, so the envelope alone cannot carry the event-time versus ingestion-time distinction; both times must travel in the event data, not only in the envelope.", "The publication-status vocabulary treats retired as covering both withdrawn and superseded, whereas this model separates retirement from supersession because they assert different things about currency; mapping to that vocabulary is therefore lossy in one direction.", "SPARQL 1.1 arbitrary-length path matching deliberately reports connectivity without enumerating or counting paths, while GQL supplies explicit path modes and path finding that return paths. The same natural-language question therefore yields different results across engines, so this model requires the result shape and path mode to be declared rather than inferred.", "SPDX RelationshipCompleteness (complete, incomplete, noAssertion) and CycloneDX compositions aggregate (ten values including first-party and third-party, proprietary and open-source partitions, plus unknown and not_specified) are not one-to-one; mapping CycloneDX to SPDX loses partition detail and conflates unknown with noAssertion. Mappings must be recorded as lossy.", "CSAF v2.0 does not define the meaning of a product absent from every status group, so consumers cannot treat silence as either not-affected or no-assertion on the standard's authority. This model resolves the ambiguity locally by treating absence as no assertion and says so explicitly.", "RFC 7089 negotiates prior states using RFC 1123 HTTP-date in headers, whereas this model requires RFC 3339 with an explicit offset for stored time values. A projection must convert, and must not present the best-match datetime as the datetime that was requested.", "AIP-158 is design guidance rather than a standard and gives no cross-page consistency guarantee, while OGC API - Features permits omitting the matched count. Neither supplies snapshot isolation, so this model's reference-point binding is a local requirement and not an inherited one.", "RDF 1.1 Semantics mandates monotonic entailment, which forbids reading absence as negation, yet SBOM practice routinely treats a delivered dependency list as exhaustive. This model sides with the standard and requires an explicit closed-world declaration before any independence claim.", "SPDX 3.0.1 expresses completeness per relationship, while ECMA-424 / CycloneDX expresses it per composition scope. A report mixing both must state which granularity each completeness claim uses; the two are not interchangeable and no lossless merge is claimed.", "CSAF 2.0 and OpenVEX define overlapping but non-identical status and justification vocabularies. Mapping between them loses information in at least one direction, so no lossless bidirectional mapping is asserted.", "SARIF baselineState describes result drift between runs, whereas STIX revoked and valid_until describe withdrawal and expiry of an assertion. Using either alone under-reports staleness, so this model requires both an age-based staleness marker and a withdrawal marker.", "Debian-style alternatives expressed with a vertical bar and virtual capabilities expressed through Provides encode choice inside the dependency declaration, whereas SPDX and CycloneDX dependency graphs commonly record already-resolved edges. A report converting between these can silently lose the alternative set, which is why alternative satisfiers are a mandatory degradation disclosure.", "STIX confidence scales are enumerated but not universal. A numeric confidence value copied between scales without naming the scale is not interoperable, so the scale reference is required alongside every value.", "W3C DQV is a Working Group Note rather than a Recommendation, so its use here is an expression alignment for quality measurement and explicitly not a conformance claim.", "NIST treats impact analysis as an analytical act distinct from configuration change control, whereas several commercial change-management tools merge assessment and approval into one record. This model follows the standards-led separation and will therefore not map cleanly onto tools that combine them.", "RFC 8785 is an Informational Independent Submission with no IETF standards standing, yet it is the most widely implemented deterministic JSON canonicalization. The model cites it as a rule set that must be named and versioned rather than as a normative requirement.", "RFC 4180 explicitly states that CSV has never been formally documented and that implementations vary widely, so a CSV projection cannot be validated against a single normative grammar; the model requires an explicit dialect declaration instead.", "SPDX 3.0.1 defines four parallel serializations and a canonical serialization notion but makes no statement about round-tripping or information loss between them, so the loss-report requirement here goes beyond the cited standard rather than deriving from it.", "SPDX models direction as exactly one `from` and one-or-many `to`, while RDF 1.2 states that relations over more than two entities can only be expressed indirectly; a faithful RDF projection therefore requires reification or a relation class and cannot be a direct edge.", "JSON-LD 1.1 enumerates constructs without RDF equivalents (@json literals, blank node predicates, @list ordering), so