Privacy Aggregation & Cohort Floor
Aggregated statistics at cohort grain with k-anonymity floors
Bundle → Layer → Finding → Questions Incomplete
3 bundles · 6 layers · 0 findings · 0 questions
cohort Which population slices may be looked at
definition
dimensions, membership rules and validity windows of cohorts
floors
minimum cohort sizes per sensitivity of the underlying data
computation Turning members into numbers safely
measures
statistics computed over cohorts and their methods
protection
cell suppression, noise addition and privacy budget accounting
release What actually leaves
review
pre-release disclosure checks against floors and budgets
publication
released series with method and provenance attached
Note: Legacy card: layers named, findings and questions never written.
Classifiers Filled
- Family
- World Models
- Category
- Cross-cutting context
- Entry kind
- mixin
- Navigation path
- NAV.XCT.PRV
- Domain
- XCT.PRV
- Industry
- Cross-industry
- Tags
- privacyaggregationfloorxct.prv
- Also called
- S5
What it is Derived, awaiting review
This meta-model describes how the state of a population is sensed without exposing any person in it: statistics are computed over cohorts, never below a minimum cohort size, with suppression and noise where counts run thin.
Note: First sentence of the legacy card introduction.
Why it exists Filled
Aggregated statistics at cohort grain with k-anonymity floors
Distinguishing features Derived, awaiting review
- It is its own model because aggregation is a distinct trade with its own artifacts: cohort definitions, k-floors, noise budgets and disclosure review are reusable machinery that many consumers rely on, and the guarantees only hold if that machinery is modelled and checked in one place.
What robots and AI may and may not do Derived, awaiting review
Must not
- This meta-model describes how the state of a population is sensed without exposing any person in it: statistics are computed over cohorts, never below a minimum cohort size, with suppression and noise where counts run thin.
- seriesSubscription: a consumer receives published series and their revisions; never anything below the published grain.
- methodAudit: an auditor examines cohort definitions, floors, budgets and methods; microdata is never in scope.
Moral aspects Missing, in the backlog
Not described yet. This gap is in the card backlog.
Owners Filled
Steward
A statistics office steward archetype operates the model within its statutory mandate: it computes and releases, but the underlying data stays with its owners, and the steward's own reads run under S2 contracts and land in the S4 log like anyone else's.
Links to other meta-models Filled
references
- world.ownership - aggregation never transfers control; source objects remain their holders' throughout.
- world.accessContract - sensing requests and series subscriptions are themselves access contracts.
- world.disclosureScope - the aggregation grains that S3 policies point to are defined and enforced here.
- world.accessAudit - every sensing run, review and release is logged.
- world.person - population registers of the person model are the typical cohort source.
imports
- differential-privacy-practice - ALIGN: noise addition and budget accounting semantics.
- sdmx - ALIGN: the exchange shape of published statistical series.
requires
- vr.wm-pol-014
- vr.wm-xct-004
What else AI and robots need to interact with it Incomplete
Identity and identifiers required Missing, in the backlog
Not described yet. This gap is in the card backlog.
Direct properties not applicable Not applicable
Not applicable
Institutional or informational subject: no invented physical properties.
Recognition optional Missing, in the backlog
Not described yet. This gap is in the card backlog.
Capabilities and actions required Derived, awaiting review
- cohortDefined: a new population slice was defined and its membership counted.
- floorAdjusted: a minimum cohort size was raised or lowered with recorded rationale.
- measureComputed: a statistic was computed over a cohort inside the protected environment.
- cellSuppressed: a thin cell was withheld or merged before release.
- budgetSpent: a release drew down a noise budget, or a budget ran out and blocked further sensing for the period.
- reviewPassed: a release candidate cleared disclosure review against floors and budgets.
- seriesPublished: reviewed aggregates were released with method and provenance.
Legacy events listed as state transitions.
Hazards and failure modes optional Missing, in the backlog
Not described yet. This gap is in the card backlog.
Standards and interfaces required Derived, awaiting review
- seriesSubscription: a consumer receives published series and their revisions; never anything below the published grain.
- sensingRequest: a party commissions a new aggregate over defined cohorts; honored only above floors and within budgets.
- methodAudit: an auditor examines cohort definitions, floors, budgets and methods; microdata is never in scope.
- publicStatistics: published series only; omits cohorts under floor, suppressed cells and all member-level data.
- methodologySheet: definitions, floors, suppression and noise methods per series; omits the values' underlying sources.
- budgetLedger: budget allocation and spend per source and period; omits what the queries were about.
Context of use required Missing, in the backlog
Not described yet. This gap is in the card backlog.
Sources Missing, in the backlog
Not described yet. This gap is in the card backlog.
Open questions
- Superseded by a researched world model? Map this legacy card to its successor or retire it.
Machine files
Provenance
legacy MMAS card (world-models v0.2) · legacy
Built from: models/world-s5-privacy-aggregation-and-cohort-floor/spec.yaml, models/docs/security-ownership-access/S5-privacy-aggregation-and-cohort-floor.md