<?xml version="1.0" encoding="utf-8"?>
<rfc ipr="trust200902" docName="draft-wang-jac-03" category="exp" tocInclude="true" sortRefs="true" symRefs="true" version="3">
  <front>
    <title abbrev="JAC">JAC: Declared Dependency Graphs for JEP Events and Receipts</title>
    <seriesInfo name="Internet-Draft" value="draft-wang-jac-03"/>
    <author initials="Y." surname="Wang" fullname="Yuqiang Wang">
      <organization/>
      <address>
        <email>signal@humanjudgment.org</email>
        <uri>https://github.com/hjs-spec</uri>
      </address>
    </author>
    <date year="2026" month="September" day="26"/>
    <keyword>JAC</keyword>
    <keyword>JEP</keyword>
    <keyword>dependency</keyword>
    <keyword>chains</keyword>
    <abstract>
      <t>This document defines JAC-2, a minimal declared-dependency graph profile for the Judgment Event Protocol (JEP) <xref target="JEP"/>.</t>
      <t>JAC-2 binds a signed JEP event to zero or more declared parent dependencies through one critical JEP extension. JEP Event Identity is used for logical JEP event dependencies; Event Hash is used only when an exact signed artifact must also be pinned. Digest-addressed receipt or external records can be linked without becoming JEP events.</t>
      <t>JAC-2 defines dependency-link structure, partial-fragment semantics, cycle handling, chain validation checks, and non-inference boundaries. It does not determine factual causality, responsibility, fault, authorization validity, workflow correctness, legal effect, or regulatory compliance.</t>
    </abstract>
  </front>
  <middle>
    <section anchor="intro"><name>Introduction</name>
      <t>Agent and automated systems often produce signed events whose interpretation depends on earlier events, records, tool outputs, receipts, or other digest-addressed artifacts.</t>
      <t>JEP-Core intentionally does not define causal-chain or dependency-graph semantics. JAC provides one optional chain profile for that purpose.</t>
      <t>The narrow JAC question is:</t>
      <sourcecode type="text"><![CDATA[
Which parent dependencies did this signed event declare,
and is the observed dependency fragment structurally and
cryptographically consistent under the selected JAC rules?
]]></sourcecode>
      <t>A declared dependency is not a protocol-level finding of real-world causality.</t>
      <t>JEP Profiles <xref target="JEP-PROFILES"/> defines profile selection and composition rules. JEP Conformance <xref target="JEP-CONFORMANCE"/> defines structured validation and test-harness conventions. JEP Receipt Profile <xref target="JEP-RECEIPT"/> defines a portable receipt format that MAY be referenced by digest from JAC.</t>
      <t>Where this document conflicts with JEP-Core, JEP-Core controls.</t>
    </section>
    <section anchor="requirements"><name>Requirements Language</name>
      <t>The key words MUST, MUST NOT, REQUIRED, SHALL, SHALL NOT, SHOULD, SHOULD NOT, RECOMMENDED, NOT RECOMMENDED, MAY, and OPTIONAL in this document are to be interpreted as described in BCP 14 <xref target="RFC2119"/> <xref target="RFC8174"/> when, and only when, they appear in all capitals.</t>
    </section>
    <section anchor="scope"><name>Scope and Terminology</name>
      <section anchor="defines"><name>JAC-2 Defines</name>
      <t>JAC-2 defines:</t>
      <ul spacing="normal">
        <li>one profile identifier;</li>
        <li>one critical dependency extension;</li>
        <li>zero-or-more parent links per JEP event;</li>
        <li>logical JEP-event parent references using Event Identity;</li>
        <li>optional exact-artifact pinning using Event Hash;</li>
        <li>digest-addressed non-JEP parent references;</li>
        <li>partial-fragment and unresolved-parent semantics;</li>
        <li>cycle detection for resolved dependency fragments;</li>
        <li>independent JAC validation checks;</li>
        <li>dependency-graph validation result semantics.</li>
      </ul>
