<?xml version="1.0" encoding="utf-8"?>
<rfc ipr="trust200902" docName="draft-wang-coe-02" category="exp" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <front>
    <title abbrev="COE">Cognition-Oriented Emergence (COE): A JEP Profile for Shared Observation and State-Claim Evidence</title>
    <seriesInfo name="Internet-Draft" value="draft-wang-coe-02"/>
    <author initials="Y." surname="Wang" fullname="Yuqiang Wang">
      <organization/>
      <address>
        <email>signal@humanjudgment.org</email>
        <uri>https://github.com/hjs-spec</uri>
      </address>
    </author>
    <date year="2026" month="September" day="26"/>
    <keyword>COE</keyword>
    <keyword>JEP</keyword>
    <keyword>observation</keyword>
    <keyword>state claim</keyword>
    <abstract>
      <t>This document defines COE-2, an optional profile of the Judgment Event Protocol (JEP) <xref target="JEP"/> for binding shared observation records and shared-state claims across heterogeneous agents, sensors, world models, simulators, and human-operated systems.</t>
      <t>COE-2 defines one critical JEP record-binding extension, two minimal digest-addressed record types, evidence-reference semantics, and independent COE validation checks. JEP remains authoritative for event verbs, Event Identity, Event Hash, signatures, references, extension processing, validation modes, and acceptance semantics.</t>
      <t>COE-2 provides verifiable shared-observation infrastructure. It does not determine objective world truth, factual causality, consensus, authorization, legal effect, fairness, trust weights, or regulatory compliance. A valid COE result establishes only the cryptographic and structural properties actually checked under the selected profiles.</t>
    </abstract>
  </front>
  <middle>
    <section anchor="intro"><name>Introduction</name>
      <t>Heterogeneous agents, sensors, simulators, world models, and human-operated systems increasingly exchange observation-derived evidence about shared operational environments. These systems may observe different projections of the same target, use different evidence formats, or derive state claims under different policies.</t>
      <t>COE addresses a narrow interoperability problem:</t>
      <sourcecode type="text"><![CDATA[
Which observation or state-claim record was bound to this JEP event,
which evidence references does that record declare,
and can those bindings be independently revalidated?
]]></sourcecode>
      <t>COE does not define a universal world model or a truth engine.</t>
      <t>JEP Profiles <xref target="JEP-PROFILES"/> defines profile selection and composition rules. JEP Conformance <xref target="JEP-CONFORMANCE"/> defines structured validation-result and test-harness conventions. JEP Receipt Profile <xref target="JEP-RECEIPT"/> MAY package COE records as evidence artifacts. JAC <xref target="JAC"/> MAY express declared dependencies between JEP events associated with COE records.</t>
      <t>Where this document conflicts with JEP-Core, JEP-Core controls.</t>
    </section>
    <section anchor="requirements"><name>Requirements Language</name>
      <t>The key words MUST, MUST NOT, REQUIRED, SHALL, SHALL NOT, SHOULD, SHOULD NOT, RECOMMENDED, NOT RECOMMENDED, MAY, and OPTIONAL in this document are to be interpreted as described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they appear in all capitals.</t>
    </section>
    <section anchor="scope"><name>Scope and Terminology</name>
      <section anchor="defines"><name>COE-2 Defines</name>
      <t>COE-2 defines:</t>
      <ul spacing="normal">
        <li>one profile identifier;</li>
        <li>one critical COE record-binding extension;</li>
        <li>one Observation Record;</li>
        <li>one Shared-State Claim Record;</li>
        <li>one Evidence Reference structure;</li>
        <li>optional semantic-profile references for observation and state-claim payloads;</li>
        <li>independent COE validation checks;</li>
        <li>open-world and non-inference boundaries.</li>
      </ul>
      </section>
      <section anchor="non-goals"><name>COE-2 Does Not Define</name>
      <t>COE-2 does not define:</t>
      <ul spacing="normal">
        <li>new JEP verbs;</li>
        <li>an independent event, signature, or hash format;</li>
        <li>a replacement for Event Identity or Event Hash;</li>
        <li>a universal world model;</li>
        <li>a global observation ontology;</li>
        <li>objective truth;</li>
        <li>consensus or trust-weight algorithms;</li>
        <li>factual causality;</li>
        <li>complete-history semantics;</li>
        <li>authorization or delegation validity;</li>
        <li>adapter correctness;</li>
        <li>timestamp authority;</li>
        <li>determinability proofs;</li>
        <li>governance or policy outcomes;</li>
        <li>legal effect or regulatory compliance.</li>
      </ul>
      </section>
      <section anchor="term-observer"><name>Observer</name>
      <t>The entity identified in an Observation Record as having produced or reported the observation.</t>
      <t>The Observer need not be the same entity as the JEP actor or signer.</t>
      </section>
      <section anchor="term-target"><name>Target</name>
      <t>The object, environment, resource, entity, region, process, or other subject about which an observation or state claim is made.</t>
      </section>
      <section anchor="term-observation"><name>Observation Record</name>
