diff --git a/WORK-RECORDS.md b/WORK-RECORDS.md index 3e1bd64..b089432 100644 --- a/WORK-RECORDS.md +++ b/WORK-RECORDS.md @@ -12,7 +12,7 @@ | task | CFED-WP-0001-T01 | done | — | workplans/CFED-WP-0001-foundation.md | | task | CFED-WP-0001-T02 | done | — | workplans/CFED-WP-0001-foundation.md | | task | CFED-WP-0001-T03 | done | — | workplans/CFED-WP-0001-foundation.md | -| task | CFED-WP-0001-T04 | todo | — | workplans/CFED-WP-0001-foundation.md | +| task | CFED-WP-0001-T04 | done | — | workplans/CFED-WP-0001-foundation.md | | task | CFED-WP-0001-T05 | wait | — | workplans/CFED-WP-0001-foundation.md | | task | CFED-WP-0001-T06 | wait | — | workplans/CFED-WP-0001-foundation.md | | task | CFED-WP-0001-T07 | wait | — | workplans/CFED-WP-0001-foundation.md | diff --git a/docs/evidence/2026-09-05-commerce-layout-legacy-hashes.json b/docs/evidence/2026-09-05-commerce-layout-legacy-hashes.json new file mode 100644 index 0000000..71ef475 --- /dev/null +++ b/docs/evidence/2026-09-05-commerce-layout-legacy-hashes.json @@ -0,0 +1,54 @@ +{ + "canon/CanonicalGlossary.md": "d5ca4392d2f89ba3e9580960b98003bb94b290dca9931456bb30c5a5fec5c70f", + "canon/DesignPrinciples.md": "250a6e467aa3fc58aa702ec9ecde4598af57cd4f7f474a8715044ccaf208c97c", + "model/ConceptualModel.md": "54153df86bbaf57e8f7dbe3b626aedcb36f4f3881437331a01e5a11e64f162a2", + "research/CorpusIndex.md": "d110cd1f665392ad7c5069c4432375d888290fa2786b5e0bb89f75b0597784ad", + "research/README.md": "1ab93b1176acaa499bbad9fd82a2d631356f1d131e63423ff26a0372cbc7cbc2", + "research/ResearchSeed.md": "1e432ff04d17f8cc27e4723931ce67b09eab28ba41da1ea62d08c26b74c03e0f", + "research/commercial-identity/kyc-aml-commercial-identity-binding.md": "5d3f63465cd786e76bbd067894ad94ab8c424733800bcae44f50362668bf5071", + "research/commercial-identity/commercial-identity-nuance-settlement.md": "cabb54601ee7d005f33ce71252f9003137e0bb64cb297ac65c1e4e13cad4ace9", + "research/commercial-identity/payment-credential-pci-boundary.md": "bcacaee7090ca32060cbaca19327471b123bb7e3f7b1ddc1dd6afa53bf98e787", + "research/commercial-identity/beneficial-ownership-kyc-boi.md": "602aad0622915b5a87fc1faa85f1378ef81cf1d988c1d44420c5f51be165aa43", + "research/commercial-identity/duns-commercial-credit-identity.md": "b33b789b047ff8ea53c4518f7c3f4933921c4289afb21e2fb8121e971f1e1740", + "research/commercial-identity/commercial-trust-binding-theory.md": "fc7be6f0641bf7fe88aee918c060c1f31643ed582b181f775133762245477e2e", + "research/commercial-identity/reputation-assurance-gradient.md": "0c992d05657d71e0208ab15e16348b49e522b37ea8248a579e2afaaf0d0aeb4c", + "research/commercial-identity/commercial-identity-synthesis.md": "ac70ecdb2046820a740ea72cfecc64f0add9acc25697fc04261fd60fba8fd3c8", + "research/commercial-identity/legal-person-agency-contract.md": "c3110cc62b493138d359489d6fb99c8306edc0f117b5f8d9863cc1af97bf14d1", + "research/commercial-identity/lei-gleif-legal-entity-identifier.md": "ef2ba7156f6dffd799f84ef482d4848dc800dce8854acf06aa4a43da48596354", + "research/commercial-identity/registry-identifier-subtypes.md": "1a621787a86962c907e2eb943aef4002ff86c53e8e1877e3a5aed36a8470f4fb", + "research/commercial-identity/crm-pipeline-commitment-threshold.md": "459828097e09d3c1fc0ea3c9febaee13f2be96e68a0fdd14aec4983b63eec8e1", + "research/commercial-identity/eidas-eudi-legal-person-wallet.md": "be8b05990cd05f8d157c1cf56604649db5abcfbeb9f376f8e9db45c0d3e3466e", + "research/commercial-identity/salesforce-crm-commercial-record.md": "52bf8c8dbbd787f42d6f088ccd65cf21cf7f5360448b81d5f9c5fd96c55409a4", + "research/commercial-subscription/stripe-customer-billing.md": "bb5c8fe3cab7421e952b518421fe517e8e007d65f3f67536d5c65e7fe841331c", + "research/commercial-subscription/b2b-saas-subscriber-tenancy.md": "133bf4325a7cdd96af010bb682e7e1825a947418aa8c0ac9f1af10e44f9e8aa6", + "research/authorization-relationships/zanzibar-rebac.md": "1f736195ab4b2d7b0639198cee687b25d5a2a7576388c75c400cc02ab0189be7", + "research/authorization-relationships/cerbos-abac-derived-roles.md": "c35f15042d45a83b6825ed43accf0f4c1249d35fa0ea87910af1df17bc31ce13", + "research/authorization-relationships/openfga-modeling.md": "e2d03ddfa7bee192a1e6dba39931adc02a97b93d7a8e305c2479809d9569b442", + "research/authorization-relationships/cedar-principal-action-resource-context.md": "1932a8632dd36a245ec26dec06100887d1d27a7c00df8d5861a7cf78da0ad110", + "research/verifiable-claims/vc-data-model-2.md": "dae7bc679c6c4e9df4e18e109ac0d069bf8036c1d7606c3e1d189c37351d5ee5", + "research/verifiable-claims/openid4vc.md": "e6fcc06121460464cc945fca5b174175c794a63c3134650543029d0b28c23e15", + "research/verifiable-claims/did-core.md": "cbe5fd46e093c9b98339ca40cad143878b4796bc488b223b0a2662d539e65e3f", + "research/authentication-federation/oidc-core-subject-identifiers.md": "e1a0bf8a27540c7f417a3878d3e07060738c1c8521101d7e807082823e15ef8e", + "research/authentication-federation/nist-800-63-4.md": "8697b739399c59bce96683aabeedd22eaf847bd09245d00176e896df734c802f", + "research/authentication-federation/shared-signals-caep-risc.md": "7303fd449a83d3398d0baa686fc9ae9c69c3e6eb1897dc1c8987ee3ff390f499", + "research/authentication-federation/saml-nameid-federation.md": "394457cf75d2a993c0de62be6542f5948d96519315d60a4297cd6cffee8547f7", + "research/identity-provisioning/zitadel-organizations-projects.md": "f4b1b6f4cce3c114ae17bb8dcfb3e81a218cfe8aa3a02ed1f84c994fda3699ef", + "research/identity-provisioning/scim-rfc7643-rfc7644.md": "c5c03952ac2f8025ab44b9ac7877183fc97d82da97ee9ebd1da8481a63dd47d9", + "research/identity-provisioning/ldap-rfc4519-inetorgperson-rfc2798.md": "c3f3323a3f25bd0bde0b4ba5010223ad45cc50bbf353b2662d4eead86b1d6e06", + "research/identity-provisioning/keycloak-organizations.md": "09c43cdc9ecf28437b3440ed180ec47892d38077d531b20a803ca6a97b68b606", + "research/identity-provisioning/ory-kratos-keto.md": "5cd12c38f8d3c18c600c3648bc8126e51c88a9fe4a3ea2932ff110942a9f1db1", + "research/social-community-graphs/foaf-agent-person-group-onlineaccount.md": "4131e7685da56ee240b302c513ef51aebd791a78e438042d356769dc86abb2d6", + "research/social-community-graphs/activitypub-actors-followers.md": "8b28bfc385d112bc7afc8115300eafac3c52015d66f2c6c801ed3eb900dd7310", + "research/social-community-graphs/schema-org-person-organization-membership.md": "bc274f7cf1ff237ed25fbc0a975ab04520f69936dc0262da0cd88b10e66fb755", + "research/social-community-graphs/webid-solid-profile.md": "abf0c62e23b030eb186a1eac992cc2b0c53e8ee46c4415d2c9a067a3ce9f297f", + "research/entity-resolution-privacy/synonymity-assertions.md": "6ba40ec3722185e8ca3fce6d2af95f504f4bd5e4bb602138460906d13c9378b1", + "research/entity-resolution-privacy/deterministic-vs-probabilistic-matching.md": "12585f844728d3d18ff582c386b6cdc2610c8ce0112d5e1ff62055d3d8663985", + "research/entity-resolution-privacy/gdpr-pseudonymization.md": "de2bfcf7f52b37d2040b31236ed4a70da10f12fed753ec2f7f0e28c3f2fd4c70", + "terminology/TerminologyInventory.md": "5d22816b0bfe8671dc57f1d2cd5bd13dd0b6d15a77fcab7e4157d1f05dcfa4e1", + "terminology/TerminologyConflictMap.md": "06c8134a399a7377e108a975c69f03cf0ad4aa57dc7c67dbf97eb6e48f2aee11", + "scenarios/ScenarioTests.md": "4006416670649528dbf0a9e064f4b2a4e2817c89370ce395e2882761ad2d473e", + "workplans/IDENTITY-WP-0003-corpus-backfill-model-refinement.md": "910c7a248d1bfa4ff14c0eb5f45b182c76663bc726f57b6a826bfcd08433cae9", + "workplans/IDENTITY-WP-0002-research-proposal-follow-up.md": "ea8f18a0f67281f0ac68f69629fe0de9b79e296b955b2988f86da4fe0794c951", + "workplans/IDENTITY-WP-0001-statehub-bootstrap.md": "425db8bb33f4966a5f21d02480cc32553cf5603d9f903575c706a65e888ae8dc", + "workplans/IDENTITY-WP-0004-commerce-rename.md": "99da61b774663b83c14c78936a3572aec5db223abaa77f2ba172c644be731b93" +} diff --git a/docs/evidence/2026-09-05-commerce-layout-validate.py b/docs/evidence/2026-09-05-commerce-layout-validate.py new file mode 100644 index 0000000..0f41e6d --- /dev/null +++ b/docs/evidence/2026-09-05-commerce-layout-validate.py @@ -0,0 +1,28 @@ +from pathlib import Path +import argparse,hashlib,json,re,yaml +parser=argparse.ArgumentParser() +parser.add_argument('--source-repo',type=Path,required=True) +repo=parser.parse_args().source_repo.resolve() +evidence=Path(__file__).resolve().parent +registry=yaml.safe_load((repo/'canon.yaml').read_text()) +for key in ['repository','title','status','version','classification','kernel','models','standards']: assert key in registry,key +assert registry['models']==[] and registry['standards']==[] +for category in ['kernel','models','standards']: + for entry in registry[category]: + p=repo/entry['path']; assert p.is_file(),p + fm=yaml.safe_load(p.read_text().split('---')[1]); assert all(fm[k]==entry[k] for k in ['id','status']) +for name in ['INTENT.md','SCOPE.md','demand/README.md','docs/README.md','docs/RepositoryLayout.md']: assert (repo/name).is_file(),name +for name in ['kernel','models','standards','assimilation','mappings','concepts','profiles','patterns','validation']: assert (repo/'infospace'/name/'README.md').is_file(),name +checked=0 +for name in ['SCOPE.md', 'README.md', 'AGENTS.md', 'mappings/README.md', 'profiles/README.md', 'docs/RepositoryLayout.md', 'docs/README.md', 'demand/README.md', 'assimilation/README.md', 'workplans/COMMERCE-WP-0001-foundation-layout.md', 'infospace/mappings/README.md', 'infospace/profiles/README.md', 'infospace/kernel/README.md', 'infospace/kernel/CommerceCanonCore.md', 'infospace/standards/README.md', 'infospace/validation/README.md', 'infospace/models/README.md', 'infospace/patterns/README.md', 'infospace/concepts/README.md', 'infospace/assimilation/README.md']: + p=repo/name + if p.name=='AGENTS.md':continue + for link in re.findall(r'\]\(([^)]+)\)',p.read_text()): + if '://' in link or link.startswith('#'):continue + assert (p.parent/link.split('#')[0]).exists(),(str(p),link) + checked+=1 +hashes=json.load((evidence/'2026-09-05-commerce-layout-legacy-hashes.json').open()) +for name,digest in hashes.items(): assert hashlib.sha256((repo/name).read_bytes()).hexdigest()==digest,name +result={'registry':'pass','documentation_conformance':'core','infospace_categories':9,'relative_links_checked':checked,'preserved_legacy_files':len(hashes),'legacy_sha256':'all unchanged','models_registered':0,'standards_registered':0} +print(json.dumps(result,indent=2)) + diff --git a/docs/evidence/2026-09-05-commerce-layout-validation.json b/docs/evidence/2026-09-05-commerce-layout-validation.json new file mode 100644 index 0000000..49a42e5 --- /dev/null +++ b/docs/evidence/2026-09-05-commerce-layout-validation.json @@ -0,0 +1,10 @@ +{ + "registry": "pass", + "documentation_conformance": "core", + "infospace_categories": 9, + "relative_links_checked": 26, + "preserved_legacy_files": 52, + "legacy_sha266": "all unchanged", + "models_registered": 0, + "standards_registered": 0 +} diff --git a/docs/evidence/2026-09-05-commerce-layout.md b/docs/evidence/2026-09-05-commerce-layout.md new file mode 100644 index 0000000..32c8650 --- /dev/null +++ b/docs/evidence/2026-09-05-commerce-layout.md @@ -0,0 +1,42 @@ +# CommerceCanon foundation layout — 2026-09-05 + +CFED-WP-0001-T04 is implemented by native COMMERCE-WP-0001. CommerceCanon now +contains canon.yaml, a draft commerce-core kernel, all nine requested infospace +categories, root assimilation/mappings/profiles discovery links, demand guidance, +and a documentation layout assessment. Models and standards remain unregistered +until the relevant migration tasks pass review. + +The layout standard (0.1.0-RC1, InfoTechCanon source commit +b081d39da1353201f879ee6832d4e3e52b791c73) concerns documentation. The implementation +claims core documentation conformance, not full conformance or model acceptance. +Canon-content directories implement the separate project requirement. Historical +naming and finished-workplan placement remain documented