Access Audit
Append-only log of every read and grant
Bundle → Layer → Finding → Questions Incomplete
3 bundles · 6 layers · 0 findings · 0 questions
ledger The immutable record itself
entries
sealed records of access events in write order
chainIntegrity
hash links between entries and periodic published anchors
evidence What each entry proves
attribution
who read, as which resolved actor, under which contract
servedShape
which projection policy version and template fingerprint shaped the disclosure
oversight Who may see the log and for how long
ownerVisibility
the owner's standing right to their own timeline
retentionAndSealing
how long entries persist and when they are sealed from further detail queries
Note: Legacy card: layers named, findings and questions never written.
Classifiers Filled
- Family
- World Models
- Category
- Cross-cutting context
- Entry kind
- mixin
- Navigation path
- NAV.XCT.AUD
- Domain
- XCT.AUD
- Industry
- Cross-industry
- Tags
- accessauditxct.aud
- Also called
- S4
What it is Derived, awaiting review
This meta-model is the append-only memory of the cluster: every read, every grant, every denial, recorded once and never rewritten.
Note: First sentence of the legacy card introduction.
Why it exists Filled
Append-only log of every read and grant
Distinguishing features Derived, awaiting review
- It exists as its own model because evidence has different physics from the data it describes: entries are written by many systems, owned by none of them, chained so that tampering is detectable, and readable above all by the person whose data was touched.
What robots and AI may and may not do Derived, awaiting review
Must not
- This meta-model is the append-only memory of the cluster: every read, every grant, every denial, recorded once and never rewritten.
- An audit registrar archetype operates the log but owns none of its content: it may not read entry payloads beyond what operation requires, and it cannot amend them at all.
Moral aspects Missing, in the backlog
Not described yet. This gap is in the card backlog.
Owners Filled
Steward
An audit registrar archetype operates the log but owns none of its content: it may not read entry payloads beyond what operation requires, and it cannot amend them at all.
Links to other meta-models Filled
references
- world.ownership - entries name registered objects, and owner visibility resolves through ownership records.
- world.accessContract - permitted events cite the contract exercised; the log is the contract's execution history.
- world.disclosureScope - each disclosure entry carries the policy version and template fingerprint that shaped it.
- world.accessEnforcement - the log is the primary evidence source for violation signals and enforcement cases.
imports
- merkle-logs - COMPOSE: the tree structure underlying anchors and inclusion proofs.
- mu-event - EXTEND: the event primitive that access events specialize.
- rfc-9162 - ALIGN: the verifiable-log pattern of published anchors and third-party auditability.
requires
- vr.wm-pol-014
- vr.wm-xct-007
What else AI and robots need to interact with it Incomplete
Identity and identifiers required Missing, in the backlog
Not described yet. This gap is in the card backlog.
Direct properties not applicable Not applicable
Not applicable
Institutional or informational subject: no invented physical properties.
Recognition optional Missing, in the backlog
Not described yet. This gap is in the card backlog.
Capabilities and actions required Derived, awaiting review
- readRecorded: a permitted read of someone's data was written to the log.
- grantRecorded: the creation, amendment or revocation of an access contract was written to the log.
- denialRecorded: an attempted read was refused and the refusal preserved.
- entrySealed: a batch of events was wrapped, hashed and chained.
- anchorPublished: a root hash for a range of entries was made public.
- proofIssued: an inclusion proof was produced for a challenged entry.
- inconsistencyDetected: a verification failed, indicating tampering or loss between entries and anchors.
Legacy events listed as state transitions.
Hazards and failure modes optional Missing, in the backlog
Not described yet. This gap is in the card backlog.
Standards and interfaces required Derived, awaiting review
- ownerAuditFeed: the owner of any object receives, on demand or by subscription, every entry that touched their objects.
- oversightExtract: the audit registrar provides aggregate, identity-free extracts for systemic oversight of access patterns.
- proofService: any party obtains anchors and inclusion proofs to verify log integrity without reading entry contents.
- ownerTimeline: who read my data, when, under which contract; omits every other owner's entries.
- readerActivitySummary: aggregate read counts and patterns per reader; omits the identities of touched objects and owners.
- integrityBundle: anchors, chain heads and proofs only; omits all event payload.
Context of use required Filled
- The standing beneficiary is the data owner, whose right to their own timeline is not itself contract-gated, while all other access follows S1/S2.
Sources Missing, in the backlog
Not described yet. This gap is in the card backlog.
Open questions
- Superseded by a researched world model? Map this legacy card to its successor or retire it.
Machine files
Provenance
legacy MMAS card (world-models v0.2) · legacy
Built from: models/world-s4-access-audit/spec.yaml, models/docs/security-ownership-access/S4-access-audit.md