      <t>A digest-addressed record declaring that an Observer produced or reported an observation about a Target and identifying the observation payload and supporting evidence.</t>
      <t>An Observation Record does not establish that the observation is true, complete, unbiased, or sufficient.</t>
      </section>
      <section anchor="term-state-claim"><name>Shared-State Claim</name>
      <t>A digest-addressed record declaring a state claim about a Target under an identified synthesis profile and evidence set.</t>
      <t>In <tt>Shared-State Claim</tt>, "shared" means that the claim is structured for exchange across systems. It does not mean that the claim is agreed, consensual, authoritative, unique, or objectively true.</t>
      <t>A Shared-State Claim does not establish objective world state, consensus, or uniqueness.</t>
      </section>
      <section anchor="term-evidence"><name>Evidence Reference</name>
      <t>A digest-first reference to evidence material.</t>
      <t>A retrieval URI, when present, is a hint and is not the integrity identity of the evidence.</t>
      </section>
    </section>
    <section anchor="identifiers"><name>Profile and Extension Identifiers</name>
      <section anchor="profile-id"><name>COE-2 Profile Identifier</name>
      <t>The profile identifier is:</t>
      <sourcecode type="text"><![CDATA[
https://humanjudgment.org/jep/profiles/coe/2
]]></sourcecode>
      <t>The label <tt>COE-2</tt> MAY be used in documentation and user interfaces.</t>
      <t>The identifier is a publisher-controlled HTTPS URI. Dereferencing it is not required for validation.</t>
      </section>
      <section anchor="binding-ext-id"><name>COE Record-Binding Extension Identifier</name>
      <t>The critical COE record-binding extension identifier is:</t>
      <sourcecode type="text"><![CDATA[
https://humanjudgment.org/jep/extensions/coe-record-binding/2
]]></sourcecode>
      <t>A JEP event claiming COE-2 conformance MUST carry this extension in <tt>ext</tt> and MUST list the extension identifier in <tt>ext_crit</tt>.</t>
      <t>A verifier that cannot process this critical extension cannot claim successful COE-2 validation.</t>
      </section>
      <section anchor="version-boundary"><name>Version Boundary</name>
      <t>COE-2 is not wire-compatible with COE-Core-1 from <tt>draft-wang-coe-01</tt>.</t>
      <t>COE-Core-1 commonly bound a COE record by placing its digest in JEP <tt>what</tt>. That cannot serve as a generic JEP-Core 0.7 binding rule because D, T, and V have verb-specific required <tt>what</tt> members.</t>
      <t>COE-2 moves record binding to one critical extension and leaves Core <tt>what</tt> semantics entirely under JEP-Core.</t>
      <t>Historical COE-Core-1 records and events MUST NOT be silently rewritten as COE-2 records or events.</t>
      </section>
    </section>
    <section anchor="jep-relation"><name>Relationship to JEP-Core</name>
      <t>COE-2 relies on JEP-Core for:</t>
      <ul spacing="normal">
        <li>J, D, T, and V semantics;</li>
        <li>required Core event members;</li>
        <li>Event Identity <tt>(who,id)</tt>;</li>
        <li>Event Hash;</li>
        <li>JEP Signing Payload and signature validation;</li>
        <li><tt>ref</tt>;</li>
        <li><tt>ext</tt> and <tt>ext_crit</tt>;</li>
        <li>independent validation checks;</li>
        <li>validation modes;</li>
        <li>idempotent acceptance.</li>
      </ul>
      <t>COE-2 MUST NOT redefine those semantics.</t>
      <t>A producer MUST satisfy the selected JEP verb's Core requirements before COE record binding is considered.</t>
      <t>In particular:</t>
      <ul spacing="normal">
        <li>a D event MUST retain <tt>what.delegatee</tt> and <tt>what.scope</tt>;</li>
        <li>a T event MUST retain <tt>what.termination_scope</tt> and identify its target through JEP <tt>ref</tt>;</li>
        <li>a V event MUST retain <tt>what.verification_scope</tt>, <tt>what.result</tt>, and JEP <tt>ref</tt>.</li>
      </ul>
      <t>COE metadata MUST NOT replace those fields.</t>
    </section>
    <section anchor="binding-extension"><name>COE Record-Binding Extension</name>
      <section anchor="extension-value"><name>Extension Value</name>
      <t>The extension value MUST be a JSON object containing:</t>
      <ul spacing="normal">
        <li><tt>profile</tt></li>
        <li><tt>record_type</tt></li>
        <li><tt>record_digest</tt></li>
        <li><tt>media_type</tt></li>
      </ul>
      <t><tt>profile</tt> MUST equal <tt>https://humanjudgment.org/jep/profiles/coe/2</tt>.</t>
      <t><tt>record_type</tt> MUST be one of:</t>
      <ul spacing="normal">
        <li><tt>observation</tt></li>
        <li><tt>shared-state-claim</tt></li>
      </ul>
      <t><tt>record_digest</tt> MUST be an algorithm-tagged digest string conforming to JEP digest-string rules.</t>
      <t><tt>media_type</tt> MUST be a non-empty string. The baseline COE-2 record encoding is <tt>application/json</tt>.</t>
      <t>The extension MAY contain <tt>record_uri</tt>. If present, it MUST be an absolute URI and is a retrieval hint only.</t>
      <t>Each COE-2 event binds exactly one primary COE record through this extension.</t>
      </section>
      <section anchor="extension-example"><name>Extension Example</name>
      <sourcecode type="json"><![CDATA[
{
  "ext": {
    "https://humanjudgment.org/jep/extensions/coe-record-binding/2": {
      "profile": "https://humanjudgment.org/jep/profiles/coe/2",
      "record_type": "observation",
      "record_digest": "sha256:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa",
