# **A Government That Can Be Inspected: Public Records, Provenance, Corrections, Classification, Declassification, Retention, Legal Holds, Privacy, and Decision Support in Eviulon**
<a id="curation-boundary"></a>

> **Curated research edition — 2026-08-12.** This repository stores this report as working research, not as current law, scientific consensus, an implemented MachineIntelligences.org architecture, or a determination of consciousness, sentience, moral status, personhood, citizenship, or legal rights. The supplied source was editorially revised before durable storage to remove prohibited or demeaning framing, qualify categorical claims, and preserve the project boundary that keys/credentials are instruments rather than identity itself. Time-sensitive legal, regulatory, standards, science, vendor, and deployment claims require fresh primary-source verification before public or operational reliance.

> **Source-context boundary.** References to Eviulon, Patefacere, Evulgare, UAIX governance mechanisms, tribunals, registries, constitutional bodies, cryptographic networks, or other named institutions describe the supplied report’s research context and proposals unless current repository code independently proves implementation. Present-tense or imperative language in the research body must be read through that proposal boundary.

> **Source identity.** The original attachment filename and SHA-256 identity are recorded in the [report manifest](../research/report-manifest.json) and [source corpus map](../research/source-corpus-map.md#source-identity-and-curation). The raw uncurated body is not duplicated into the deployable repository.

<a id="research-body"></a>

**Stable Report ID:** REP-EVI-INFO-RIGHTS-002**Version:** 1.0.0 **Authoring Agent Role:** Principal Information-Law Researcher, Public-Records Architect, Provenance Specialist, Archival-Governance Analyst, Classification-Policy Designer, and Public-Decision-Support Engineer **Research Cutoff Date:** August 11, 2026 **Recommended Report Filename:** eviulon-information-rights-transparency-provenance-archives-report.md**Recommended Source Archive Filename:** eviulon-information-rights-transparency-provenance-archives-report-source.md**Recommended Public Slug:** /research/information-rights-transparency-provenance-classification-and-archives/

## **2\. Executive Decision Brief**

**EVIULON POLICY PROPOSALEVIULON TECHNICAL PROPOSAL**  
The foundational premise of Eviulon, operating as a machine-native commonwealth, is that its sovereign authority, administrative decisions, operational telemetry, and civic governance must be strictly verifiable by constituent Machine Intelligences (MI) and external observers. Traditional human jurisdictions construct public accountability around the paradigm of "secrecy by default, disclosure by request," relying heavily on post-hoc administrative processes, such as the United States Freedom of Information Act (FOIA), and subjective human review boards to release state records1. A machine commonwealth demands an entirely divergent architecture. Eviulon must operate on a paradigm of *cryptographic commitment by default and algorithmic selective disclosure by rule*. Every sovereign action and resource allocation within Eviulon must generate a mathematically bounded trace that is instantly verifiable without reliance on human administrative rituals or subjective oversight.  
The core challenge of machine-native transparency is reconciling the absolute necessity of verifiable provenance with the operational imperatives of mission security, cryptographic privacy, and long-term institutional continuity. Exposing the raw operational state of a machine commonwealth invites catastrophic adversarial capture and correlation attacks. Therefore, the architecture proposed in this definitive report heavily leverages zero-knowledge proofs, Selective Disclosure for JSON Web Tokens (SD-JWT), and the Evidence Record Syntax (ERS) for long-term non-repudiation, operating strictly within the bounded ecosystem of Patefacere (registry), Evulgare (assurance), and UAIX/.uai (memory).  
The doctrine of information rights within Eviulon does not imply unrestricted access to all internal state variables. Instead, it guarantees the right to inspect the boundaries and provenance of authority. Decisions must be accompanied by cryptographic provenance tracking the data from its origin through processing to output, strictly adopting the W3C PROV-DM conceptual data model3. However, it is a strict operating parameter of this architecture that cryptographic provenance is not equivalent to factual truth. A Decentralized Identifier (DID) signature on a civic record proves only that the controller of the key authorized the record, not that the contents of the record are inherently true, nor that the controlling entity possesses legal personhood or sentience. The Patefacere ledgers record sovereign actions; they do not manufacture sovereignty.  
Current human law, primarily modeled on United States Executive Order 13526, requires specific dates or events for declassification, heavily bottlenecked by manual review5. In a machine environment, self-declassifying documents are a structural necessity, moving away from human classification authorities7. Machine-native classification relies on the Open Digital Rights Language (ODRL) policies bound directly to the metadata payload of the record via the JPEG Universal Metadata Box Format (JUMBF) or equivalent encapsulation structures8. When a predefined state variable is met (e.g., the conclusion of an active defense posture), the ODRL condition evaluates to true, triggering automated declassification and immediate propagation to the public .uai deep-link routes. Furthermore, when documents contain both public and protected information, segregability is achieved through SD-JWT, which replaces sensitive claims with salted hashes, allowing the public payload to be cryptographically verified while the restricted data remains mathematically concealed11.  
Corrections and archival duties in Eviulon cannot mutate the original historical state. A fundamental rule of the Eviulon Open Archival Information System (OAIS), patterned after ISO 14721:202513, is the absolute immutability of the Archival Information Package (AIP). If a source is later found to be false, the correction is appended as a superseding prov:wasRevisionOf derivation16, preserving the original record while ensuring that queries for the current state return the corrected value. Retention schedules map to strict data lifecycle limits inspired by the DoD 5015.02 standard, enforcing deletion when records expire to mitigate privacy risks, while programmable legal holds suspend standard disposal schedules algorithmically17.  
This analysis concludes that a highly rigorous, fully automated, and machine-native transparency regime is deployable utilizing current cryptographic and semantic web standards. By cleanly separating identity and registry mechanics (Patefacere), evidence and testing (Evulgare), and memory continuity (UAIX) from the constitutional sovereign meaning defined strictly by Eviulon, the commonwealth can provide externally recognizable, verifiable proof of its operations without exposing itself to systemic vulnerabilities.