a JSON-LD projection is not automatically a lossless RDF projection even though both are cited as semantic carriers.", "RDF 1.2 Concepts is a Candidate Recommendation Snapshot rather than a Recommendation, so its triple-term and reifier constructs are cited as a stabilising but not yet final basis for uncertainty and non-assertion encoding.", "MCP versions on a date-stamped scheme incremented only on backwards-incompatible change, whereas semantic versioning increments a numeric major component; a projection profile served over MCP must therefore carry both its own semantic version and the protocol version, which the three-axis rule accommodates but does not reconcile.", "WHATWG microdata declares properties unordered except among same-named properties, which conflicts with the requirement for a declared total order over target-endpoint lists; HTML projections must therefore rely on same-name grouping or accept an ordering loss entry." ], "regional_assumptions": [ "Jurisdiction is treated as an opaque code bound to an external registry. No region-specific regime governing the disclosure, retention or cross-border transfer of dependency assertions was verified against a primary source in this research, so no regional rule is asserted.", "CISA guidance is United States federal guidance. Other regimes, including European product-cybersecurity legislation, may impose different transparency, depth or reporting expectations; the adopting Dimension must bind its own regulatory profile because this model selects none.", "DORA, CSDDD, the EBA guidelines, ELI and ESCO are European instruments used as worked examples of dependency typing, not as globally applicable requirements; an adopting Dimension outside the EU must bind local equivalents.", "The evidence base is drawn from software supply-chain, packaging, orchestration and semantic-web standards published in English by international bodies; domain vocabularies in engineering, construction, clinical and regulatory settings may carry dependency notions this pass has not tested.", "The SBOM attribute expectations cited come from US federal-procurement framing (CISA, third edition, October 2024); other regimes, including the EU Cyber Resilience Act, may require different minimum attributes and the adopting Dimension must map them.", "No retention period, statute of limitations or records-management schedule is assumed; all are delegated to the adopting Dimension because they vary by jurisdiction and sector.", "No jurisdiction-specific content is asserted. The only region-sensitive point is deletion: where a data-protection regime such as the EU GDPR right to erasure compels physical removal, the adopting Dimension's retention policy overrides the tombstone rule and the resulting gap must be recorded as a declared known unknown rather than as an absent edge.", "Directive 2011/92/EU as amended, the European Commission Better Regulation Guidelines and Toolbox, and Regulation (EU) 2022/2554 are European Union instruments. They are used here as evidence that baseline scenarios, direct and indirect effect typing, scenario-based business impact analysis and maintained dependency registers are required somewhere in authoritative practice - not as obligations binding any adopting Dimension.", "Regulation (EU) 2022/2554 binds only EU financial entities; its treatment of critical or important functions, concentration risk and exit strategies is used as evidence that these concepts are real and externally designated, not as a universal obligation.", "NARA guidance on unauthorized dispositions and the 44 U.S.C. 3106 reporting obligation is United States federal practice cited as an authoritative example of records-authority ownership; non-US Dimensions must substitute their own records regime and reporting obligation.", "Retention periods, erasure obligations and the definition of a legitimate erasure request are jurisdiction-specific and are owned entirely by the adopting Dimension and its referenced retention policy model; nothing here asserts a universal retention rule.", "No jurisdiction-specific electronic-records regime is assumed. Where one applies (for example a validated-systems or records-integrity regime), the adopting Dimension's audit and retention models must add signature manifestation, signature-to-record linking and audit-trail retention obligations; this model provides the hooks but asserts none of them.", "No jurisdiction-specific legal requirement is assumed. Retention horizons for result artifacts, tombstone content and audit correlation are set by the adopting Dimension's jurisdictional policy, and this model states only the shape those obligations attach to.", "No jurisdiction-specific breach, outage or incident notification duty is modelled. A notification-content draft is a draft whose legal sufficiency and timing must be assessed by the adopting Dimension's regulatory model.", "Time values are assumed to be recordable with an explicit UTC offset; deployments in jurisdictions or systems that store wall-clock time without an offset will fail the timestamp rule and must add offset capture before adopting." ], "adversarial_checks": [ "Searched for a normative source establishing one universal dependency direction and found none: TOSCA, SPDX and CycloneDX