      "media_type": "application/json"
    }
  },
  "ext_crit": [
    "https://humanjudgment.org/jep/extensions/coe-record-binding/2"
  ]
}
]]></sourcecode>
      <t>The example digest is illustrative.</t>
      </section>
      <section anchor="circularity"><name>Binding-Event Circularity</name>
      <t>A COE record MUST NOT contain the Event Hash of the JEP event that binds that record.</t>
      <t>The record MAY contain that event's Event Identity when a companion profile requires such a back-reference, because Event Identity is stable independently of the event signature.</t>
      </section>
    </section>
    <section anchor="evidence-reference"><name>Evidence Reference</name>
      <t>An Evidence Reference MUST be a JSON object containing:</t>
      <ul spacing="normal">
        <li><tt>digest</tt></li>
      </ul>
      <t><tt>digest</tt> MUST be an algorithm-tagged digest string.</t>
      <t>An Evidence Reference MAY additionally contain:</t>
      <ul spacing="normal">
        <li><tt>kind</tt></li>
        <li><tt>profile</tt></li>
        <li><tt>record_type</tt></li>
        <li><tt>media_type</tt></li>
        <li><tt>uri</tt></li>
        <li><tt>redaction</tt></li>
      </ul>
      <t>When present:</t>
      <ul spacing="normal">
        <li><tt>kind</tt>, <tt>record_type</tt>, and <tt>media_type</tt> MUST be non-empty strings;</li>
        <li><tt>profile</tt> and <tt>uri</tt> MUST be absolute URIs;</li>
        <li><tt>redaction</tt> SHOULD be one of <tt>none</tt>, <tt>partial</tt>, <tt>digest-only</tt>, or <tt>withheld</tt>.</li>
      </ul>
      <t>The digest is the integrity identity. URI resolution success MUST NOT be treated as digest-integrity success.</t>
      <t>If an Evidence Reference identifies an object governed by another profile, such as JEP Receipt Profile, validity under that other profile MUST be evaluated and reported separately from COE validity.</t>
    </section>
    <section anchor="observation-record"><name>Observation Record</name>
      <section anchor="observation-shape"><name>Required Shape</name>
      <t>A COE-2 Observation Record MUST be a JSON object containing:</t>
      <ul spacing="normal">
        <li><tt>coe_record</tt></li>
        <li><tt>record_type</tt></li>
        <li><tt>observer</tt></li>
        <li><tt>target</tt></li>
        <li><tt>observed_at</tt></li>
        <li><tt>observation</tt></li>
        <li><tt>evidence</tt></li>
      </ul>
      <t><tt>coe_record</tt> MUST equal <tt>"2"</tt>.</t>
      <t><tt>record_type</tt> MUST equal <tt>"observation"</tt>.</t>
      <t><tt>observer</tt> MUST be an object containing a non-empty string <tt>id</tt>. <tt>observer.type</tt> MAY be a non-empty string.</t>
      <t><tt>target</tt> MUST be an object containing non-empty string members <tt>type</tt> and <tt>id</tt>.</t>
      <t><tt>observed_at</tt> MUST be a non-negative integer representing declared Unix seconds. It is not trusted time or proof of freshness.</t>
      <t><tt>observation</tt> MUST be an Evidence Reference whose <tt>digest</tt> identifies the observation payload.</t>
      <t><tt>evidence</tt> MUST be an array of zero or more Evidence References.</t>
      </section>
      <section anchor="observation-optional"><name>Optional Members</name>
      <t>An Observation Record MAY additionally contain:</t>
      <ul spacing="normal">
        <li><tt>observation_profile</tt></li>
        <li><tt>world_model</tt></li>
        <li><tt>adapter</tt></li>
        <li><tt>context</tt></li>
      </ul>
      <t><tt>observation_profile</tt>, when present, MUST be an absolute URI identifying the schema, vocabulary, semantic profile, or equivalent interpretation contract for the observation payload.</t>
      <t>If interoperable semantic interpretation of the observation payload is required outside the originating deployment, the producer MUST include <tt>observation_profile</tt>.</t>
      <t>A verifier that does not understand <tt>observation_profile</tt> MAY still validate the COE record binding and digest, but MUST NOT claim semantic interpretation of the observation payload under that profile.</t>
      <t><tt>world_model</tt>, when present, MUST be an Evidence Reference.</t>
      <t><tt>adapter</tt>, when present, MUST be an Evidence Reference.</t>
      <t><tt>context</tt>, when present, MUST be a JSON object whose semantics are defined by the deployment or an explicitly selected companion profile.</t>
      <t>COE-2 does not define confidence scores, trust weights, or accuracy metrics. A companion profile MAY define them.</t>
      </section>
      <section anchor="observation-digest"><name>Observation Record Digest</name>
      <t>The Observation Record Digest uses JCS <xref target="RFC8785"/> and is:</t>
      <sourcecode type="text"><![CDATA[
sha256(UTF8(JCS(observation_record)))
]]></sourcecode>
      <t>COE-2 producers and verifiers MUST support <tt>sha256</tt> for Observation Record digests.</t>
      <t>A companion profile MAY permit additional digest algorithms.</t>
      </section>
    </section>
    <section anchor="state-claim-record"><name>Shared-State Claim Record</name>
      <section anchor="state-shape"><name>Required Shape</name>
      <t>A COE-2 Shared-State Claim Record MUST be a JSON object containing:</t>
      <ul spacing="normal">
        <li><tt>coe_record</tt></li>
        <li><tt>record_type</tt></li>
        <li><tt>target</tt></li>
        <li><tt>claim</tt></li>
        <li><tt>evidence</tt></li>
        <li><tt>synthesis_profile</tt></li>
      </ul>
      <t><tt>coe_record</tt> MUST equal <tt>"2"</tt>.</t>
