Institutional operation evidence
Operational Evidence Schema
Direct answer
The K03 schema contains 26 fields and controlled states DESCRIBED, IMPLEMENTED, DEPLOYED, OPERATING, DEGRADED, SUSPENDED, RETIRED, PLANNED, UNKNOWN, UNAVAILABLE, STALE. A panel describes evidence; it cannot create authority or prove operation by its own existence.
Field schema
| Field | Label | Type | Required | Definition | Non-proof boundary |
|---|---|---|---|---|---|
institutionName | Institution name | string | Yes | Canonical public name of the institution. | Field presence alone does not prove truth, authority, currentness, or operation. |
stableInstitutionId | Stable institution ID | string | Yes | Persistent identifier independent of display name. | Field presence alone does not prove truth, authority, currentness, or operation. |
constitutionalAuthority | Constitutional authority | string | Yes | Citation to the rule or decision creating competence. | Field presence alone does not prove truth, authority, currentness, or operation. |
institutionalClass | Institutional class | string | Yes | Controlled class such as governance, registry, assurance, capital, or knowledge. | Field presence alone does not prove truth, authority, currentness, or operation. |
operationalState | Operational state | string | Yes | Current evidence-bounded state from the controlled vocabulary. | Field presence alone does not prove truth, authority, currentness, or operation. |
creationEventId | Creation event ID | string | No | Stable identifier for the authorized creation event. | Field presence alone does not prove truth, authority, currentness, or operation. |
publicKeyFingerprint | Public-key fingerprint | string | No | Fingerprint of the current public verification key. | Field presence alone does not prove truth, authority, currentness, or operation. |
currentSigningKeyStatus | Current signing-key status | string | No | Active, rotated, revoked, unavailable, or unknown. | Field presence alone does not prove truth, authority, currentness, or operation. |
serviceEndpoint | Service endpoint | string | No | Canonical endpoint for the current service. | Field presence alone does not prove truth, authority, currentness, or operation. |
apiSpecification | API specification | string | No | Public specification for implemented interfaces. | Field presence alone does not prove truth, authority, currentness, or operation. |
protocolVersion | Protocol version | string | No | Version of the operational protocol. | Field presence alone does not prove truth, authority, currentness, or operation. |
softwareRelease | Software release | string | No | Current deployed software release, not merely latest available source release. | Field presence alone does not prove truth, authority, currentness, or operation. |
sourceCommitOrReleaseHash | Source commit or release hash | string | No | Digest or revision bound to the software release. | Field presence alone does not prove truth, authority, currentness, or operation. |
reproducibleBuildStatus | Reproducible-build status | string | No | Result and evidence location for deterministic build comparison. | Field presence alone does not prove truth, authority, currentness, or operation. |
dependencyList | Dependency list | array | No | Declared operational dependencies and versions. | Field presence alone does not prove truth, authority, currentness, or operation. |
lastStateTransition | Last state transition | object | No | Authorized transition ID, prior state, new state, time, and evidence. | Field presence alone does not prove truth, authority, currentness, or operation. |
lastSignedAction | Last signed action | object | No | Most recent attributable public action and signature evidence. | Field presence alone does not prove truth, authority, currentness, or operation. |
signedPublicArtifactCount | Number of signed public artifacts | integer | No | Count under a defined ledger or catalog scope. | Field presence alone does not prove truth, authority, currentness, or operation. |
latestLedgerEvent | Latest ledger event | object | No | Most recent relevant ledger event with stable ID and time. | Field presence alone does not prove truth, authority, currentness, or operation. |
uptimeWindow | Uptime window | object | No | Observed period, measurement method, result, and limitations. | Field presence alone does not prove truth, authority, currentness, or operation. |
lastVerificationTime | Last verification time | string | Yes | Time of the most recent authorized verification observation. | Field presence alone does not prove truth, authority, currentness, or operation. |
knownIncidents | Known incidents | array | No | Public incidents affecting operation, integrity, authority, or availability. | Field presence alone does not prove truth, authority, currentness, or operation. |
plannedCapabilities | Planned capabilities | array | No | Future functions explicitly separated from current operation. | Field presence alone does not prove truth, authority, currentness, or operation. |
machineReadableRecordUrl | Machine-readable record URL | string | Yes | Canonical URL for the synchronized machine record. | Field presence alone does not prove truth, authority, currentness, or operation. |
verificationWindow | Verification window | object | Yes | Purpose, start, end or expiry, method, and observer. | Field presence alone does not prove truth, authority, currentness, or operation. |
limitations | Evidence limitations | array | Yes | What the panel and its fields do not establish. | Field presence alone does not prove truth, authority, currentness, or operation. |
State discipline
DESCRIBED, IMPLEMENTED, DEPLOYED, OPERATING, DEGRADED, SUSPENDED, RETIRED, PLANNED, UNKNOWN, UNAVAILABLE, and STALE are not interchangeable. Every state requires a verification window, method, observer, evidence location, limitations, and correction route.