agree, but CSAF categories invert and RFC 8288 deprecated reversed relations rather than standardising them. The attractive claim of an inherent direction was rejected; direction is a local normalization with mandatory preservation of the source term.", "Tested whether a single universal depends-on kind would suffice. Rejected: SPDX phase scoping, CycloneDX provides, TOSCA hosting with occurrences, and Debian Conflicts, Pre-Depends and Recommends cannot be collapsed into one relation without losing direction, negation, ordering or capability semantics that each source defines normatively.", "Ownership test: substitute a wholly owned subsidiary that supplies nothing. If the assertion survives, it was a control or consolidation edge misfiled as a dependency; GLEIF Level 2 data is the reference for the test.", "Flattening test: take a condition guarded by an architecture restriction and a build profile, project it into a target vocabulary without guard support, and confirm the projection is refused or emits a lossiness report naming the dropped guard, never an unconditional edge.", "Does any finding or function evaluate, verify, enforce or adjudicate? Checked: the strength finding records values but computes no score; the contradiction function registers and refers but selects no winner; the freshness output exposes recorded times but makes no staleness decision; signature verification and appraisal are named as externally owned in boundary notes and composition links.", "Searched for a normative standard that assigns a graded health value to a dependency relationship itself rather than to a managed resource. None was found: ITU-T X.731 and RFC 4268 place operational state on the managed entity and FHIR places status on the record, so the degraded value is declared a local synthesis and marked as a coverage gap rather than presented as canonical.", "Attempted to justify a 'no impact' answer from a traversal alone. Rejected: CycloneDX states that objects absent from the dependency graph may have unknown dependencies and should be treated as opaque, and RDF is purely assertional with no way to state absence. The structure therefore blocks the answer unless a covering completeness declaration with the closed-world flag exists.", "Can any bundle, layer, finding or function approve, authorise, schedule, execute or roll back a change? Checked against all eight functions and all nine findings: no. Approval and execution appear only as a required REFERENCE composition link to the change model, in out_of_scope, in a boundary note, and as a mandatory non-authorisation statement on every release.", "Boundary sweep against every composition link: no bundle, layer, finding or function asserts a risk level, approves or executes a mitigation, sets or tests a continuity objective, performs failover, enforces policy, or hosts a referenced system's audit trail. The mitigation finding is deliberately reference-only with an explicit ownership question, and derive-resilience-determination states that it performs no failover, remediation, enforcement or supervisory designation.", "Does any bundle, layer, finding or function grant, deny or evaluate access? Checked: the access-attribute finding, the duty-conflict screening function and the accountable-party resolution function were each written to publish attributes or return a lookup only, with explicit statements that no permission is granted and no obligation discharged. Obligations and advice are noted as discharged by the external enforcement point.", "Tested whether one canonicalization algorithm suffices. It does not: RFC 8785 operates on the JSON data model and RDFC-1.0 on RDF datasets, and RFC 8785 explicitly performs no Unicode normalization. The structure was changed to declare canonicalization per shape family and to refuse any claim of cross-shape digest equality.", "Replay the same declare command twice with the same idempotency key but different payloads: the contract must refuse the second on fingerprint mismatch with no partial effect, rather than creating a second statement or silently overwriting the first.", "Tried to justify a local authorization-filtering or policy-evaluation function so that reads could enforce visibility directly. Rejected: XACML places evaluation at the PDP and enforcement at the PEP, so only a decision reference and an exclusion disclosure are carried here, and no function evaluates or re-evaluates a decision.", "Does any bundle, layer, finding or function grant approval, execution, remediation, delivery or audit-trail authority? Each was re-read against the boundary notes and the relation ledger. Approval, execution, remediation, delivery, audit storage, retention execution and access grants appear only as REFERENCE targets, out-of-scope entries and named owners on the non-authorising declaration. No function effect performs any of them, and the validation function explicitly returns a verdict without enforcing it.", "Ownership creep test: every finding and function was re-read against the boundary notes. Naming an HTTP or MCP interface does not grant enforcement or audit ownership; naming a publication owner does not grant approval authority. dep-proj-fn-package-candidate ends at a handoff, dep-proj-fn-verify-roundtrip only recommends a