      <t><tt>record_type</tt> MUST equal <tt>"shared-state-claim"</tt>.</t>
      <t><tt>target</tt> MUST be an object containing non-empty string members <tt>type</tt> and <tt>id</tt>.</t>
      <t><tt>claim</tt> MUST be an Evidence Reference identifying the state-claim payload.</t>
      <t><tt>evidence</tt> MUST be a non-empty array of Evidence References.</t>
      <t><tt>synthesis_profile</tt> MUST be an absolute URI identifying the procedure or policy under which the claim was derived.</t>
      </section>
      <section anchor="state-optional"><name>Optional Members</name>
      <t>A Shared-State Claim Record MAY contain:</t>
      <ul spacing="normal">
        <li><tt>claim_profile</tt></li>
        <li><tt>synthesis_report</tt></li>
        <li><tt>validity</tt></li>
        <li><tt>context</tt></li>
      </ul>
      <t><tt>claim_profile</tt>, when present, MUST be an absolute URI identifying the schema, vocabulary, semantic profile, or equivalent interpretation contract for the state-claim payload.</t>
      <t>If interoperable semantic interpretation of the claim payload is required outside the originating deployment, the producer MUST include <tt>claim_profile</tt>.</t>
      <t>A verifier that does not understand <tt>claim_profile</tt> MAY still validate the COE record binding and digest, but MUST NOT claim semantic interpretation of the state-claim payload under that profile.</t>
      <t><tt>synthesis_report</tt>, when present, MUST be an Evidence Reference.</t>
      <t><tt>validity</tt>, when present, MUST be an object that MAY contain <tt>valid_from</tt> and <tt>valid_until</tt>.</t>
      <t><tt>valid_from</tt> and <tt>valid_until</tt>, when present and non-null, MUST be non-negative integers representing declared Unix seconds.</t>
      <t>If both are present and non-null, <tt>valid_until</tt> MUST NOT precede <tt>valid_from</tt>.</t>
      <t>These times are declared claim intervals. They are not trusted timestamps or proof that the external world had the claimed state during that interval.</t>
      <t><tt>context</tt>, when present, MUST be a JSON object defined by the deployment or an explicitly selected companion profile.</t>
      </section>
      <section anchor="state-claim-digest"><name>Shared-State Claim Digest</name>
      <t>The Shared-State Claim Record Digest uses JCS <xref target="RFC8785"/> and is:</t>
      <sourcecode type="text"><![CDATA[
sha256(UTF8(JCS(shared_state_claim_record)))
]]></sourcecode>
      <t>COE-2 producers and verifiers MUST support <tt>sha256</tt> for Shared-State Claim digests.</t>
      </section>
      <section anchor="synthesis-external"><name>Synthesis Is External</name>
      <t>COE-2 does not define a state-synthesis algorithm.</t>
      <t>A synthesis profile MAY define aggregation, filtering, conflict resolution, confidence handling, voting, weighting, model comparison, or other methods.</t>
      <t>A COE verifier MUST NOT infer that a synthesis profile is correct, unbiased, complete, authoritative, or suitable merely because its identifier is present.</t>
      </section>
    </section>
    <section anchor="verb-usage"><name>JEP Verb Usage</name>
      <t>COE-2 does not assign new meanings to J/D/T/V.</t>
      <t>A J event MAY carry a claim concerning issuance, adoption, or interpretation of a COE record while the COE binding remains in the critical extension.</t>
      <t>A D event MAY carry a COE binding, but its delegation meaning remains entirely defined by JEP-Core and any applicable delegation profile.</t>
      <t>A T event MAY terminate future reliance on a referenced JEP event within its declared termination scope. COE-2 does not define a state-claim retraction or cascade rule merely because a COE record is associated with that event.</t>
      <t>A V event MAY record evaluation of a COE record or COE evidence under a declared verification scope.</t>
      <t>COE record type MUST NOT be inferred solely from the JEP verb.</t>
    </section>
    <section anchor="receipt-profile"><name>Interaction with JEP Receipt Profile</name>
      <t>JEP Receipt Profile is optional for COE-2.</t>
      <t>A COE record MAY appear as an external evidence object in a JEP Receipt Profile bundle.</t>
      <t>A receipt bundle MAY include:</t>
      <ul spacing="normal">
        <li>a JEP event carrying the COE binding extension;</li>
        <li>the bound COE record;</li>
        <li>evidence referenced by that COE record;</li>
        <li>a receipt manifest referring to those artifacts.</li>
      </ul>
      <t>Receipt Profile validity and COE validity MUST be reported separately.</t>
      <t>A valid receipt does not make a COE state claim true, and a valid COE record does not by itself make a receipt complete.</t>
    </section>
    <section anchor="jac"><name>Interaction with JAC</name>
      <t>JAC is optional for COE-2.</t>
      <t>A JEP event associated with a COE record MAY also carry JAC dependency metadata.</t>
      <t>A COE Evidence Reference does not automatically create a JAC graph edge.</t>
      <t>A JAC edge between events does not automatically create a COE evidence relationship.</t>
      <t>If both profiles are used, implementations MUST preserve their independent semantics and validation results.</t>
      <t>JAC validity does not establish observation truth, state-claim truth, or COE evidence sufficiency.</t>
    </section>
    <section anchor="validation"><name>Validation</name>
      <section anchor="validation-layers"><name>Layer Separation</name>
      <t>A COE validation result separates:</t>