      </section>
      <section anchor="non-goals"><name>JAC-2 Does Not Define</name>
      <t>JAC-2 does not define:</t>
      <ul spacing="normal">
        <li>new JEP verbs;</li>
        <li>a new event format;</li>
        <li>a new signature or hash format;</li>
        <li>a replacement for Event Identity or Event Hash;</li>
        <li>automatic delegation, authorization, or termination propagation;</li>
        <li>factual causality;</li>
        <li>complete real-world history;</li>
        <li>responsibility, fault, negligence, intent, fairness, or entitlement;</li>
        <li>task, workflow, state-machine, handoff, or result semantics;</li>
        <li>legal liability or regulatory compliance;</li>
        <li>a mandatory bundle, transport, archive, or ledger.</li>
      </ul>
      </section>
      <section anchor="term-dependency"><name>Declared Dependency</name>
      <t>A signed statement that the current JEP event depends on or is based on an identified parent according to the relation semantics selected for the link.</t>
      <t>The baseline relation defined by JAC-2 is <tt>declared-dependency</tt>.</t>
      </section>
      <section anchor="term-parent"><name>Parent</name>
      <t>The object referenced by one JAC dependency link.</t>
      <t>A parent MAY be:</t>
      <ul spacing="normal">
        <li>a JEP event identified by Event Identity;</li>
        <li>a digest-addressed receipt record;</li>
        <li>another digest-addressed external record.</li>
      </ul>
      </section>
      <section anchor="term-fragment"><name>Dependency Fragment</name>
      <t>A set of JEP events and referenced parent objects observed together for JAC validation.</t>
      <t>A Dependency Fragment is partial by default.</t>
      <t>JAC retains the term "chain" for continuity, but the JAC-2 baseline data model is a directed dependency graph: it MAY branch and join because an event can declare zero or more parents.</t>
      </section>
      <section anchor="term-resolved"><name>Resolved Parent</name>
      <t>A parent for which the verifier has obtained the referenced object or exact artifact needed by the requested validation context.</t>
      </section>
      <section anchor="term-unresolved"><name>Unresolved Parent</name>
      <t>A syntactically valid parent reference for which the referenced object is not available or cannot be resolved in the requested validation context.</t>
      <t>An unresolved parent is not proof that the parent does not exist.</t>
      </section>
    </section>
    <section anchor="identifiers"><name>Profile and Extension Identifiers</name>
      <section anchor="profile-id"><name>JAC-2 Profile Identifier</name>
      <t>The profile identifier is:</t>
      <sourcecode type="text"><![CDATA[
https://humanjudgment.org/jep/profiles/jac/2
]]></sourcecode>
      <t>The human-readable label <tt>JAC-2</tt> MAY be used in documentation.</t>
      <t>The identifier is a publisher-controlled HTTPS URI. Dereferencing it is not required for validation.</t>
      </section>
      <section anchor="dep-ext-id"><name>Dependency Extension Identifier</name>
      <t>The dependency extension identifier is:</t>
      <sourcecode type="text"><![CDATA[
https://humanjudgment.org/jep/extensions/dependency/2
]]></sourcecode>
      <t>A JEP event claiming JAC-2 conformance MUST carry this extension in <tt>ext</tt> and MUST list the extension identifier in <tt>ext_crit</tt>.</t>
      <t>A verifier that cannot process this critical extension cannot claim successful JAC-2 validation.</t>
      </section>
      <section anchor="version-boundary"><name>Version Boundary</name>
      <t>JAC-2 is not wire-compatible with JAC-Core-1 from <tt>draft-wang-jac-02</tt>.</t>
      <t>JAC-Core-1 used a single digest-oriented <tt>based_on</tt> link and commonly treated JEP Event Hash as the parent-event reference. JAC-2 instead supports multiple parents and uses Event Identity for logical JEP event references.</t>