downgrade, and dep-proj-fn-emit-loss-report blocks but does not override. Audit-trail semantics are explicitly assigned to the external access and audit model in access.audit_requirements." ] }, "researchAdjudication": { "providerMode": "single-provider-waiver", "activeProviders": [ "claude" ], "waivedProviders": [ "grok" ], "providerPolicy": { "contract_version": "1.0.0", "mode": "single-provider-waiver", "effective_at": "2026-09-05T20:28:01Z", "scope": "Stream 01 queued subject-model research from WM-XCT-037 onward", "active_providers": [ "claude" ], "waived_providers": [ { "provider": "grok", "authorized_by": "repository owner", "authorized_at": "2026-09-05T20:28:01Z", "reason": "The repository owner explicitly instructed stream 01 to ignore Grok and finish the work without it after two schema-invalid Grok responses." } ], "review_rule": "Claude-only results require a separate no-tools adversarial audit and remain reviewable drafts with a visible single-provider hold." }, "boundaryDecision": { "entry_kind": "relationship", "status": "reclassified", "rationale": "Two axes must be kept apart. Record plane: the frozen registry sets record_plane=world-model and entry_kind=mixin. 'mixin' is a valid schema token, but as used in that record it classifies packaging and reuse - a format-neutral attribute set embedded in an adopting Dimension's host record - and that packaging claim is accurate and should be preserved as a composition_role rather than as the subject kind. Subject-model plane: the thing actually modelled is a reified, identified, versioned, attributed statement that a dependent endpoint requires a prerequisite endpoint under a typed relation, carrying canonical direction (dependent -> prerequisite), role-bound endpoint references, arity, cardinality, ordering, cycle and transitivity semantics, its own lifecycle (draft/active/superseded/retracted/expired) and its own artifacts. That is a relationship under the schema enum, not a bundle of host attributes. dep-tech-edge-identity and dep-graph-edge-fact are decisive: both declare the edge assertion a first-class record with its own identifier, distinct from both endpoints and from any carrying document, which no mixin classification supports. The reclassification is published as a hold against the frozen registry rather than as an edit to it, and it does not resolve the internal contradiction with dep-life-weak-identity, which asserts the opposite; that reconciliation is required before the record leaves reviewable-draft status." }, "decisions": [ { "concept": "Subject-model entry kind: mixin versus relationship", "disposition": "reclassified to relationship", "rationale": "The delivered subject is a reified, attributed, versioned dependency edge with direction, arity, cardinality and its own lifecycle and artifacts, which the schema enum names a relationship; mixin correctly describes only the packaging axis and is retained as a composition descriptor rather than the subject kind." }, { "concept": "Aggregate root of the model", "disposition": "accepted with second-aggregate caveat", "rationale": "dep-core-assertion-envelope is the defensible root and every other partition binds back to the assertion identifier, but the impact partitions (dep-impact-scenario-frame, dep-impact-result-assurance, dep-graph-derived-projections, dep-res-*) carry their own identity, versioning, supersession and artifacts and read as a second aggregate that should be split or explicitly declared subordinate." }, { "concept": "Impact traversal and computation inside the boundary", "disposition": "rejected as internally inconsistent; correction required", "rationale": "out_of_scope forbids computation of closure, reachability and blast radius, and dep-tech-propagation and dep-graph-analysis-run state the model never traverses or executes, yet dep-impact-fn-derive-affected-set, dep-res-fn-project-downstream-impact and dep-res-fn-derive-resilience-determination each perform traversal or derivation; either the functions must be narrowed to record-only or the scope statement must be widened." }, { "concept": "Strength of assertion identity", "disposition": "accepted as draft; reconciliation required", "rationale": "dep-tech-edge-identity and dep-graph-edge-fact declare a first-class identifier distinct from both endpoints while dep-life-weak-identity declares no independent global identity and a key composed from the host record and endpoint references; both cannot govern the same key and a consumer cannot tell which applies." }, { "concept": "Content digests used as artifact identifiers", "disposition": "rejected for two artifacts", "rationale": "artifact_rules explicitly bars a content digest from serving as identity, but dep-graph-art-analysis-run-descriptor keys on the input snapshot digest and dep-proj-art-canonical-serialization keys on its own algorithm-qualified digest; either declare a content-addressed exception in artifact_rules or re-key both to a minted run identifier with the digest carried as an integrity claim." }, { "concept": "Seven parallel completeness declarations", "disposition": "accepted with normalization requirement", "rationale": "Completeness is independently declared in dep-core-assertion-states, dep-tech-determination, dep-cond-openworld-disclosure, dep-evd-completeness-unknown, dep-graph-completeness-declaration, dep-qry-completeness