      <ul spacing="normal">
        <li>underlying JEP validation status;</li>
        <li>COE checks;</li>
        <li>COE overall status.</li>
      </ul>
      <t>COE MUST NOT overwrite the underlying JEP validation result.</t>
      </section>
      <section anchor="validation-mode"><name>Baseline Validation Mode</name>
      <t>A COE-2 verifier MUST support JEP <tt>archival</tt> validation mode.</t>
      <t>If no JEP validation mode is explicitly requested, COE validation MUST use <tt>archival</tt> mode.</t>
      <t>Archival COE validation MUST NOT consume JEP acceptance state.</t>
      <t>A deployment MAY explicitly request another JEP validation mode when needed.</t>
      </section>
      <section anchor="validation-checks"><name>COE Checks</name>
      <t>The initial COE-2 check identifiers are:</t>
      <ul spacing="normal">
        <li><tt>https://humanjudgment.org/jep/profiles/coe/2#profile-binding</tt></li>
        <li><tt>https://humanjudgment.org/jep/profiles/coe/2#record-binding</tt></li>
        <li><tt>https://humanjudgment.org/jep/profiles/coe/2#record-structure</tt></li>
        <li><tt>https://humanjudgment.org/jep/profiles/coe/2#target-consistency</tt></li>
        <li><tt>https://humanjudgment.org/jep/profiles/coe/2#evidence-reference</tt></li>
        <li><tt>https://humanjudgment.org/jep/profiles/coe/2#evidence-integrity</tt></li>
        <li><tt>https://humanjudgment.org/jep/profiles/coe/2#synthesis-reference</tt></li>
        <li><tt>https://humanjudgment.org/jep/profiles/coe/2#validity-interval</tt></li>
      </ul>
      <t>Check statuses use the JEP conformance vocabulary:</t>
      <ul spacing="normal">
        <li><tt>pass</tt></li>
        <li><tt>fail</tt></li>
        <li><tt>not_checked</tt></li>
        <li><tt>not_applicable</tt></li>
        <li><tt>unsupported</tt></li>
        <li><tt>indeterminate</tt></li>
      </ul>
      <t>A verifier MUST NOT report an unperformed COE check as <tt>pass</tt>.</t>
      </section>
      <section anchor="required-checks"><name>Required Checks</name>
      <t>For any COE-2 event, the required checks are:</t>
      <ul spacing="normal">
        <li><tt>profile-binding</tt></li>
        <li><tt>record-binding</tt></li>
        <li><tt>record-structure</tt></li>
      </ul>
      <t><tt>target-consistency</tt> is required when the requested validation context contains an external target identifier to compare against the COE record.</t>
      <t>The presence of <tt>observation_profile</tt> or <tt>claim_profile</tt> does not make semantic interpretation part of baseline COE structural validation. A deployment or companion profile that requires semantic interpretation MUST define the supported profile identifiers and the validation procedure for them.</t>
      <t><tt>evidence-reference</tt> is required when the COE record contains evidence references.</t>
      <t><tt>evidence-integrity</tt> is required only for evidence objects that the requested validation context requires to be resolved and checked.</t>
      <t><tt>synthesis-reference</tt> and <tt>validity-interval</tt> are required for Shared-State Claim Records when the corresponding fields are present.</t>
      </section>
      <section anchor="target-consistency"><name>Target Consistency</name>
      <t>COE-2 does not define a universal target-comparison algorithm.</t>
      <t>A domain profile that requires target matching MUST define normalization and comparison rules.</t>
      <t>Absent such a domain rule, a verifier MUST NOT claim semantic target equality merely from string similarity.</t>
      </section>
      <section anchor="overall-status"><name>COE Overall Status</name>
      <t>The COE overall status is one of:</t>
      <ul spacing="normal">
        <li><tt>valid</tt></li>
        <li><tt>invalid</tt></li>
        <li><tt>indeterminate</tt></li>
      </ul>
      <t>For the requested COE validation context:</t>
      <ul spacing="normal">
        <li><tt>invalid</tt> means the underlying required JEP validation is invalid or at least one required COE check failed;</li>
        <li><tt>indeterminate</tt> means no required check failed, but the underlying required JEP validation is indeterminate or at least one required COE check is unsupported, not checked, or indeterminate;</li>
        <li><tt>valid</tt> means the underlying required JEP validation is valid and every required COE check passed or was not applicable.</li>
      </ul>
      <t><tt>valid</tt> means structurally and cryptographically valid under the selected checks. It does not mean objectively true.</t>
      </section>
      <section anchor="validation-procedure"><name>Validation Procedure</name>
      <t>A COE verifier SHOULD:</t>
      <ul spacing="normal">
        <li>validate the JEP event under the requested JEP mode and selected profiles;</li>
        <li>process the critical COE record-binding extension;</li>
        <li>verify the COE profile identifier;</li>
        <li>obtain the bound COE record;</li>
        <li>canonicalize and hash the record;</li>
        <li>compare the recomputed digest with <tt>record_digest</tt>;</li>
        <li>validate the record structure for <tt>record_type</tt>;</li>
        <li>evaluate target consistency when required;</li>
        <li>validate evidence-reference structure;</li>
        <li>resolve and verify required evidence digests;</li>
        <li>validate synthesis-profile and optional synthesis-report references for a Shared-State Claim;</li>
        <li>validate the declared validity interval when present;</li>