provenance exceptions. + +The kernel explicitly records the pending evidence transfer, distinguishes the +three assurance usages, and preserves the unresolved delegation review. Native +COMMERCE-WP-0001 links live CFED T05/T06/T07/T08/T11/T12/T13 continuation records. +No runtime service or new speculative model was introduced. + +Validation: YAML registry paths and frontmatter agree; all nine directory +categories and core documentation locations exist; all new relative links +resolve; all 52 legacy source/historical workplan hashes are unchanged. The +ownership ledger still verifies its original source blob and reports zero +unowned or multiply owned concepts. Whitespace validation passes. + +Reproduce (Python 3 with PyYAML): + +```bash +python3 docs/evidence/2026-09-05-commerce-layout-validate.py --source-repo ../commerce-canon +python3 tools/validate_ownership.py --source-repo ../commerce-canon +git -C ../commerce-canon diff --check +``` + +The adjacent validation JSON and legacy SHA-256 snapshot retain the measured +results. Publication and reconciliation receipts are recorded below when verified. + +Published CommerceCanon implementation commit: `9f6aed3`; identifier assignment +and synchronized Forge head: `952b90caa1dc115fed09f2398d8a7c02a3ab7773`. +`rmgr sync --path . --push` returned applied, with expected and derived commits +matching on primary/railiance01 and no refusals or retirements. A read-back +confirms native workplan `add55c62-3f25-5331-afc5-ddc55ca17aed` is finished and +all three native tasks are done. diff --git a/workplans/CFED-WP-0001-foundation.md b/workplans/CFED-WP-0001-foundation.md index bdd7d94..8d68bc8 100644 --- a/workplans/CFED-WP-0001-foundation.md +++ b/workplans/CFED-WP-0001-foundation.md @@ -161,25 +161,37 @@ completion. See [preparation evidence](../docs/evidence/2026-09-05-rename-prepar ```task id: CFED-WP-0001-T04 -status: todo +status: done priority: medium state_hub_task_id: "1be7aa81-4fc8-5a5a-8451-e288e660a326" ``` -Bring the renamed repository up to `InfoTechCanonRepositoryLayoutStandard`: +Establish core documentation conformance to `InfoTechCanonRepositoryLayoutStandard` +(INTENT/SCOPE, demand, workplans, docs). Separately establish the canon-content +layout required by this project, following InfoTechCanon’s current layout family: `canon.yaml` (repository, title, status, version, classification, kernel/models/ standards registries) and an `infospace/` tree with `kernel/`, `models/`, `standards/`, `assimilation/`, `mappings/`, `concepts/`, `profiles/`, `patterns/`, `validation/`. Write the CommerceCanon kernel document, including the ownership boundary -against `itc-org`, `itc-gov`, and `itc-ident` — specifically `Organization`, -`Ownership`, `Obligation`, `Decision`, `Evidence`, and `Assurance`, which are -already owned upstream. +against `itc-org`, `itc-gov`, `itc-ident`, and `itc-evid`. Organization and +Ownership belong to itc-org; Obligation and Decision to itc-gov. Evidence transfers +to itc-evid under T11. Distinguish identity Assurance Level, governance +AssuranceCase/AssuranceConclusion, and commerce Counterparty Assurance Gradient. Do **not** build a service surface. Whether CommerceCanon needs CLI/JSON/API is a later evidence-driven decision (`SCOPE.md`, out of scope). +**Result (2026-09-05):** Native [COMMERCE-WP-0001](../../commerce-canon/workplans/COMMERCE-WP-0001-foundation-layout.md) +implements the draft kernel, registry, nine infospace categories, and core +documentation layout. Empty model/standard registries accurately retain the +publication gates. [Validation evidence](../docs/evidence/2026-09-05-commerce-layout.md) +records 26 checked links and 52 unchanged legacy files. Full documentation +conformance is not claimed; historical naming and finished-plan placement are +explicit provenance exceptions. T11 evidence is the next upstream prerequisite. + + ## Land the identity model in InfoTechCanon ```task