and dep-rpt-confidence-completeness; one normative statement with per-surface references is needed so the seven cannot disagree about the same subject." }, { "concept": "Declared omissions register", "disposition": "rejected as stale; must be reconciled", "rationale": "known_omissions still assigns impact propagation, blast radius, criticality scoring and the typed dependency vocabulary to an adjacent split reached only through boundary notes, while dep-impact-*, dep-res-criticality-impact, dep-res-resilience-posture and dep-tech-kind-register deliver exactly those in depth; the register appears carried over from per-partition passes and misdescribes the merged whole." }, { "concept": "Ownership boundary against endpoints, policy, audit and retention", "disposition": "accepted", "rationale": "Endpoint non-ownership, delegated policy evaluation and enforcement, audit emission without audit storage, and disposition request without erasure execution are stated consistently across out_of_scope, boundary notes, policies, roles, access rules and function effects, and the referenced-not-copied rule holds throughout the artifact set." }, { "concept": "Composition relations against the frozen contract", "disposition": "deferred", "rationale": "The frozen relationship contract is empty and the registry carries no parent, contains or aligned model identifiers with factor_overlap at 0.06, yet the model mandates references to endpoint, party, authorization, audit, retention, privacy, change, risk, observation and vocabulary-registry models; the required links cannot be minted under a single-provider waiver and need an owner decision." }, { "concept": "Duplicate source registrations", "disposition": "accepted with correction", "rationale": "At least fifteen documents are registered twice or three times under distinct identifiers (RFC 3339 as SRC-007/069/113, RFC 8141 as 009/116, RFC 8785 as 109/122, RFC 6902 as 111/121, RFC 9562 as 008/114, RFC 7089 as 061/131, RFC 8126 as 068/102, OpenVEX as 058/076, DORA as 035/083/094, SemVer as 025/156, CycloneDX 1.6 schema as 021/132, NIST SP 800-30 as 081/088, CISA framing as 030/060), which inflates the declared 156-source count and fragments citation lineage." }, { "concept": "Paywalled and near-cutoff source pins", "disposition": "deferred to live verification", "rationale": "Specific normative content is cited from paywalled ISO/IEC 39075, ISO/IEC 11179-6, ISO/IEC 9075-2 and IEC 61025, 61078 and 60812 whose landing pages cannot substantiate it, and ECMA-424, ECMA-427, OSV 1.9.0, RDF 1.2 Candidate Recommendation, MCP 2026-07-28 and the WHATWG living standard are edition- or date-sensitive and must be re-pinned live." }, { "concept": "Retention and tombstone contract", "disposition": "accepted with residual gap", "rationale": "No hard delete, non-reassignable identifiers, tombstones preserving identifier, final digest, disposition reason and policy reference, and delegated erasure execution are coherent and the GDPR-versus-preservation tension is disclosed; unaddressed is whether a retained digest of an erased record is itself personal data or a re-identification vector." }, { "concept": "Access contract and existence disclosure", "disposition": "accepted with residual risk recorded", "rationale": "Deny-by-default with an external decision point, recorded decision references and bundle-to-artifact scopes is sound, but the dangling-reference exception combined with the rule that redaction preserves the visible existence of an assertion discloses reliance structure to readers who may not read the assertion itself, which is materially sensitive in a supply-chain graph." }, { "concept": "Question-kind balance across 611 questions", "disposition": "accepted with gap noted", "rationale": "Privacy at three, security and event at four and retention at six are thin for a model that names accountable individuals in governance records, emits change events as a contract obligation and carries legal-hold and records-regime markers; the imbalance cannot be remedied by addition under the single-provider waiver." }, { "concept": "Model name and purpose statement", "disposition": "accepted with restatement recommended", "rationale": "The name 'Dependency / Impact' and a purpose framed solely as a reusable mixin undersell a delivered contract spanning 30 bundles, 74 layers, 135 findings, 90 artifacts and 117 functions including record, service, mutation, query, reporting and projection surfaces, which will mislead a reader deciding whether to adopt it." }, { "concept": "Service-layer merge flag", "disposition": "accepted as schema compatibility only", "rationale": "merge_service_layers remains true so the plan validates, but no merge occurs: one active provider supplies the only service_layers block and the waived provider contributes nothing that could be merged into it." } ], "publicationHolds": [ "Live source and version verification hold: none of the 156 registered sources was re-fetched in this no-tools audit. Before any normative status, every URL must be resolved live and every edition pinned, with priority on the paywalled ISO/IEC 39075, ISO/IEC 11179-6, ISO/IEC 9075-2 and IEC 61025, 61078 and 60812 entries whose cited