        <li>return JEP status, COE checks, and COE status separately.</li>
      </ul>
      </section>
    </section>
    <section anchor="verification-events"><name>Verification Events</name>
      <t>A JEP V event MAY record a COE evaluation.</t>
      <t>The V event MUST satisfy JEP-Core V requirements.</t>
      <t>COE-2 defines the following provisional profile-specific verification scopes:</t>
      <ul spacing="normal">
        <li><tt>https://humanjudgment.org/jep/profiles/coe/2#record-binding</tt></li>
        <li><tt>https://humanjudgment.org/jep/profiles/coe/2#observation-validation</tt></li>
        <li><tt>https://humanjudgment.org/jep/profiles/coe/2#state-claim-validation</tt></li>
        <li><tt>https://humanjudgment.org/jep/profiles/coe/2#evidence-integrity</tt></li>
      </ul>
      <t>A V event MUST identify the evaluated target through JEP <tt>ref</tt>.</t>
      <t><tt>what.result</tt> records the semantic result of the declared verification scope. It MUST NOT be confused with the independent per-check status vocabulary used by a COE validator.</t>
      <t>A V event MUST NOT imply truth, completeness, or determinability beyond its declared verification scope.</t>
    </section>
    <section anchor="partial-observation"><name>Partial Observation and Determinability</name>
      <t>COE-2 uses an open-world observation model.</t>
      <t>Absence of an Observation Record MUST NOT be interpreted as proof that an observation did not occur.</t>
      <t>Absence of a conflicting observation MUST NOT be interpreted as proof that no conflicting observation exists.</t>
      <t>A set of COE records MUST NOT be presented as complete unless an explicitly selected external profile defines a complete-observation assumption and the requirements of that profile were satisfied.</t>
      <t>COE-2 does not define whether a target fact is uniquely or zero-error determinable from available evidence.</t>
      <t>A determinability report MAY be referenced as evidence under an external profile, but COE validity MUST NOT be presented as proof that the report is correct or that the target fact is determinable.</t>
    </section>
    <section anchor="companion-semantics"><name>Optional Companion Semantics</name>
      <t>COE-01 defined or described adapter, synthesis-report, version-anchor, timestamp-anchor, determinability-report, and multiple record-type-specific extensions.</t>
      <t>COE-2 removes those elements from the narrow waist.</t>
      <t>A companion profile MAY define:</t>
      <ul spacing="normal">
        <li>adapter descriptors;</li>
        <li>synthesis reports;</li>
        <li>timestamp evidence;</li>
        <li>version anchors;</li>
        <li>consensus or weighting methods;</li>
        <li>determinability reports;</li>
        <li>confidence models;</li>
        <li>multi-party evidence views;</li>
        <li>domain ontologies;</li>
        <li>observation and claim semantic profiles;</li>
        <li>evidence-access policy.</li>
      </ul>
      <t>Such profiles MUST NOT redefine JEP-Core semantics or the COE-2 baseline record types.</t>
    </section>
    <section anchor="conformance"><name>Conformance</name>
      <section anchor="conf-producer"><name>COE-2 Producer</name>
      <t>A conforming COE-2 Producer MUST:</t>
      <ul spacing="normal">
        <li>produce a JEP event conforming to the applicable JEP Producer requirements;</li>
        <li>preserve the selected JEP verb semantics;</li>
        <li>include the critical COE record-binding extension;</li>
        <li>list the extension in <tt>ext_crit</tt>;</li>
        <li>use the COE-2 profile identifier;</li>
        <li>bind exactly one Observation Record or Shared-State Claim Record by digest;</li>
        <li>produce that record according to this specification;</li>
        <li>avoid circular binding through the binding event's Event Hash.</li>
      </ul>
      </section>
      <section anchor="conf-verifier"><name>COE-2 Verifier</name>
      <t>A conforming COE-2 Verifier MUST:</t>
      <ul spacing="normal">
        <li>perform or consume an actual JEP validation result;</li>
        <li>support JEP <tt>archival</tt> validation mode;</li>
        <li>process the critical COE extension;</li>
        <li>support JCS plus SHA-256 record digest calculation;</li>
        <li>perform all COE checks required by its validation context;</li>
        <li>preserve independent check statuses;</li>
        <li>distinguish JEP validity from COE validity;</li>
        <li>return <tt>indeterminate</tt> rather than success when a required check cannot be completed.</li>
      </ul>
      </section>
    </section>
    <section anchor="security"><name>Security Considerations</name>
      <t>A valid COE result does not prove observation truth or objective state.</t>
      <t>Implementations MUST consider:</t>
      <ul spacing="normal">
        <li>actor/signer/observer confusion;</li>
        <li>false but correctly signed observations;</li>
        <li>false but correctly hashed evidence;</li>
        <li>Event Identity/Event Hash confusion;</li>
        <li>record substitution;</li>
        <li>URI substitution;</li>
        <li>circular binding;</li>
        <li>omitted or selectively exported evidence;</li>
        <li>inconsistent target identifiers;</li>
        <li>synthesis-profile confusion;</li>
        <li>unsupported critical extensions;</li>
        <li>false completeness assumptions;</li>
        <li>confidence or trust-weight inflation;</li>