      <t>Historical JAC-Core-1 events MUST NOT be silently rewritten as JAC-2 events.</t>
      </section>
    </section>
    <section anchor="jep-relation"><name>Relationship to JEP-Core</name>
      <t>JAC-2 relies on JEP-Core for:</t>
      <ul spacing="normal">
        <li>the signed event object;</li>
        <li>J/D/T/V semantics;</li>
        <li>Event Identity <tt>(who,id)</tt>;</li>
        <li>Event Hash;</li>
        <li>the JEP Signing Payload;</li>
        <li>signature validation;</li>
        <li><tt>ref</tt>;</li>
        <li><tt>ext</tt> and <tt>ext_crit</tt>;</li>
        <li>independent validation checks;</li>
        <li>validation modes;</li>
        <li>idempotent acceptance.</li>
      </ul>
      <t>JAC-2 MUST NOT redefine any of those semantics.</t>
      <t>A JAC dependency link is separate from JEP <tt>ref</tt>.</t>
      <t>JEP <tt>ref</tt> retains the meaning defined by JEP-Core. The JAC dependency extension declares graph edges used by JAC chain processing.</t>
      <t>An implementation MUST NOT infer a JAC dependency solely from JEP <tt>ref</tt>.</t>
      <t>A deployment MAY use both JEP <tt>ref</tt> and JAC parent links in one event.</t>
    </section>
    <section anchor="dependency-extension"><name>JAC Dependency Extension</name>
      <section anchor="ext-shape"><name>Extension Shape</name>
      <t>The JAC-2 dependency extension MUST be a JSON object containing:</t>
      <ul spacing="normal">
        <li><tt>profile</tt></li>
        <li><tt>parents</tt></li>
      </ul>
      <t><tt>profile</tt> MUST equal <tt>https://humanjudgment.org/jep/profiles/jac/2</tt>.</t>
      <t><tt>parents</tt> MUST be a JSON array containing zero or more Parent Link objects.</t>
      <t>An empty <tt>parents</tt> array declares that the event is a JAC root in the observed dependency structure. It does not prove that the event had no external predecessors in the real world.</t>
      <t>No other members are defined by the JAC-2 baseline extension.</t>
      <t>The order of entries in <tt>parents</tt> has no semantic meaning.</t>
      </section>
      <section anchor="parent-link"><name>Parent Link</name>
      <t>A Parent Link MUST be a JSON object containing:</t>
      <ul spacing="normal">
        <li><tt>relation</tt></li>
        <li><tt>parent</tt></li>
      </ul>
      <t><tt>relation</tt> MUST equal <tt>declared-dependency</tt> for the JAC-2 baseline.</t>
      <t><tt>parent</tt> MUST be a Parent Reference defined in Section 6.3.</t>
      <t>A future profile MAY define additional relation identifiers. Such identifiers MUST be absolute URIs, MUST be collision-resistant, and MUST define:</t>
      <ul spacing="normal">
        <li>exact edge semantics;</li>
        <li>required parent fields;</li>
        <li>graph-processing rules;</li>
        <li>cycle rules if different from JAC-2;</li>
        <li>non-inference boundaries.</li>
      </ul>
      <t>An additional relation MUST NOT silently redefine <tt>declared-dependency</tt>.</t>
      </section>
      <section anchor="parent-ref"><name>Parent Reference</name>
      <t>A Parent Reference MUST be a JSON object containing <tt>kind</tt>.</t>
      <t><tt>kind</tt> MUST be one of:</t>
      <ul spacing="normal">
        <li><tt>jep-event</tt></li>
        <li><tt>digest-record</tt></li>
      </ul>
      <t><strong>JEP Event Parent</strong></t>
      <t>When <tt>kind</tt> is <tt>jep-event</tt>, the Parent Reference MUST contain <tt>event_identity</tt>.</t>
      <t><tt>event_identity</tt> MUST be an object containing non-empty string members <tt>who</tt> and <tt>id</tt>.</t>
      <t>The Parent Reference MAY additionally contain:</t>
      <ul spacing="normal">
        <li><tt>event_hash</tt></li>
        <li><tt>uri</tt></li>
      </ul>
      <t><tt>event_hash</tt>, when present, MUST be a valid JEP algorithm-tagged digest string and pins one exact signed artifact for the identified event.</t>
