shape
What an output looks like
fieldSelection`: include and exclude lists over property paths · `transformation`: redaction, generalization, bucketing, pseudonymization per field · `aggregationGrain`: rollup definitions when only summaries leave
This meta-model describes the shape data is allowed to leave in: which fields, after which transformations, at which grain. A grant (S2) says that data may flow; this model says what the flow looks like, from a full subset through redacted and generalized forms down to aggregate-only shapes. It is its own model because disclosure shapes are reusable, versioned artifacts in their own right: one policy is authored once, reviewed once, and then bound into many contracts and audiences.
What an output looks like
fieldSelection`: include and exclude lists over property paths · `transformation`: redaction, generalization, bucketing, pseudonymization per field · `aggregationGrain`: rollup definitions when only summaries leave
Where a shape applies
policyAttachment`: attaching policies to contracts, object types and audiences · `sensitivityTiers`: classification of fields that constrains which shapes are lawful
How policies are made and evolve
authoringAndApproval`: drafting and owner sign-off · `versioning`: supersession and the version each disclosure was served under
Catalogue-native findings must describe the information grouped by each layer. This legacy version does not declare them separately.
Questions, artifact requirements and serial naming rules are required by Vercy vNext; they remain unassigned in this reference version.
Format-independent core. Concrete artifact formats and naming prefixes are not declared in this legacy version.
CRUD procedures and interface bindings are not declared in this legacy version.
The data owner stewards every policy over their objects; approval is theirs and cannot be delegated beyond what S1 mandates record. Reading policy data is itself an S2-granted act, and every served shape leaves a trace in S4.