        <li>semantic inflation from "declared state claim" to "world truth".</li>
      </ul>
      <t>A verifier MUST compare the recomputed COE record digest with the digest inside the signed critical COE extension.</t>
      <t>A verifier MUST NOT infer actor binding, authority, causality, truth, completeness, or policy compliance from successful COE structural validation.</t>
    </section>
    <section anchor="privacy"><name>Privacy Considerations</name>
      <t>COE records can expose:</t>
      <ul spacing="normal">
        <li>observers and system identifiers;</li>
        <li>observed targets;</li>
        <li>observation timing;</li>
        <li>world-model or adapter relationships;</li>
        <li>evidence relationships;</li>
        <li>physical or organizational structure;</li>
        <li>location or environment context;</li>
        <li>shared-state claims.</li>
      </ul>
      <t>Implementations SHOULD minimize plaintext personal or sensitive data.</t>
      <t>Evidence SHOULD be referenced by digest when embedding it is unnecessary.</t>
      <t>Digest references may still support correlation or dictionary attacks.</t>
      <t>Partial export and redaction MAY reduce disclosure, but omitted material MUST NOT be presented as nonexistent or irrelevant.</t>
      <t>COE does not determine access rights, consent, lawful basis, retention periods, or entitlement to disclose evidence.</t>
    </section>
    <section anchor="non-inference"><name>Non-Inference Boundary</name>
      <t>A successful COE validation MUST NOT be presented, by itself, as proof:</t>
      <ul spacing="normal">
        <li>that an observation is objectively true;</li>
        <li>that a Shared-State Claim is the objective world state;</li>
        <li>that all relevant observations were disclosed;</li>
        <li>that no conflicting observation exists;</li>
        <li>that a state claim is uniquely determined;</li>
        <li>that a synthesis method is correct or authoritative;</li>
        <li>that a confidence or trust value is justified;</li>
        <li>that one event or observation caused another;</li>
        <li>that an action was authorized;</li>
        <li>that a policy or governance outcome should follow;</li>
        <li>that a person or organization is liable or not liable;</li>
        <li>that a legal or regulatory requirement was satisfied.</li>
      </ul>
      <t>External profiles MAY use COE evidence when making those determinations, but those conclusions remain outside COE-2.</t>
    </section>
    <section anchor="iana"><name>IANA Considerations</name>
      <t>This document requests no IANA actions.</t>
      <t>The COE-2 profile identifier, record-binding extension identifier, COE check identifiers, and COE verification-scope identifiers are publisher-controlled HTTPS URI identifiers.</t>
      <t>Future specifications MAY define registries if deployment experience shows that stable shared registries are needed.</t>
    </section>
    <section anchor="examples"><name>Examples</name>
      <section anchor="ex-observation"><name>Observation Record</name>
      <sourcecode type="json"><![CDATA[
{
  "coe_record": "2",
  "record_type": "observation",
  "observer": {
    "id": "did:example:robot-a",
    "type": "sensor-system"
  },
  "target": {
    "type": "warehouse-zone",
    "id": "warehouse-zone-3"
  },
  "observed_at": 1790424000,
  "observation": {
    "digest": "sha256:1111111111111111111111111111111111111111111111111111111111111111",
    "kind": "sensor-output",
    "media_type": "application/json"
  },
  "observation_profile": "https://example.org/coe/observations/temperature/v1",
  "evidence": [
    {
      "digest": "sha256:2222222222222222222222222222222222222222222222222222222222222222",
      "kind": "sensor-calibration",
      "media_type": "application/json"
    }
  ]
}
]]></sourcecode>
      </section>
      <section anchor="ex-state-claim"><name>Shared-State Claim</name>
      <sourcecode type="json"><![CDATA[
{
  "coe_record": "2",
  "record_type": "shared-state-claim",
  "target": {
    "type": "warehouse-zone",
    "id": "warehouse-zone-3"
  },
  "claim": {
    "digest": "sha256:3333333333333333333333333333333333333333333333333333333333333333",
    "kind": "state-claim-payload",
    "media_type": "application/json"
  },
  "claim_profile": "https://example.org/coe/claims/warehouse-state/v1",
  "evidence": [
    {
      "digest": "sha256:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa",
      "profile": "https://humanjudgment.org/jep/profiles/coe/2",
      "record_type": "observation",
      "media_type": "application/json"
    }
  ],
  "synthesis_profile": "https://example.org/coe-synthesis/v1",
  "validity": {
    "valid_from": 1790424000,
    "valid_until": 1790427600
  }
}
]]></sourcecode>
      </section>
      <section anchor="ex-jep-binding"><name>JEP Event Carrying a COE Binding</name>
      <sourcecode type="json"><![CDATA[
{
  "jep": "1",
  "id": "urn:uuid:018f4f8d-0000-7000-8000-000000000101",
  "verb": "J",
  "who": "did:example:observer-service",
  "when": 1790424000,
  "what": {
    "claim": "observation-record-issued"
  },
  "ext": {
    "https://humanjudgment.org/jep/extensions/coe-record-binding/2": {
      "profile": "https://humanjudgment.org/jep/profiles/coe/2",
      "record_type": "observation",
      "record_digest": "sha256:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa",
      "media_type": "application/json"
    }
  },
  "ext_crit": [
    "https://humanjudgment.org/jep/extensions/coe-record-binding/2"
  ],
  "sig": "..."