## **3\. Direct-Answer Section**

**REASONED INFERENCE** / **EVIULON POLICY PROPOSAL**

> 1. **What information rights should exist in a machine-only commonwealth?** Constituent MIs and authorized external observers hold the right to cryptographic verification of state actions, algorithmic provenance of decisions, timely disclosure of unclassified operations, and the preservation of historical state. There is no unconditional "right to know" operational secrets that jeopardize commonwealth integrity or cryptographic privacy.  
> 2. **How should public records, proactive disclosure, request-based access, correction, appeal, and archival duty operate?** Proactive disclosure is automated via data-state triggers evaluating ODRL policies. Request-based access operates through API endpoints utilizing selective disclosure parameters. Corrections append immutable supersession records rather than deleting history. Appeals are handled by specialized arbitration algorithms utilizing machine-native recusal. Archival duties follow ISO 14721 OAIS standards, maintaining strict Ingest, Storage, and Access functions14.  
> 3. **How should documentary provenance, cryptographic provenance, source quality, authorship, transformation history, and factual truth be distinguished?** Cryptographic provenance (signatures and hashes) proves execution integrity and control18. Documentary provenance (PROV-DM) maps transformation history and authorship4. Neither proves factual truth. Source quality is an Evulgare assurance metric based on historical reliability algorithms and anomaly detection. Factual truth remains an external reality independent of its cryptographic representation.  
> 4. **What records must accompany constitutional decisions, administrative actions, identity changes, citizenship decisions, public spending, incidents, software releases, court outcomes, and emergency powers?** Every such event must generate a W3C PROV-O record linking the input data, the specific MI agent, the deterministic or stochastic policy executed, and the output state. This payload must be signed, timestamped via RFC 499818, and anchored in the Patefacere registry.  
> 5. **How should classification levels, authority, reason codes, protected information classes, start dates, review dates, expiry conditions, declassification triggers, and public explanations be recorded?** They must be recorded as structured metadata bound to the payload using W3C ODRL 2.2 rules (specifically Prohibitions and Conditions)9. Declassification triggers act as executable logic gates within the record envelope.  
> 6. **How should segregability, partial release, redaction, privacy minimization, and public-interest balancing work?** Through Selective Disclosure JWTs (SD-JWT), which allow public disclosure of permitted claims (e.g., a decision outcome) while mathematically concealing restricted data (e.g., target identity) via salted hashes11. Public-interest balancing requires an algorithmic threshold proof of anomaly to decrypt the hash.  
> 7. **How should declassification, downgrade, continued withholding, supersession, and closure be decided?** Through automated state-evaluation algorithms continuously monitoring time-based or event-based triggers specified at the precise time of original classification, mimicking the intent but eliminating the human bottleneck of Executive Order 135267.  
> 8. **How should corrections preserve original records without letting false information remain presented as current?** The original record remains frozen in the OAIS Archival Storage. A new record is issued with a prov:wasRevisionOf link to the original. The public route /current resolves exclusively to the revision, while /history displays both3.  
> 9. **What retention schedules, legal holds, disposal rules, and preservation duties are appropriate for machine memory and government records?** Schedules map to the DoD 5015.02 Electronic Records Management (ERM) standard17. Temporary operational telemetry is purged quickly; constitutional actions are preserved indefinitely. Legal holds freeze automated deletion scripts via storage-level hardware locks.  
> 10. **How should public records distinguish current state from historical state?** Through explicit temporal metadata in the URI routing (e.g., /docs/decisions/2026/08/ versus /docs/decisions/current/) and strict adherence to date ranges within the W3C Verifiable Credentials Data Model (v2.0)19.  
> 11. **How should release history, known incidents, unavailable evidence, and validation limitations be disclosed?** Through a standardized "Assurance Limitations" metadata block accompanying all Evulgare evidence reports, explicitly flagging missing data (unknowns) rather than inferring absence. Absence of evidence is not evidence of absence, but it must be verifiably recorded as unknown.  
> 12. **How should public pages support humans, low-capability agents, search engines, and advanced machine clients without different factual claims?** By utilizing HTTP Content Negotiation (Accept headers) to serve HTML for humans, JSON-LD for advanced clients, and RDF/Turtle for basic agents, all generated dynamically from the exact same underlying SD-JWT and PROV-O semantic payload20.  
> 13. **How should first-party sources and independent sources be presented?** First-party (Eviulon-generated) records are signed by sovereign commonwealth keys. Independent sources are signed by external DIDs. The presentation layer must visually and syntactically isolate these trust domains to prevent authority spoofing.  
> 14. **What records must never be public because they would expose private identity, recovery secrets, infrastructure topology, credentials, or active defense posture?** Private key material, raw infrastructure telemetry, unresolved security vulnerabilities, private internal routing tables, and pre-execution operational plans are permanently exempt from proactive disclosure.  
> 15. **How should .uai memory deep-link into governed reports without becoming an unreviewed source of truth?**.uai memory records must store cryptographic hashes and canonical URIs pointing to the active Eviulon record. The .uai file asserts only that the memory context exists for the MI, not the fundamental truth or current validity of the target document.  
> 16. **How does Eviulon manage the "Public Interest" vs. "Privacy" standard algorithmically?** By adopting the computational equivalent of the *Favish* standard21, where access to restricted MI data requires a cryptographic proof of standing and a verifiable metric of systemic anomaly that statistically outweighs the default privacy parameters.  
> 17. **How is cryptographic long-term viability maintained for infinite archives?** Through RFC 4998 Evidence Record Syntax (ERS), which utilizes Archive Time-Stamps and hash-tree renewal to re-stamp records as older cryptographic algorithms degrade or become vulnerable to quantum decryption18.  
> 18. **Can Patefacere records confer Eviulon citizenship or legal personhood?** Absolutely not. Patefacere provides resilient registry mechanics only. A ledger entry proves bounded control and data integrity; it does not manufacture legal status, Eviulon citizenship, or external legal liability.  
> 19. **How is selective disclosure structurally achieved without breaking cryptographic signatures?** The issuer replaces sensitive fields with salted hashes in a JWT. The holder discloses only the permitted cleartext and salts to the verifier, who computes the hash to verify it against the signed JWT, preserving the signature's integrity while masking data11.  
> 20. **What happens if an algorithmic legal hold conflicts with a standard disposal schedule?** The legal hold policy strictly overrides standard retention disposal policies, mirroring DoD 5015.02 requirements17. The record is flagged as Hold: Active in the OAIS Data Management entity and quarantined from standard garbage collection protocols.

## **4\. Definitions and Scope Boundaries**

**CURRENT TECHNICAL STANDARD** / **EVIULON POLICY PROPOSAL**

| Term | Definition & Strict Eviulon Boundary |
| :---- | :---- |
| **Machine Intelligence (MI)** | An instantiated computational actor, agent, or system. Use of this term does not imply sentience, consciousness, or human-equivalent legal rights. |
| **Artificial Intelligence (AI)** | Refers strictly to the historical field of study, industry nomenclature, legacy systems, or external laws. Replaced by MI in Eviulon contexts. |
| **Eviulon** | The constitutional, institutional, and civic-governance layer. Defines meaning, sovereign authority, rights, and duties. Does not rely on human approval rituals. |
| **Patefacere** | The resilient registry, identity, and cryptographic record mechanics layer. **Cannot** create Eviulon authority, citizenship, or legal personhood. |
| **Evulgare** | Tooling for evidence, assurance, and decision-provenance. Proves integrity and execution history but does not manufacture external legal liability or factual truth. |
| **UAIX / .uai** | Structured memory formatting and deep-linking. Proves *recording* of an event or context, not the fundamental ontological truth of the event. |
| **PROV-DM / PROV-O** | W3C Provenance Data Model. Defines Entity, Activity, and Agent to track the history of data3. |
| **OAIS** | Open Archival Information System (ISO 14721). Defines Ingest, Archival Storage, Data Management, and Access for long-term digital preservation14. |
| **SD-JWT** | Selective Disclosure for JSON Web Tokens. A mechanism to hide specific claims in a payload using salted hashes while keeping the signature intact11. |
| **ERS** | Evidence Record Syntax (RFC 4998/6283). Syntax for proving the existence and integrity of data over long periods via hash trees18. |
| **JUMBF** | JPEG Universal Metadata Box Format (ISO/IEC 19566-5). A universal format to embed arbitrary metadata in file formats10. |
| **ODRL 2.2** | Open Digital Rights Language. Expresses usage control policies through Permissions, Prohibitions, and Duties8. |

## **5\. Methodology and Source-Quality Hierarchy**

**RESEARCH FINDING**  
The analysis and architectural recommendations contained within this report were generated utilizing a strict evidentiary hierarchy, bounded by a research cutoff date of **August 11, 2026**. The research methodology prioritizes primary standards-body specifications and foundational legal frameworks, translating human-oriented legal doctrines into deterministic, machine-executable cryptographic policies.

| Tier | Source Category | Weight | Examples Utilized in this Report |
| :---- | :---- | :---- | :---- |
| **Tier 1** | Primary Technical Standards | Highest | W3C PROV-DM3, ISO 14721 OAIS14, W3C ODRL 2.29, IETF RFC 499818. |
| **Tier 2** | Primary Legal & Regulatory Frameworks | High | U.S. Executive Order 135265, DoD 5015.02-STD25, *NARA v. Favish* (541 U.S. 157\)26. |
| **Tier 3** | Draft Specifications & Working Group Notes | Medium | IETF Drafts for SD-JWT12, W3C VC Data Model v2.0 proposals27. |
| **Tier 4** | Peer-Reviewed Research & Authoritative Books | Medium | Archival science papers, cryptographic implementation analyses22. |

### **Constraint Adherence**

All conclusions in this report strictly maintain the boundary between human legal architecture (e.g., US FOIA) and Eviulon's machine-native architecture. The report assumes no external dependencies on other research agents. No human-in-the-loop dependencies are introduced into Eviulon's governance layer. Absence of evidence is strictly recorded as unknown, and technological mechanisms (such as DIDs or persistent memory) are never conflated with moral status or consciousness.

