← Back to catalogue
Previous version

Privacy Aggregation & Cohort Floor

vr.wm-xct-005 · world-s5-privacy-aggregation-and-cohort-floor

Aggregated statistics at cohort grain with k-anonymity floors

World Models Cross-cutting context XCT.PRV

Bundle → Layer → Finding → Questions Incomplete

3 bundles · 6 layers · 0 findings · 0 questions

cohort Which population slices may be looked at

definition

dimensions, membership rules and validity windows of cohorts

floors

minimum cohort sizes per sensitivity of the underlying data

computation Turning members into numbers safely

measures

statistics computed over cohorts and their methods

protection

cell suppression, noise addition and privacy budget accounting

release What actually leaves

review

pre-release disclosure checks against floors and budgets

publication

released series with method and provenance attached

Note: Legacy card: layers named, findings and questions never written.

Classifiers Filled

Family
World Models
Category
Cross-cutting context
Entry kind
mixin
Navigation path
NAV.XCT.PRV
Domain
XCT.PRV
Industry
Cross-industry
Tags
privacyaggregationfloorxct.prv
Also called
S5

What it is Derived, awaiting review

This meta-model describes how the state of a population is sensed without exposing any person in it: statistics are computed over cohorts, never below a minimum cohort size, with suppression and noise where counts run thin.

Note: First sentence of the legacy card introduction.

Why it exists Filled

Aggregated statistics at cohort grain with k-anonymity floors

Distinguishing features Derived, awaiting review

  • It is its own model because aggregation is a distinct trade with its own artifacts: cohort definitions, k-floors, noise budgets and disclosure review are reusable machinery that many consumers rely on, and the guarantees only hold if that machinery is modelled and checked in one place.

What robots and AI may and may not do Derived, awaiting review

Must not

  • This meta-model describes how the state of a population is sensed without exposing any person in it: statistics are computed over cohorts, never below a minimum cohort size, with suppression and noise where counts run thin.
  • seriesSubscription: a consumer receives published series and their revisions; never anything below the published grain.
  • methodAudit: an auditor examines cohort definitions, floors, budgets and methods; microdata is never in scope.

Moral aspects Missing, in the backlog

Not described yet. This gap is in the card backlog.

Owners Filled

Steward

A statistics office steward archetype operates the model within its statutory mandate: it computes and releases, but the underlying data stays with its owners, and the steward's own reads run under S2 contracts and land in the S4 log like anyone else's.

Links to other meta-models Filled

references

  • world.ownership - aggregation never transfers control; source objects remain their holders' throughout.
  • world.accessContract - sensing requests and series subscriptions are themselves access contracts.
  • world.disclosureScope - the aggregation grains that S3 policies point to are defined and enforced here.
  • world.accessAudit - every sensing run, review and release is logged.
  • world.person - population registers of the person model are the typical cohort source.

imports

  • differential-privacy-practice - ALIGN: noise addition and budget accounting semantics.
  • sdmx - ALIGN: the exchange shape of published statistical series.

requires

  • vr.wm-pol-014
  • vr.wm-xct-004

What else AI and robots need to interact with it Incomplete

Identity and identifiers required Missing, in the backlog

Not described yet. This gap is in the card backlog.

Direct properties not applicable Not applicable

Not applicable

Institutional or informational subject: no invented physical properties.

Recognition optional Missing, in the backlog

Not described yet. This gap is in the card backlog.

Capabilities and actions required Derived, awaiting review

  • cohortDefined: a new population slice was defined and its membership counted.
  • floorAdjusted: a minimum cohort size was raised or lowered with recorded rationale.
  • measureComputed: a statistic was computed over a cohort inside the protected environment.
  • cellSuppressed: a thin cell was withheld or merged before release.
  • budgetSpent: a release drew down a noise budget, or a budget ran out and blocked further sensing for the period.
  • reviewPassed: a release candidate cleared disclosure review against floors and budgets.
  • seriesPublished: reviewed aggregates were released with method and provenance.

Legacy events listed as state transitions.

Hazards and failure modes optional Missing, in the backlog

Not described yet. This gap is in the card backlog.

Standards and interfaces required Derived, awaiting review

  • seriesSubscription: a consumer receives published series and their revisions; never anything below the published grain.
  • sensingRequest: a party commissions a new aggregate over defined cohorts; honored only above floors and within budgets.
  • methodAudit: an auditor examines cohort definitions, floors, budgets and methods; microdata is never in scope.
  • publicStatistics: published series only; omits cohorts under floor, suppressed cells and all member-level data.
  • methodologySheet: definitions, floors, suppression and noise methods per series; omits the values' underlying sources.
  • budgetLedger: budget allocation and spend per source and period; omits what the queries were about.

Context of use required Missing, in the backlog

Not described yet. This gap is in the card backlog.

Sources Missing, in the backlog

Not described yet. This gap is in the card backlog.

Open questions

  • Superseded by a researched world model? Map this legacy card to its successor or retire it.

Machine files

Provenance

legacy MMAS card (world-models v0.2) · legacy

Built from: models/world-s5-privacy-aggregation-and-cohort-floor/spec.yaml, models/docs/security-ownership-access/S5-privacy-aggregation-and-cohort-floor.md