}
]]></sourcecode>
      </section>
    </section>
    <section anchor="changes"><name>Changes from -01</name>
      <t>Major changes from <tt>draft-wang-coe-01</tt>:</t>
      <ul spacing="normal">
        <li>aligned COE with JEP-Core 0.7, JEP Profiles-01, and JEP Conformance-01;</li>
        <li>introduced COE-2 as an incompatible profile revision;</li>
        <li>replaced the generic JEP <tt>what</tt> digest-binding pattern with one critical COE record-binding extension so D, T, and V retain their Core <tt>what</tt> semantics;</li>
        <li>changed logical event relationships to inherit JEP Event Identity semantics and limited Event Hash to exact-artifact pinning;</li>
        <li>removed the HJS technical dependency and aligned optional receipt packaging with JEP Receipt Profile;</li>
        <li>aligned optional dependency-graph semantics with JAC-2;</li>
        <li>reduced the COE narrow waist to two primary record types: Observation Record and Shared-State Claim Record;</li>
        <li>removed the standalone COE Validation Record from the narrow waist; JEP V provides the protocol verification statement;</li>
        <li>reduced evidence to one digest-first Evidence Reference structure;</li>
        <li>added <tt>observation_profile</tt> and <tt>claim_profile</tt> as optional semantic-profile hooks for interoperable payload interpretation without defining a global ontology;</li>
        <li>clarified that "shared" means structured for cross-system exchange, not consensus, authority, or objective truth;</li>
        <li>removed the standalone Evidence Descriptor, Adapter Descriptor, and State-Synthesis Report record types from the COE narrow waist;</li>
        <li>removed observation, validation, state-claim, evidence, adapter, synthesis-report, version-anchor, timestamp-anchor, and determinability-report extension families from the narrow waist;</li>
        <li>defined exact baseline JSON shapes for COE-2 records;</li>
        <li>defined JCS plus SHA-256 record digest rules;</li>
        <li>added a binding-event circularity rule;</li>
        <li>made JEP <tt>archival</tt> mode the required and default repeatable COE validation mode when no other mode is explicitly requested;</li>
        <li>replaced the earlier structural-validation model with independent COE checks and <tt>valid</tt> / <tt>invalid</tt> / <tt>indeterminate</tt> result semantics;</li>
        <li>clarified target matching, partial observation, unresolved evidence, and determinability boundaries;</li>
        <li>changed profile and extension identifiers to publisher-controlled HTTPS URIs;</li>
        <li>changed IANA language to request no action.</li>
      </ul>
    </section>
  </middle>
  <back>
    <references>
      <name>References</name>
      <references>
        <name>Normative References</name>
        <reference anchor="JEP">
          <front><title>Judgment Event Protocol (JEP)</title><author initials="Y." surname="Wang" fullname="Yuqiang Wang"/><date year="2026" month="September" day="26"/></front>
          <seriesInfo name="Internet-Draft" value="draft-wang-jep-judgment-event-protocol-07"/>
        </reference>
        <reference anchor="JEP-PROFILES">
          <front><title>JEP Profiles and Interoperability</title><author initials="Y." surname="Wang" fullname="Yuqiang Wang"/><date year="2026" month="September" day="26"/></front>
          <seriesInfo name="Internet-Draft" value="draft-wang-jep-profiles-01"/>
        </reference>
        <reference anchor="JEP-CONFORMANCE">
          <front><title>JEP Conformance and Test Suite</title><author initials="Y." surname="Wang" fullname="Yuqiang Wang"/><date year="2026" month="September" day="26"/></front>
          <seriesInfo name="Internet-Draft" value="draft-wang-jep-conformance-01"/>
        </reference>
        <reference anchor="RFC2119">
          <front><title>Key words for use in RFCs to Indicate Requirement Levels</title><author initials="S." surname="Bradner"/><date year="1997" month="March"/></front>
          <seriesInfo name="BCP" value="14"/><seriesInfo name="RFC" value="2119"/>
        </reference>
        <reference anchor="RFC8174">
          <front><title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title><author initials="B." surname="Leiba"/><date year="2017" month="May"/></front>
          <seriesInfo name="BCP" value="14"/><seriesInfo name="RFC" value="8174"/>
        </reference>
        <reference anchor="RFC8785">
          <front><title>JSON Canonicalization Scheme (JCS)</title><author initials="A." surname="Rundgren"/><author initials="B." surname="Jordan"/><author initials="S." surname="Erlandsson"/><date year="2020" month="June"/></front>
          <seriesInfo name="RFC" value="8785"/>
        </reference>
      </references>
      <references>
        <name>Informative References</name>
        <reference anchor="JEP-RECEIPT">
          <front><title>JEP Receipt Profile: Verifiable Behavior and Evidence Receipts</title><author initials="Y." surname="Wang" fullname="Yuqiang Wang"/><date year="2026" month="September" day="26"/></front>
          <seriesInfo name="Internet-Draft" value="draft-wang-jep-receipt-profile-00"/>
        </reference>
        <reference anchor="JAC">
          <front><title>JAC: Declared Dependency Graphs for JEP Events and Receipts</title><author initials="Y." surname="Wang" fullname="Yuqiang Wang"/><date year="2026" month="September" day="26"/></front>
          <seriesInfo name="Internet-Draft" value="draft-wang-jac-03"/>
        </reference>
      </references>
    </references>
  </back>
</rfc>