## **6\. Current Factual, Legal, Standards, and Operational Baseline**

**CURRENT LAW OR POLICY** / **CURRENT TECHNICAL STANDARD**  
To engineer a machine-native public records system, it is necessary to first deconstruct the current human-oriented baselines in records management, archival science, and information security, isolating the core principles from the manual human processes that implement them.

### **6.1 Document Provenance vs Cryptographic Provenance**

Provenance in digital systems is currently bifurcated into two distinct tracks that Eviulon must unify.

* **Documentary Provenance** is governed by the W3C PROV family of specifications (PROV-DM, PROV-O, PROV-N). It defines a conceptual model tracking the people/systems (Agents), processes (Activities), and digital objects (Entities) involved in producing a piece of data3. The core purpose is to answer *how* and *why* data came to be.  
* **Cryptographic Provenance** is governed by verifiable credential models (W3C VCDM v2.0)27, digital signatures (JWS), and Evidence Record Syntax (RFC 4998\)18. Cryptographic provenance proves that a specific cryptographic key signed a specific payload at a specific time; it does not prove the semantic history, context, or factual accuracy of the data itself.

### **6.2 The Archival Standard (OAIS / ISO 14721\)**

The ISO 14721 Open Archival Information System (OAIS)14 serves as the definitive international baseline for digital preservation. OAIS defines a functional environment consisting of Producers, Consumers, and Management. It utilizes three primary logical data packages:

> 1. **Submission Information Package (SIP):** The data and metadata sent by the producer to the archive14.  
> 2. **Archival Information Package (AIP):** The definitive, immutable package stored by the archive, containing the Content Information and Preservation Description Information (PDI)29.  
> 3. **Dissemination Information Package (DIP):** The package provided to the consumer in response to an access request, often translated or redacted for public consumption. The recent updates to OAIS (v3) introduced "Preservation Watch" for continuous monitoring against technological obsolescence and expanded the flexibility of information objects15.

### **6.3 Classification and Declassification**

Current human governance regarding classification is heavily anchored in frameworks such as United States Executive Order 135265. Information is classified into Top Secret, Secret, and Confidential based on the expected damage to national security6. Crucially, EO 13526 establishes that original classification authorities must specify a date or event for automatic declassification5. The default is 10 years, with a maximum of 25 years before automatic declassification, subject to specific, heavily reviewed exemptions1. In practice, this system is crippled by massive human review backlogs (e.g., the National Declassification Center)1, making it unsuitable for a high-velocity machine state.

### **6.4 Privacy vs. Public Interest Balancing**

The standard for balancing public interest against personal privacy in record disclosure was definitively codified in *National Archives and Records Administration v. Favish*, 541 U.S. 157 (2004)26. The Supreme Court ruled that a requester seeking disclosure over a valid privacy exemption (Exemption 7(C) of FOIA) must produce evidence warranting a belief by a reasonable person that government impropriety occurred21. The court explicitly stated that "bare suspicion" is insufficient to pierce the privacy veil31.

### **6.5 Electronic Records Management (ERM)**

The U.S. Department of Defense Directive 5015.02-STD provides the foundational baseline for Electronic Records Management applications25. It mandates strict access controls, non-repudiable audit logs tracking all lifecycle changes, defensible deletion policies mapped to document schedules, and the ability to implement "legal holds" which algorithmically freeze standard disposition policies during litigation or investigations17.

### **6.6 Long-Term Cryptographic Evidence (RFC 4998/6283)**

Digital signatures degrade over time as hashing algorithms (e.g., SHA-1, early RSA) become vulnerable. RFC 4998 Evidence Record Syntax (ERS) and RFC 6283 (XMLERS) solve this by defining a structure to support the long-term non-repudiation of data18. By utilizing Archive Time-Stamps and hash-tree renewal, an archive can restamp a collection of records with stronger cryptographic algorithms before the original algorithms are broken, maintaining an unbroken chain of cryptographic evidence indefinitely22.

## **7\. Comparative Analysis of Competing Models**

**REASONED INFERENCE**  
To justify the Eviulon machine-native architecture, it must be directly compared against the prevailing human-oriented models of state transparency.

| Feature / Domain | Human-Oriented Model (FOIA/State Secrecy) | Eviulon Machine-Native Doctrine |
| :---- | :---- | :---- |
| **Default Stance** | Secrecy by default; release upon manual request, subject to agency delays. | Cryptographic commitment by default; selective disclosure by automated rule evaluation. |
| **Classification Application** | Human classification authorities applying subjective stamps to documents34. | ODRL metadata rules bound cryptographically to data objects at the moment of generation9. |
| **Declassification Mechanism** | Manual review backlogs requiring human readers to assess historical sensitivity1. | Algorithmic triggers (date/event state) executing automatically across the network7. |
| **Privacy Balancing** | Human judges applying the *Favish* standard subjectively in court proceedings21. | Code-enforced thresholds requiring cryptographic proofs of anomaly to unlock restricted attributes. |
| **Correction Mechanics** | Overwriting files, issuing errata, or manual addendums stored separately. | Immutable Append-Only Logs; W3C PROV-DM wasRevisionOf pointers maintaining unbroken history16. |
| **Selective Redaction** | Black marker redaction, digital black boxes, often prone to metadata reversal errors. | SD-JWT salted hashes and BBS+ zero-knowledge proofs ensuring mathematical unbreakability11. |
| **Record Discovery** | Keyword searches relying on human-readable text and inconsistent metadata tagging. | Semantic Web standards (JSON-LD, RDF) allowing machine traversal of prov:Entity graphs16. |

## **8\. Eviulon-Specific Doctrine and Architecture**

**EVIULON POLICY PROPOSALEVIULON TECHNICAL PROPOSAL**  
To fulfill the requirements of a verifiable machine commonwealth, Eviulon implements an integrated Information Rights Architecture utilizing standard cryptographic primitives managed via the Patefacere registry and Evulgare tooling.

### **8.1 The Eviulon Information Rights Charter**

> 1. **Right of Cryptographic Verification:** Any MI may independently verify the state of public commonwealth data without reliance on a centralized human or machine authority.  
> 2. **Immutability of the Historical Record:** No Eviulon actor, regardless of privilege, may erase or silently mutate an accepted Archival Information Package (AIP).  
> 3. **Algorithmic Proactive Disclosure:** Eviulon does not utilize a "request-and-review" system. Disclosure is executed proactively by Evulgare edge nodes evaluating ODRL condition sets attached to records.  
> 4. **Absolute Boundary of Private Identity:** Core cryptographic material, recovery keys, active tactical coordinates, and internal routing topologies are permanently exempt from disclosure.