      <t><tt>uri</tt>, when present, is a retrieval hint only.</t>
      <t>The logical dependency node is Event Identity, not Event Hash.</t>
      <t>A verifier MUST NOT create two logical JAC nodes merely because two valid signed artifacts for the same Event Identity have different Event Hash values.</t>
      <t>If the same Event Identity resolves to conflicting unsigned JEP event content, JEP Event Identity conflict processing applies and JAC dependency-graph validation MUST NOT report success.</t>
      <t><strong>Digest Record Parent</strong></t>
      <t>When <tt>kind</tt> is <tt>digest-record</tt>, the Parent Reference MUST contain <tt>digest</tt>.</t>
      <t><tt>digest</tt> MUST be an algorithm-tagged digest string.</t>
      <t>The Parent Reference MAY additionally contain:</t>
      <ul spacing="normal">
        <li><tt>profile</tt></li>
        <li><tt>record_type</tt></li>
        <li><tt>media_type</tt></li>
        <li><tt>uri</tt></li>
      </ul>
      <t>If present, <tt>profile</tt> MUST be an absolute URI, <tt>record_type</tt> and <tt>media_type</tt> MUST be non-empty strings, and <tt>uri</tt> MUST be an absolute URI.</t>
      <t>These members are descriptive and MUST NOT replace digest integrity.</t>
      <t>If <tt>profile</tt> equals <tt>https://humanjudgment.org/jep/profiles/receipt/1</tt>, the referenced record is claiming the JEP Receipt Profile namespace. A verifier MUST NOT claim Receipt Profile validity unless that record was separately validated under the applicable Receipt Profile rules.</t>
      </section>
      <section anchor="duplicate-parent"><name>Duplicate Parent Links</name>
      <t>Within one dependency extension, two Parent Links MUST NOT identify the same logical parent under the same relation.</t>
      <t>For <tt>jep-event</tt>, logical equality is Event Identity equality.</t>
      <t>For <tt>digest-record</tt>, logical equality is exact digest-string equality.</t>
      <t>A producer MAY refer to the same logical parent under two different profile-defined relations only when the semantics of those relations require that distinction.</t>
      </section>
      <section anchor="self-dependency"><name>Self-Dependency</name>
      <t>A JAC event MUST NOT contain a <tt>jep-event</tt> parent whose Event Identity equals the current event's Event Identity.</t>
      <t>A self-dependency is a JAC structural failure.</t>
      </section>
    </section>
    <section anchor="examples"><name>Examples</name>
      <section anchor="ex-root"><name>JAC Root</name>
      <sourcecode type="json"><![CDATA[
{
  "jep": "1",
  "id": "urn:uuid:018f4f8d-0000-7000-8000-000000000001",
  "verb": "J",
  "who": "did:example:agent-a",
  "when": 1790424000,
  "what": {
    "claim": "begin-analysis"
  },
  "ext": {
    "https://humanjudgment.org/jep/extensions/dependency/2": {
      "profile": "https://humanjudgment.org/jep/profiles/jac/2",
      "parents": []
    }
  },
  "ext_crit": [
    "https://humanjudgment.org/jep/extensions/dependency/2"
  ],
  "sig": "..."
}
]]></sourcecode>
      </section>
      <section anchor="ex-single"><name>Single JEP Parent</name>
      <sourcecode type="json"><![CDATA[
{
  "jep": "1",
  "id": "urn:uuid:018f4f8d-0000-7000-8000-000000000002",
  "verb": "J",
  "who": "did:example:agent-b",
  "when": 1790424010,
  "what": {
    "claim": "use-prior-analysis"
  },
  "ext": {
    "https://humanjudgment.org/jep/extensions/dependency/2": {
      "profile": "https://humanjudgment.org/jep/profiles/jac/2",
      "parents": [
        {
          "relation": "declared-dependency",
          "parent": {
            "kind": "jep-event",
            "event_identity": {
              "who": "did:example:agent-a",
              "id": "urn:uuid:018f4f8d-0000-7000-8000-000000000001"
            }
          }
        }
      ]
    }
  },
  "ext_crit": [
    "https://humanjudgment.org/jep/extensions/dependency/2"
  ],
  "sig": "..."
