← Back to catalogue
Previous version

Access Audit

vr.wm-xct-004 · world-s4-access-audit

Append-only log of every read and grant

World Models Cross-cutting context XCT.AUD

Bundle → Layer → Finding → Questions Incomplete

3 bundles · 6 layers · 0 findings · 0 questions

ledger The immutable record itself

entries

sealed records of access events in write order

chainIntegrity

hash links between entries and periodic published anchors

evidence What each entry proves

attribution

who read, as which resolved actor, under which contract

servedShape

which projection policy version and template fingerprint shaped the disclosure

oversight Who may see the log and for how long

ownerVisibility

the owner's standing right to their own timeline

retentionAndSealing

how long entries persist and when they are sealed from further detail queries

Note: Legacy card: layers named, findings and questions never written.

Classifiers Filled

Family
World Models
Category
Cross-cutting context
Entry kind
mixin
Navigation path
NAV.XCT.AUD
Domain
XCT.AUD
Industry
Cross-industry
Tags
accessauditxct.aud
Also called
S4

What it is Derived, awaiting review

This meta-model is the append-only memory of the cluster: every read, every grant, every denial, recorded once and never rewritten.

Note: First sentence of the legacy card introduction.

Why it exists Filled

Append-only log of every read and grant

Distinguishing features Derived, awaiting review

  • It exists as its own model because evidence has different physics from the data it describes: entries are written by many systems, owned by none of them, chained so that tampering is detectable, and readable above all by the person whose data was touched.

What robots and AI may and may not do Derived, awaiting review

Must not

  • This meta-model is the append-only memory of the cluster: every read, every grant, every denial, recorded once and never rewritten.
  • An audit registrar archetype operates the log but owns none of its content: it may not read entry payloads beyond what operation requires, and it cannot amend them at all.

Moral aspects Missing, in the backlog

Not described yet. This gap is in the card backlog.

Owners Filled

Steward

An audit registrar archetype operates the log but owns none of its content: it may not read entry payloads beyond what operation requires, and it cannot amend them at all.

Links to other meta-models Filled

references

  • world.ownership - entries name registered objects, and owner visibility resolves through ownership records.
  • world.accessContract - permitted events cite the contract exercised; the log is the contract's execution history.
  • world.disclosureScope - each disclosure entry carries the policy version and template fingerprint that shaped it.
  • world.accessEnforcement - the log is the primary evidence source for violation signals and enforcement cases.

imports

  • merkle-logs - COMPOSE: the tree structure underlying anchors and inclusion proofs.
  • mu-event - EXTEND: the event primitive that access events specialize.
  • rfc-9162 - ALIGN: the verifiable-log pattern of published anchors and third-party auditability.

requires

  • vr.wm-pol-014
  • vr.wm-xct-007

What else AI and robots need to interact with it Incomplete

Identity and identifiers required Missing, in the backlog

Not described yet. This gap is in the card backlog.

Direct properties not applicable Not applicable

Not applicable

Institutional or informational subject: no invented physical properties.

Recognition optional Missing, in the backlog

Not described yet. This gap is in the card backlog.

Capabilities and actions required Derived, awaiting review

  • readRecorded: a permitted read of someone's data was written to the log.
  • grantRecorded: the creation, amendment or revocation of an access contract was written to the log.
  • denialRecorded: an attempted read was refused and the refusal preserved.
  • entrySealed: a batch of events was wrapped, hashed and chained.
  • anchorPublished: a root hash for a range of entries was made public.
  • proofIssued: an inclusion proof was produced for a challenged entry.
  • inconsistencyDetected: a verification failed, indicating tampering or loss between entries and anchors.

Legacy events listed as state transitions.

Hazards and failure modes optional Missing, in the backlog

Not described yet. This gap is in the card backlog.

Standards and interfaces required Derived, awaiting review

  • ownerAuditFeed: the owner of any object receives, on demand or by subscription, every entry that touched their objects.
  • oversightExtract: the audit registrar provides aggregate, identity-free extracts for systemic oversight of access patterns.
  • proofService: any party obtains anchors and inclusion proofs to verify log integrity without reading entry contents.
  • ownerTimeline: who read my data, when, under which contract; omits every other owner's entries.
  • readerActivitySummary: aggregate read counts and patterns per reader; omits the identities of touched objects and owners.
  • integrityBundle: anchors, chain heads and proofs only; omits all event payload.

Context of use required Filled

  • The standing beneficiary is the data owner, whose right to their own timeline is not itself contract-gated, while all other access follows S1/S2.

Sources Missing, in the backlog

Not described yet. This gap is in the card backlog.

Open questions

  • Superseded by a researched world model? Map this legacy card to its successor or retire it.

Machine files

Provenance

legacy MMAS card (world-models v0.2) · legacy

Built from: models/world-s4-access-audit/spec.yaml, models/docs/security-ownership-access/S4-access-audit.md