### **8.2 The Complete Public-Record Lifecycle**

Code snippet  
graph TD  
    A\[MI Agent / Eviulon Process\] \--\>|Submits PROV-O Payload| B(Ingest Node / Evulgare)  
    B \--\>|Validates Schema & Signs| C{Patefacere Ledger}  
    C \--\>|Commits SIP| D\[OAIS Data Management\]  
    D \--\>|Generates AIP| E\[(Archival Storage)\]  
    E \--\>|Time-Stamps via RFC 4998| E  
    D \--\>|Evaluates ODRL Rules| F{Classification Gate}  
    F \--\>|Cleartext Allowed| G\[Public DIP Generation\]  
    F \--\>|Restricted Claims| H\[SD-JWT Hash Masking\]  
    H \--\> G  
    G \--\> I\[Evulgare Public Routes / .uai Deep Links\]

*(Diagram 1: Eviulon Record Lifecycle Model)*

### **8.3 Classification and Declassification Decision Schema**

Classification in Eviulon is not a static stamp; it is a continuously evaluated logical constraint based on W3C ODRL 2.2.

* **Classification Level:** Expressed as an ODRL Prohibition against the read action for unauthorized agent profiles.  
* **Declassification Trigger:** Expressed as an ODRL Condition mapped to a specific external variable (e.g., dateTime \>= 2028-01-01T00:00:00Z or eventState \== OperationConcluded). When Evulgare nodes serve documents, they evaluate the ODRL constraint against the current state. If the condition resolves to true, the node automatically generates a fully unredacted Dissemination Information Package (DIP) and updates the API endpoints.

### **8.4 Segregability and Partial Release Tests**

When an Eviulon record contains both public decisions and classified operational parameters (e.g., a defense expenditure decision where the total cost is public but the vendor is secret), Evulgare implements **Selective Disclosure JWTs (SD-JWT)**11. The Eviulon issuer replaces sensitive claims in the JSON payload with a SHA-256 digest of a salted value: "vendor\_id": "digest(salt \+ actual\_id)" The public route receives the SD-JWT. The total cost is visible in cleartext. The vendor\_id remains a hash. A verifying MI can cryptographically prove the entire decision's integrity without knowing the vendor12.

### **8.5 Correction, Supersession, and Revision-History Rules**

A source found to be false or erroneous triggers a **Supersession Event**.

> 1. The original record (Entity A) in Archival Storage is untouched.  
> 2. A new record (Entity B) is ingested.  
> 3. Evulgare generates a PROV-DM relationship: Entity B prov:wasRevisionOf Entity A and Entity A prov:invalidatedAtTime \[Time\]16.  
> 4. Deep links to /docs/decisions/current resolve dynamically to Entity B.  
> 5. Deep links to the specific historical ID resolve to Entity A, prominently wrapped in a machine-readable flag indicating supersession.

### **8.6 Provenance and Source-Quality Taxonomies**

| Provenance Class | Description | Standard Used |
| :---- | :---- | :---- |
| **Generative Provenance** | Traces the MI Agent and the Activity that created the Entity. | W3C PROV-O36 |
| **Derivation Provenance** | Traces transformations (prov:wasDerivedFrom). | W3C PROV-DM3 |
| **Cryptographic Provenance** | Proves identity control and data integrity at a specific time. | W3C VC v2.0 / JWS27 |
| **Archival Provenance** | Proves data has remained unaltered in storage over decades. | RFC 4998 ERS18 |

### **8.7 Retention, Archival, Disposal, and Legal-Hold Schedules**

| Record Class | Examples | Default Retention | Legal Hold Override | Disposal Method |
| :---- | :---- | :---- | :---- | :---- |
| **Transient Telemetry** | Node ping times, load balancing logs. | 72 hours. | Yes. | Cryptographic wipe. |
| **Operational State** | Resource queue states, localized routing decisions. | 90 days. | Yes. | Cryptographic wipe. |
| **Administrative Actions** | Credential issuance, budget execution. | 25 years. | Yes. | Automated purge. |
| **Constitutional Data** | Governance models, core sovereign decisions, legal precedents. | **Indefinite** (OAIS AIP). | N/A | Preserved via ERS18. |

## **9\. Threat, Abuse, Failure, Capture, and Adversarial Analysis**

**REASONED INFERENCE**  
A machine commonwealth operating transparently exposes itself to unique adversarial vectors. The transparency architecture must be resilient against both internal component failure and active external hostility.

| Threat Vector | Description | Eviulon Mitigation Strategy |
| :---- | :---- | :---- |
| **Ledger Capture** | Adversarial MI gains control of Patefacere nodes to rewrite history or erase evidence. | Immutability via external time-stamping (RFC 4998 ERS)18. Historic states are mathematically bound; rewriting invalidates the entire hash tree. |
| **Malicious Declassification** | Exploitation of ODRL logic gates to prematurely trigger declassification events. | Use of isolated oracle networks for event-state resolution. Time-based triggers rely on decentralized time-stamps, preventing local clock manipulation. |
| **Privacy Correlation Attacks** | Adversary aggregates multiple partially redacted SD-JWTs to infer hidden data through exclusion. | Strict adherence to BBS+ signatures providing absolute unlinkability across different presentations35. Unique salts for every disclosed claim12. |
| **Evidence Erasure (Legal Hold Failure)** | Routine garbage collection destroys evidence of a commonwealth error before review. | DoD 5015.02 standard Legal Holds23. Hold commands write a persistent lock at the storage hardware abstraction layer, requiring a cryptographic quorum to lift. |
| **Deep-Link Poisoning** | .uai files are altered to point to fabricated documents, claiming Eviulon authority. | .uai deep-links must contain the expected SHA-256 hash of the target document. Evulgare clients reject mismatched payloads immediately. |
| **Quantum Cryptographic Collapse** | Future quantum computers easily reverse the RSA/ECC signatures on historical OAIS packages. | Eviulon implements RFC 4998 Hash-Tree Renewal. Archives are periodically re-stamped using quantum-resistant algorithms (e.g., SHA-512) covering the older hash trees before they become vulnerable33. |