normative content cannot be read from their landing pages, and on the edition-sensitive ECMA-424, ECMA-427, OSV 1.9.0, RDF 1.2 Candidate Recommendation, MCP 2026-07-28, CycloneDX v1.7, ESCO v1.2.1 and WHATWG living-standard entries.", "Single-provider hold, owner-authorized: Grok was waived by the repository owner at 2026-09-05T20:28:01Z after two schema-invalid responses, so no independent second-provider review of this result exists. The publication must carry a visible notice that the result rests on one provider plus this adversarial audit, and must remain a reviewable draft until independent review is restored or the owner records that it will not be.", "Entry-kind reconciliation hold: this audit publishes the subject-model kind as relationship while the frozen registry record vr.wm-xct-037 states entry_kind mixin. The registry record and the published entry must be reconciled, with mixin retained as the packaging or composition descriptor, before the record is treated as consistent with its frozen source.", "Boundary contradiction hold: the scope statement, out_of_scope list, dep-tech-propagation and dep-graph-analysis-run all forbid traversal, closure and impact computation, while dep-impact-fn-derive-affected-set, dep-res-fn-project-downstream-impact and dep-res-fn-derive-resilience-determination perform them. The published draft must display this contradiction and must not be cited as settling what the model does until it is resolved in one direction.", "Composition-contract hold: the frozen relationship contract is empty and the registry lists no aligned models, yet the model requires references to endpoint, party and agent, authorization, audit, retention, privacy, change, risk and observation models. Until those links exist, the declared composition is unsatisfiable and no adopting Dimension can implement the model as written.", "Identity contradiction hold: first-class edge identity in dep-tech-edge-identity and dep-graph-edge-fact conflicts with weak host-dependent identity in dep-life-weak-identity, and two artifacts key on content digests in direct breach of the artifact_rules prohibition. Both defects must be corrected before any identifier guidance in this model is treated as normative.", "Declared-omissions hold: the known_omissions register still assigns impact propagation, blast radius, criticality scoring and the typed dependency vocabulary to an adjacent split, contradicting the bundles that deliver them. The register must be rewritten against the merged whole so readers are not told that delivered scope is absent.", "Source-register hygiene hold: at least fifteen documents are registered under duplicate identifiers, so the declared count of 156 sources overstates the distinct evidence base and source-level citations fragment across identifiers for the same document. De-duplicate and re-map all source_refs before publishing any coverage or authority-tier claim.", "Independent second-provider review was explicitly waived by the repository owner; this Claude-only result remains a reviewable draft." ], "deferredResearch": [ "Graded dependency health: no primary source was found that assigns satisfied, degraded, broken or restored to a dependency relationship rather than to a managed entity or a record. Search IEC 60300-series dependability, ISO/IEC 20000 service management and ITU-T service-quality material, or obtain an owner decision to keep the ordering an explicitly local synthesis with Dimension-owned thresholds.", "Confidence-to-uncertainty bridging: opaque zero-to-one tool confidence in CycloneDX and metrological dispersion under JCGM VIM are not interconvertible, so cross-method comparison and aggregation stay blocked. Research whether any governed confidence-scale vocabulary or published comparability rule exists, or fix a permanent prohibition on cross-scale arithmetic.", "Deploy-phase vocabulary: SPDX LifecycleScopeType has no deploy value and CycloneDX carries no phase facet, so deploy is a local extension with unmapped residue. Investigate whether an SPDX extension request or another governed phase vocabulary can close the gap before the residue accumulates across projections.", "Units-of-measure binding: no registry is bound for capacity, throughput, duration or monetary consequence values, so quantitative fields recorded under dep-tech-relation-nature, dep-soc financial reliance and dep-res impact estimation are not safely comparable across records. Identify a governed unit registry and a declaration rule.", "Change-control alignment: NIST SP 800-53 CM-3 and CM-4, ISO/IEC 20000 and ITIL could not be retrieved live in the source pass, so the review and approval gate rests on an analogous assessment pattern rather than a change-management standard. Retrieve and verify, or restate the gate as an unaligned local construct.", "Tombstone digest after erasure: determine whether a retained content digest of a record that contained personal data is itself personal data or a re-identification vector under the applicable data-protection regime, since the current tombstone rule preserves it by default and the model asserts no jurisdictional position." ] }, "statistics": { "sources": 156, "bundles": 30, "layers": 74, "findings": 135, "questions": 611, "artifacts": 90, "functions": 117 } }