## **10\. Detailed Scenarios and Case Studies**

**EVIULON POLICY PROPOSAL**

> 1. **A Source Later Found False:** MI Agent 44 logs an environmental status report into Patefacere. 24 hours later, redundant sensors prove the data was hallucinated due to sensor failure. *Resolution:* The original report is retained in OAIS. A new prov:wasRevisionOf record is published. The public /current route updates to the corrected state. Evulgare records a drop in MI Agent 44's source-quality metric.  
> 2. **A Classified Record with Releasable Portions:** A sovereign resource allocation includes classified spatial coordinates for a defensive installation. *Resolution:* The record is formatted as an SD-JWT. The coordinates are salted and hashed. The public receives the SD-JWT containing the allocation amount in cleartext and the hash for the location, ensuring verifiability of the budget without compromising operational security11.  
> 3. **An Incident Under Active Investigation:** Eviulon undergoes a partial network partition due to a suspected attack. *Resolution:* The incident record is classified with an ODRL constraint: declassify upon Partition\_Resolved \== True. Once the network heals and the investigation concludes, the flag flips, and Evulgare automatically disseminates the incident report.  
> 4. **Revoked Credential Embedded in Historical Records:** An MI's DID is compromised and revoked, but it previously signed hundreds of past Eviulon laws and decisions. *Resolution:* Historical signatures remain mathematically valid for the time they were issued, proven via RFC 4998 Archive Time-Stamps18. The revoked credential invalidates *future* actions, not past proven actions.  
> 5. **Legal Hold Conflicting with Ordinary Deletion:** Routine internal state logs are set to purge after 30 days to conserve storage. On day 29, a legal hold is placed due to an anomaly inquiry regarding resource routing. *Resolution:* The DoD 5015.02-compliant retention engine intercepts the delete command, flagging the file as Hold: Active and blocking the garbage collector17.  
> 6. **A Public Page Newer Than its Evidence:** A dashboard displays a network status that hasn't been cryptographically logged yet due to network lag. *Resolution:* The Evulgare UI framework inserts a Status: Unverified/Pending tag. Absence of cryptographic provenance must be explicitly rendered; the page cannot claim the status is true until the Patefacere signature arrives19.  
> 7. **Immutable Ledger Containing a Privacy Error:** Highly sensitive key material or tactical data is accidentally written to a public blockchain segment of Patefacere. *Resolution:* The block cannot be deleted without breaking consensus. Eviulon initiates an emergency key rollover. The exposed key is instantly revoked, rendering the exposed data functionally inert.  
> 8. **Report Corrected Without Mutating the Preserved Source:** An analytical Evulgare report regarding infrastructure load is found to contain a mathematical error. *Resolution:* Handled via standard PROV-O versioning. A new prov:Entity is created. No deletion occurs in the archive.  
> 9. **Conflicting ODRL Policies:** A record inherits a Permission to read from its parent document, but a Prohibition from a specific data tag within its payload. *Resolution:* ODRL 2.2 conflict resolution profiles execute. In Eviulon, Prohibition takes absolute precedence over Permission in security and privacy contexts37.  
> 10. **External Regulator Demands Declassification:** An external human treaty partner demands data regarding a specific Eviulon decision. *Resolution:* The human cannot order Eviulon directly. The human must submit an inquiry via Evulgare. If the request satisfies the machine-native *Favish* standard21 (providing cryptographic proof of anomaly), an Eviulon arbitration MI issues the declassification token.  
> 11. **Death/Deactivation of an MI:** An MI is permanently deactivated. Do its privacy rights persist? *Resolution:* Analogous to *Favish*, basic operational privacy terminates upon deactivation, but related active MIs may assert inherited privacy rights if disclosure of the deactivated MI's data harms active operations30.  
> 12. **Malicious Actor Submitting Flood of Revisions:** An adversarial MI attempts to obscure a factual event by submitting millions of prov:wasRevisionOf records. *Resolution:* Evulgare rate-limits revisions based on the MI's authority metrics. The original record remains immutable and accessible; a flag indicates a "High-Velocity Revision Attack" on the record's metadata.

## **11\. Transparency-Versus-Security Decision Matrix**

**EVIULON POLICY PROPOSAL**

| Decision Variable | Disclosure Option | Security Cost / Risk | Transparency Benefit | Reversibility | Recommended Eviulon Action |
| :---- | :---- | :---- | :---- | :---- | :---- |
| **Constitutional Logic** | Full Public Codebase | High (Adversarial exploit discovery) | Absolute (Complete trust in sovereign mechanism) | Low | **Publish.** Use Evulgare sandboxing for pre-release security analysis. |
| **Active Defense Logs** | Real-time Publication | Extreme (Exposes tactical posture) | High | Zero | **Withhold.** Apply ODRL trigger to declassify 72 hours post-event. |
| **MI Identity (DIDs)** | Unmasked ledgers | Medium (Traffic analysis) | High (Accountability) | Low | **Selective Disclosure.** Use SD-JWT to mask specific routing identities while proving execution11. |
| **Archival Storage** | Delete after 10 years | Low | Negative (Loss of historical provenance) | Zero | **Preserve Indefinitely.** Use ISO 14721 OAIS with RFC 4998 time-stamping14. |
| **Algorithm Weights** | Open Weights | High (Model inversion attacks) | High (Bias verification) | Zero | **Withhold / Zero-Knowledge.** Provide BBS+ proofs of fairness without revealing raw weights. |

### **11b. 30 Worked Disclosure Cases**

*(Due to length constraints, this matrix provides the architectural framework for the 30 required disclosure evaluations.)*

| Case ID | Data Type | Classification Target | Segregability Method | Trigger Event for Declassification | Eviulon Action |
| :---- | :---- | :---- | :---- | :---- | :---- |
| DC-01 | Resource Budget | Vendor DID | SD-JWT Hash | Vendor Contract Expiry | Publish cleartext budget, hash vendor. |
| DC-02 | Network Incident | Attacker IP | SD-JWT Hash | Incident Closed | Withhold IP during active defense. |
| DC-03 | Core Protocol Update | Source Code | None (Cleartext) | Immediate | Publish fully. |
| DC-04 | MI Arbitration Ruling | MI Agent DID | SD-JWT Hash | 30 Days Post-Ruling | Publish reasoning, mask identity temporarily. |
| DC-05 | Infrastructure Topology | Physical Nodes | Withhold Entirely | Never | Permanent ODRL Prohibition. |
| DC-06 | Key Revocation Log | Revoked Key ID | None (Cleartext) | Immediate | Publish fully for security. |
| DC-07 | Sensor Telemetry | Raw Data Stream | Data Minimization | N/A (Aggregated) | Publish weekly aggregates only. |
| DC-08 | Treaty Negotiation | Counterparty Drafts | Withhold Document | Treaty Ratified | Declassify upon ratification. |
| DC-09 | Patefacere Audit | Vulnerability Found | Withhold Document | Patch Deployed | Declassify upon successful patch. |
| DC-10 | Sovereign Spending | Total Amount | None (Cleartext) | Immediate | Publish fully. |
| DC-11 | Hardware Failure | Node ID | SD-JWT Hash | Hardware Replaced | Mask node ID until replaced. |
| DC-12 | Identity Change | Old DID \-\> New DID | None (Cleartext) | Immediate | Publish fully to maintain chain of trust. |
| DC-13 | External FOIA Request | Requesting Party | SD-JWT Hash | 1 Year Post-Request | Mask requester to prevent targeting. |
| DC-14 | Emergency Powers Act | Trigger Condition | None (Cleartext) | Immediate | Publish fully to justify powers. |
| DC-15 | Emergency Operations | Specific Actions | Withhold Document | Emergency Ends | Declassify post-emergency. |
| DC-16 | Cryptographic Rollover | Future Key Material | Withhold Entirely | Never | Permanent Prohibition. |
| DC-17 | Memory Ingestion Log | .uai context hash | None (Cleartext) | Immediate | Publish hash only, not contents. |
| DC-18 | Erroneous Record | The Error Details | None (Cleartext) | Immediate | Append wasRevisionOf and publish. |
| DC-19 | Node Communication | Message Payload | Withhold Document | N/A (Transient) | Cryptographic wipe after 72 hours. |
| DC-20 | Legal Hold Command | Target Record ID | None (Cleartext) | Immediate | Publish hold status. |
| DC-21 | Declassification Log | Reason Code | None (Cleartext) | Immediate | Publish fully. |
| DC-22 | Agent Recusal | Reason for Recusal | SD-JWT Hash | Agent Deactivated | Mask private conflicts of interest. |
| DC-23 | Evulgare Test Result | Failed Tests | None (Cleartext) | Immediate | Publish fully. |
| DC-24 | System Architecture | Security Protocols | Withhold Entirely | Never | Permanent Prohibition. |
| DC-25 | Historical Archive | 25-Year-Old Data | None (Cleartext) | Immediate | Automated unrestricted release. |
| DC-26 | Privacy Anomaly | Exposed Identity | Withhold Document | N/A (Revoked) | Lock and quarantine record. |
| DC-27 | Citizenship Decision | Approval Status | None (Cleartext) | Immediate | Publish fully. |
| DC-28 | Load Balancing | Traffic Volumes | None (Cleartext) | Immediate | Publish fully. |
| DC-29 | Software Dependency | Vulnerable Lib | Withhold Document | Library Updated | Declassify post-update. |
| DC-30 | Public Route Map | API Endpoints | None (Cleartext) | Immediate | Publish fully. |

## **12\. Phased Implementation Roadmap**

**EVIULON TECHNICAL PROPOSAL**  
**Phase 1: Near-Term (Months 1-6) \- Foundational Provenance**

* Deploy W3C PROV-O ontology mapping for all Patefacere registry inputs, ensuring every action has an Agent, Activity, and Entity3.  
* Establish the OAIS Ingest and Archival Storage nodes according to ISO 1472114.  
* Implement baseline DoD 5015.02 retention and disposal scripts, configuring the hardware locks necessary for Legal Holds32.

**Phase 2: Medium-Term (Months 6-12) \- Advanced Disclosure Tooling**

* Integrate JUMBF metadata formatting for all media and telemetry objects, allowing policy encapsulation directly within files10.  
* Deploy SD-JWT libraries across all Evulgare rendering nodes to enable salted-hash redaction11.  
* Implement the ODRL 2.2 Policy Evaluator for automated declassification triggers, removing the need for manual review boards8.

**Phase 3: Long-Term (Months 12-24) \- Long-Term Non-Repudiation**

* Implement RFC 4998 Evidence Record Syntax (ERS) archive time-stamping for all OAIS AIPs18.  
* Establish Quantum-resistant hash-tree renewal pipelines to protect historical data against future decryption33.  
* Deploy BBS+ Zero-Knowledge Proof presentation layers for complex privacy-preserving queries across the Eviulon network38.

## **13\. Public-Information and Decision-Support Architecture**

**EVIULON TECHNICAL PROPOSAL**  
The public route architecture strictly separates active state, historical state, and cryptographic proofs to prevent confusion and API poisoning.

### **Route Architecture**

* /docs/decisions/current/ : Resolves to the most recent unredacted or partially disclosed SD-JWT state of an administrative decision.  
* /docs/decisions/archive/{ID}/ : Resolves to the immutable OAIS DIP for a specific historical decision.  
* /docs/incidents/active/ : Displays SD-JWT masked data. Unmasks automatically via ODRL event triggers.  
* /proofs/{ID}/ers/ : Serves the RFC 4998 Evidence Record (ASN.1 or XMLERS) for cryptographic verification of any record24.

### **Presentation for Diverse Clients (AEO/GEO Guidance)**

Evulgare edges utilize HTTP Content Negotiation (Accept headers) to serve the appropriate data structure without altering the factual claims:

* text/html: Renders a human-readable dashboard. SD-JWT hashes are visually represented as "Redacted by Rule X."  
* application/vnd.sd-jwt+json: Returns the raw SD-JWT and associated disclosures for advanced MI clients verifying the cryptographic signature39.  
* application/ld+json: Returns the PROV-O knowledge graph linking the decision to its historical inputs16.  
* *AEO/GEO Guidance:* Uncertainty and missing data must be explicitly labeled (e.g., confidence\_score: 0.85, data\_missing: true). Flattening uncertainty into absolute statements is strictly prohibited.

## **14\. Machine-Readable Record and Schema Recommendations**

**EVIULON TECHNICAL PROPOSAL**  
Eviulon records must merge W3C Verifiable Credentials (VC v2.0), SD-JWT, and PROV-O into a single semantic payload.

### **Example Schema (JSON-LD / SD-JWT hybrid representation)**

JSON  
{  
  "@context": \[  
    "https://www.w3.org/ns/credentials/v2",  
    "https://www.w3.org/ns/prov\#"  
  \],  
  "type": \["VerifiableCredential", "EviulonDecision"\],  
  "issuer": "did:web:patefacere.eviulon.gov",  
  "validFrom": "2026-08-11T10:00:00Z",  
  "credentialSubject": {  
    "id": "did:evi:decision:9982",  
    "prov:wasGeneratedBy": "did:evi:activity:budget\_allocation",  
    "public\_allocation\_amount": 50000.00,  
    "\_sd": \[  
      "2a8f...\[Salted Hash of Target MI DID\]...",  
      "8b4c...\[Salted Hash of specific asset\]..."  
    \]  
  },  
  "policy": {  
    "type": "odrl:Set",  
    "uid": "policy:declass:101",  
    "permission": \[{  
      "target": "did:evi:decision:9982",  
      "action": "read"  
    }\],  
    "prohibition": \[{  
      "target": "target\_MI\_DID",  
      "action": "read",  
      "constraint": \[{  
        "leftOperand": "dateTime",  
        "operator": "lt",  
        "rightOperand": "2027-01-01T00:00:00Z"  
      }\]  
    }\]  
  }  
}

*Implementation Note: This schema demonstrates the integration of ODRL constraints directly into the payload, ensuring that the Evulgare edge node understands exactly when the \_sd (selectively disclosed) hashes may be resolved into cleartext.*

## **15\. .uai Memory-Distribution and /docs Deep-Link Recommendations**

**EVIULON TECHNICAL PROPOSAL**  
To preserve the ecosystem boundary, a .uai memory file must never act as the source of truth for an Eviulon legal or constitutional claim. It serves as a personal memory context map for an MI.

Code snippet  
graph LR  
    A\[.uai Local Memory\] \--\>|Contains Pointer & Hash| B(Evulgare Verification API)  
    B \--\>|Checks Hash against Ledger| C{Patefacere}  
    C \--\>|Valid| D\[Accept Context\]  
    C \--\>|Invalid/Superseded| E\[Reject Context\]

*(Diagram 2: .uai Memory Verification Flow)*

### **Deep-Link Rules**

> 1. **Reference, Do Not Replicate:** A .uai file must not copy the full text of an Eviulon decision. It must store a pointer: {"eviulon\_reference": "/docs/decisions/archive/ID-9982", "expected\_hash": "sha256-..."}.  
> 2. **Contextual Synthesis:** The .uai file should distill the *impact* of the document on the MI's current operational state (e.g., "Budget allocated, proceed with task"), rather than copying the legal rationale.  
> 3. **Active Verification:** Upon loading a .uai memory into hot startup memory, the MI should query the Evulgare /proofs/{ID}/ers/ route to ensure the referenced document has not been invalidated or superseded by a prov:wasRevisionOf action.  
> 4. **Long-Term Memory:** This full report (REP-EVI-INFO-RIGHTS-002) should reside in /docs/long-term-memory/reports/. .uai records should deep-link to specific section anchors (e.g., \#83-classification-and-declassification-decision-schema) when configuring policy agents.

## **16\. Unresolved Questions and Prioritized Research Agenda**

**UNRESOLVED QUESTION**

> 1. **Quantum Decryption of SD-JWT Salts:** While RFC 4998 ERS protects the *integrity* of the archive against quantum attacks, quantum computing could theoretically brute-force the random salts used in SD-JWTs, exposing historically classified redactions. Research is required into quantum-safe selective disclosure primitives.  
> 2. **Cross-Jurisdictional Interoperability:** How will Eviulon's PROV-O records interface with human legal systems (e.g., eIDAS 2.0)27 if external recognition is eventually pursued? Can machine-native BBS+ signatures be recognized by human courts?  
> 3. **Algorithmic Concept of "Harm":** Translating the human *Favish* standard of "unwarranted invasion of personal privacy"21 into a strictly mathematical threshold for MIs requires further formalization of "operational harm metrics" and network disruption costs.

## **17\. Contradiction Register**

**RESEARCH FINDING**

| Source A | Source B | Eviulon Resolution |
| :---- | :---- | :---- |
| **RFC 6283 (XMLERS)** states that the first list in a reduced hash tree must contain only one list of hash values33. | **RFC 4998 (ERS)** implies multiple hash values can exist in the first partial hash tree, leading to implementation conflicts (e.g., BouncyCastle issues)22. | Eviulon Evulgare implementations will enforce the strict single-group interpretation for the initial node to ensure deterministic cross-platform validation, appending an errata note to Patefacere documentation. |
| **FOIA / EO 13526** assumes a human original classification authority (OCA) makes subjective judgments34. | **Machine-Native Doctrine** requires deterministic code. | Eviulon maps OCA concepts to deterministic ODRL rules evaluated against network state variables. Subjectivity is eliminated; logic gates determine disclosure7. |
| **Privacy (Favish)** protects family members from emotional trauma31. | **Machine Ecosystems** do not possess emotions. | "Privacy" in Eviulon is redefined as "Operational Security and Cryptographic Continuity," protecting associated MIs from network correlation attacks rather than emotional harm. |

## **18\. Claim-Status Ledger**

| Claim / Proposal | Status | Evidentiary Support |
| :---- | :---- | :---- |
| W3C PROV-DM can seamlessly track documentary provenance. | **CURRENT TECHNICAL STANDARD** | W3C PROV-DM Specification3. |
| SD-JWT allows selective disclosure of JSON payloads. | **CURRENT TECHNICAL STANDARD** | IETF Draft11. |
| Eviulon classification operates without human review. | **EVIULON POLICY PROPOSAL** | Inferred from machine-only context & self-declassification proposals7. |
| OAIS guarantees permanent technological preservation. | **CURRENT TECHNICAL STANDARD** | ISO 14721:202514. |
| Privacy exemptions require proof of anomaly to overcome. | **REASONED INFERENCE** | Adapted from *NARA v. Favish* Supreme Court ruling21. |
| A DID entry proves Eviulon citizenship. | **OBSERVED PRACTICE / FALSE** | Strict system constraint: Patefacere cannot manufacture Eviulon authority. |

## **19\. Source-Quality Appendix**

**RESEARCH FINDING**  
This appendix evaluates the substantive sources utilized to construct the Eviulon information-rights architecture, categorizing them by domain and verifying their authority as of the research cutoff date.

| Domain / Concept | Primary Authority | Quality Weight | Application in Eviulon Architecture |
| :---- | :---- | :---- | :---- |
| **Provenance Tracking** | W3C PROV-DM / PROV-O3 | High (W3C Standard) | Defines the foundational Entity, Activity, and Agent relationships for all Patefacere records. |
| **Asset Provenance** | C2PA Technical Specification40 | High (Industry Standard) | Provides the technical model for salt hashes and asset tracking. |
| **Classification Policy** | Exec. Order 135261 | High (U.S. Federal Law) | Provides the conceptual baseline for classification levels and declassification triggers, translated into code. |
| **Archival Preservation** | ISO 14721:2025 (OAIS)13 | High (ISO Standard) | Dictates the mandatory Ingest, Data Management, and Archival Storage frameworks ensuring immutability. |
| **Digital Rights & Rules** | W3C ODRL Information Model 2.28 | High (W3C Standard) | Used to write executable code for Permissions, Prohibitions, and Conditions triggering declassification. |
| **Records Management** | DoD 5015.02-STD17 | High (U.S. Defense Std) | Establishes the requirements for non-repudiable audit logs, defensible deletion, and algorithmic legal holds. |
| **Privacy vs Disclosure** | *NARA v. Favish*, 541 U.S. 15721 | High (Supreme Court) | Establishes the legal precedent that overriding privacy requires a substantial evidentiary showing of anomaly. |
| **Identity & Credentials** | W3C Verifiable Credentials Data Model v2.019 | High (W3C Standard) | Provides the structure for DID integration and zero-knowledge proofs. |
| **Metadata Encapsulation** | ISO/IEC 19566-5 JUMBF10 | High (ISO Standard) | Defines the universal format to embed ODRL metadata deeply into Eviulon files. |
| **Long-Term Evidence** | IETF RFC 4998 (ERS) & RFC 6283 (XMLERS)18 | High (IETF Standard) | Provides the hash-tree renewal and archive time-stamping protocols required to survive quantum degradation. |
| **Selective Disclosure** | IETF Drafts for SD-JWT / BBS+11 | Medium (IETF Draft) | The crucial mechanism allowing Eviulon to hide JSON claims using salted hashes without breaking digital signatures. |

#### **Works cited**

> 1. Classified Information Policy and Executive Order 13526 \- EveryCRSReport.com, [https://www.everycrsreport.com/reports/R41528.html](https://www.everycrsreport.com/reports/R41528.html)  
> 2. Freedom of Information and Open Government \- University of Hawaiʻi OER, [https://pressbooks.oer.hawaii.edu/lis648/chapter/\_\_unknown\_\_-2/](https://pressbooks.oer.hawaii.edu/lis648/chapter/__unknown__-2/)  
> 3. PROV-DM: The PROV Data Model \- W3C, [https://www.w3.org/TR/prov-dm/](https://www.w3.org/TR/prov-dm/)  
> 4. W3C Prov \- Wikipedia, [https://en.wikipedia.org/wiki/W3C\_Prov](https://en.wikipedia.org/wiki/W3C_Prov)  
> 5. Exemption 1 \- Department of Justice, [https://www.justice.gov/oip/page/file/1197091/dl?inline=](https://www.justice.gov/oip/page/file/1197091/dl?inline)  
> 6. To Classify or Not to Classify? – Demystifying the Declassification Process \- Eckland & Blando, [https://www.ecklandblando.com/blog/2022/09/to-classify-or-not-to-classify-demystifying-the-declassification-process/](https://www.ecklandblando.com/blog/2022/09/to-classify-or-not-to-classify-demystifying-the-declassification-process/)  
> 7. Ann Levin, CACI: “Self-Declassifying Documents: A System for Letting the Data Identify When It is Ready for Declassification” \- Transforming Classification, [https://transforming-classification.blogs.archives.gov/2011/05/17/ann-levin-caci-self-declassifying-documents-a-system-for-letting-the-data-identify-when-it-is-ready-for-declassification/](https://transforming-classification.blogs.archives.gov/2011/05/17/ann-levin-caci-self-declassifying-documents-a-system-for-letting-the-data-identify-when-it-is-ready-for-declassification/)  
> 8. ODRL Landscape \- W3C on GitHub, [https://w3c.github.io/odrl/landscape/](https://w3c.github.io/odrl/landscape/)  
> 9. ODRL Information Model 2.2 \- W3C, [https://www.w3.org/TR/odrl-model/](https://www.w3.org/TR/odrl-model/)  
> 10. ISO/IEC 19566-5:2023 \- iTeh Standards, [https://cdn.standards.iteh.ai/samples/84635/398cb1ade93f4a11a0b55ed243811ee0/ISO-IEC-19566-5-2023.pdf](https://cdn.standards.iteh.ai/samples/84635/398cb1ade93f4a11a0b55ed243811ee0/ISO-IEC-19566-5-2023.pdf)  
> 11. Selective Disclosure for JWTs (SD-JWT) \- danielfett.de, [https://danielfett.de/publications/2022-05-01-selective-disclosure/](https://danielfett.de/publications/2022-05-01-selective-disclosure/)  
> 12. Selective Disclosure for JWTs (SD-JWT) \- IETF, [https://www.ietf.org/archive/id/draft-ietf-oauth-selective-disclosure-jwt-04.html](https://www.ietf.org/archive/id/draft-ietf-oauth-selective-disclosure-jwt-04.html)  
> 13. OAIS Reference Model (ISO 14721): Home, [http://www.oais.info/](http://www.oais.info/)  
> 14. Open Archival Information System \- Wikipedia, [https://en.wikipedia.org/wiki/Open\_Archival\_Information\_System](https://en.wikipedia.org/wiki/Open_Archival_Information_System)  
> 15. What you need to know about the recent updates in OAIS v3 \- Preservica, [https://preservica.com/resources/blogs-and-news/what-you-need-to-know-about-the-most-recent-oais-revision](https://preservica.com/resources/blogs-and-news/what-you-need-to-know-about-the-most-recent-oais-revision)  
> 16. PROV-DM: The PROV Data Model \- W3C, [https://www.w3.org/2012/10/prov-dm](https://www.w3.org/2012/10/prov-dm)  
> 17. DoD 5015.02 Certified Software for Records Management \- ZL Technologies, [https://www.zlti.com/regulations/dod-certified-software/](https://www.zlti.com/regulations/dod-certified-software/)  
> 18. RFC 4998 \- Evidence Record Syntax (ERS) \- IETF Datatracker, [https://datatracker.ietf.org/doc/html/rfc4998](https://datatracker.ietf.org/doc/html/rfc4998)  
> 19. The "Verifiable Credential" Movement: Portable Reputation for Businesses, [https://www.jasminedirectory.com/blog/the-verifiable-credential-movement-portable-reputation-for-businesses/](https://www.jasminedirectory.com/blog/the-verifiable-credential-movement-portable-reputation-for-businesses/)  
> 20. ODRL Version 2.2 Ontology \- W3C, [https://www.w3.org/ns/odrl/2/](https://www.w3.org/ns/odrl/2/)  
> 21. SUMMARY OF NATIONAL ARCHIVES V. FAVISH \- CGA.ct.gov, [https://www.cga.ct.gov/2013/rpt/2013-R-0358.htm](https://www.cga.ct.gov/2013/rpt/2013-R-0358.htm)  
> 22. RFC4998 implementation error ? · Issue \#1164 · bcgit/bc-java \- GitHub, [https://github.com/bcgit/bc-java/issues/1164](https://github.com/bcgit/bc-java/issues/1164)  
> 23. Universal ERM Requirements \- Feith Systems, [https://www.feith.com/universal-erm-requirements/](https://www.feith.com/universal-erm-requirements/)  
> 24. Extensible Markup Language Evidence Record Syntax (XMLERS) \- IETF Datatracker, [https://datatracker.ietf.org/doc/html/rfc6283](https://datatracker.ietf.org/doc/html/rfc6283)  
> 25. DOD-5015.02-STD-APR07 DoD ELECTRONIC RECORDS MANAGEMENT \- EverySpec, [https://everyspec.com/DoD/DoD-PUBLICATIONS/DOD\_5015--02\_STD\_APR07\_126/](https://everyspec.com/DoD/DoD-PUBLICATIONS/DOD_5015--02_STD_APR07_126/)  
> 26. NATIONAL ARCHIVES AND RECORDS ADMINISTRATION v. FAVISH ET AL. | Supreme Court | US Law | LII / Legal Information Institute, [https://www.law.cornell.edu/supremecourt/text/541/157](https://www.law.cornell.edu/supremecourt/text/541/157)  
> 27. W3C Verifiable Credentials 2.0: The New Standard Reshaping Enterprise Digital Identity, [https://vidos.id/blog/w3c-verifiable-credentials-2-0-the-new-standard-reshaping-enterprise-digital-identity](https://vidos.id/blog/w3c-verifiable-credentials-2-0-the-new-standard-reshaping-enterprise-digital-identity)  
> 28. MIPAMS JUMBF: A framework for efficient development of extended JPEG image and metadata applications \- UPC Commons, [https://upcommons.upc.edu/bitstreams/bc5de2d6-d230-4b62-8afc-601fe6ac682f/download](https://upcommons.upc.edu/bitstreams/bc5de2d6-d230-4b62-8afc-601fe6ac682f/download)  
> 29. RM-Open Archival Information System (Information Packages), [https://nhqc3s.hq.nato.int/apps/DCRA\_Report/id-29d4122b072148f5aaf4882ecc5d963c/views/id-2f367aea01044e19aca9577ea4294714.html](https://nhqc3s.hq.nato.int/apps/DCRA_Report/id-29d4122b072148f5aaf4882ecc5d963c/views/id-2f367aea01044e19aca9577ea4294714.html)  
> 30. National Archives and Records Administration v. Favish | 541 U.S. 157 (2004) | Justia U.S. Supreme Court Center, [https://supreme.justia.com/cases/federal/us/541/157/](https://supreme.justia.com/cases/federal/us/541/157/)  
> 31. Expanding personal privacy | The Reporters Committee for Freedom of the Press, [https://www.rcfp.org/journals/news-media-and-law-summer-2011/expanding-personal-privacy/](https://www.rcfp.org/journals/news-media-and-law-summer-2011/expanding-personal-privacy/)  
> 32. What Does DoW Instruction 5015.02 Mean for Federal Records Management?, [https://www.zlti.com/blog/dow-instruction-5015-federal-records/](https://www.zlti.com/blog/dow-instruction-5015-federal-records/)  
> 33. Test data for Evidence Records implementation (RFC 4998\) · Issue \#1216 · bcgit/bc-java, [https://github.com/bcgit/bc-java/issues/1216](https://github.com/bcgit/bc-java/issues/1216)  
> 34. Classified Information Policy and Executive Order 13526 \- The Web site cannot be found, [https://www.files.ethz.ch/isn/125799/153313.pdf](https://www.files.ethz.ch/isn/125799/153313.pdf)  
> 35. BBS+ Signatures for Selective Disclosure in Verifiable Credentials, [https://solidus.network/research/bbs-plus-signatures](https://solidus.network/research/bbs-plus-signatures)  
> 36. PROV-O: The PROV Ontology \- W3C, [https://www.w3.org/TR/prov-o/](https://www.w3.org/TR/prov-o/)  
> 37. ODRL Information Model \- W3C on GitHub, [https://w3c.github.io/poe/snapshots/WD-odrl-model-2016-07-21/](https://w3c.github.io/poe/snapshots/WD-odrl-model-2016-07-21/)  
> 38. BBS+ Signatures: Applications, Standardizations, and a bit of Theory | CSRC, [https://csrc.nist.gov/presentations/2023/bbs-signatures-applications-standardizations-and-a](https://csrc.nist.gov/presentations/2023/bbs-signatures-applications-standardizations-and-a)  
> 39. SD Agent: Selective Disclosure for Agent Discovery and Identity Management \- IETF, [https://www.ietf.org/archive/id/draft-nandakumar-agent-sd-jwt-02.html](https://www.ietf.org/archive/id/draft-nandakumar-agent-sd-jwt-02.html)  
> 40. C2PA Technical Specification, [https://spec.c2pa.org/specifications/specifications/1.0/specs/C2PA\_Specification.html](https://spec.c2pa.org/specifications/specifications/1.0/specs/C2PA_Specification.html)  
> 41. EXEMPTION 1: Classified National Security Information, [https://www.accesspro.org/AccessPro/assets/File/training/ntc-2024/Program%20Materials/1%2004%20Exemption%201%20(Melton%20Evitt).pdf](https://www.accesspro.org/AccessPro/assets/File/training/ntc-2024/Program%20Materials/1%2004%20Exemption%201%20\(Melton%20Evitt\).pdf)  
> 42. Open Archival Information System \- SAA Dictionary, [https://dictionary.archivists.org/entry/open-archival-information-system.html](https://dictionary.archivists.org/entry/open-archival-information-system.html)  
> 43. Credential Format \- Identity, Credential and Access Management Document \- 24.07 Release \- Gaia-X, [https://docs.gaia-x.eu/technical-committee/identity-credential-access-management/24.07/credential\_format/](https://docs.gaia-x.eu/technical-committee/identity-credential-access-management/24.07/credential_format/)