}
]]></sourcecode>
      </section>
      <section anchor="ex-multiple"><name>Multiple Parents with Exact Artifact Pin</name>
      <sourcecode type="json"><![CDATA[
{
  "profile": "https://humanjudgment.org/jep/profiles/jac/2",
  "parents": [
    {
      "relation": "declared-dependency",
      "parent": {
        "kind": "jep-event",
        "event_identity": {
          "who": "did:example:agent-a",
          "id": "urn:uuid:018f4f8d-0000-7000-8000-000000000001"
        },
        "event_hash": "sha256:aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa"
      }
    },
    {
      "relation": "declared-dependency",
      "parent": {
        "kind": "digest-record",
        "digest": "sha256:bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb",
        "profile": "https://humanjudgment.org/jep/profiles/receipt/1",
        "record_type": "behavior",
        "media_type": "application/json"
      }
    }
  ]
}
]]></sourcecode>
      <t>The second example fragment is the extension value only.</t>
      </section>
    </section>
    <section anchor="graph"><name>Dependency Graph Semantics</name>
      <section anchor="direction"><name>Direction</name>
      <t>Each Parent Link creates a directed edge:</t>
      <sourcecode type="text"><![CDATA[
current event -> declared parent
]]></sourcecode>
      <t>The edge means only that the current event declares the parent as a dependency under the stated relation.</t>
      <t>It does not, by itself, mean that the parent caused the current event.</t>
      </section>
      <section anchor="multiple-parents"><name>Multiple Parents</name>
      <t>A JAC event MAY declare multiple parents.</t>
      <t>Multiple parents do not imply equal weight, joint sufficiency, complete input coverage, or causal exhaustiveness.</t>
      <t>JAC-2 does not define a parent ordering.</t>
      </section>
      <section anchor="roots"><name>Roots</name>
      <t>An event with an empty <tt>parents</tt> array is a declared JAC root.</t>
      <t>Root status is local to the declared JAC dependency structure.</t>
      <t>A root declaration MUST NOT be interpreted as proof that no earlier real-world event, input, instruction, or cause existed.</t>
      </section>
      <section anchor="acyclicity"><name>Acyclicity</name>
      <t>The baseline <tt>declared-dependency</tt> relation is acyclic.</t>
      <t>A resolved dependency fragment containing a directed cycle under <tt>declared-dependency</tt> is invalid under JAC-2.</t>
      <t>Cycle detection operates on logical JEP Event Identity nodes and digest-record digest identities.</t>
      <t>An unresolved parent cannot by itself prove that a cycle exists or does not exist outside the observed fragment.</t>
      </section>
      <section anchor="partial-observation"><name>Partial Observation</name>
      <t>JAC-2 uses an open-world, partial-fragment default.</t>
      <t>A valid observed fragment does not imply that:</t>
      <ul spacing="normal">
        <li>all parents were disclosed;</li>
        <li>all relevant events were observed;</li>
        <li>all real-world causes were represented;</li>
        <li>the fragment is a complete chain;</li>
        <li>the declared root is a real-world first cause.</li>
      </ul>
      <t>A profile claiming complete-log or closed-world semantics MUST define those assumptions explicitly.</t>
      </section>
      <section anchor="unresolved-parents"><name>Unresolved Parents</name>
      <t>An unresolved parent reference MAY remain structurally valid.</t>
      <t>Whether unresolved parent resolution is required depends on the requested validation context.</t>
      <t>A verifier MUST NOT convert an unresolved parent into a fabricated success, missing-parent fault, or proof of non-existence.</t>
      </section>
    </section>
    <section anchor="receipt-deps"><name>Receipt and External Record Dependencies</name>
      <t>A JAC <tt>digest-record</tt> parent is identified by digest.</t>
      <t>JAC verifies only the properties requested by the JAC validation context.</t>
      <t>Digest equality establishes integrity identity for the referenced record; it does not establish the truth or sufficiency of that record.</t>
      <t>If a referenced record declares another profile, such as JEP Receipt Profile, that profile's validity MUST be reported separately from JAC status.</t>
      <t>JAC MUST NOT convert Receipt Profile validity into causal validity, authorization validity, or completeness.</t>
    </section>
    <section anchor="validation"><name>Validation Model</name>
      <section anchor="validation-layers"><name>Layer Separation</name>
      <t>A JAC validation result separates:</t>
      <ul spacing="normal">
        <li>underlying JEP validation status;</li>
        <li>JAC profile checks;</li>
        <li>JAC overall status;</li>
        <li>fragment completeness statement.</li>
      </ul>
      <t>JAC MUST NOT overwrite the JEP validation result.</t>
      </section>
      <section anchor="validation-contexts"><name>Validation Contexts</name>
      <t>JAC-2 defines two profile validation contexts:</t>
      <ul spacing="normal">
        <li><tt>link</tt></li>
        <li><tt>fragment</tt></li>
      </ul>
      <t><tt>link</tt> validates one event's dependency extension and parent-reference structure. Parent resolution is not required unless exact artifact integrity is explicitly requested.</t>
      <t><tt>fragment</tt> validates an observed multi-node dependency fragment. It requires cycle analysis over all resolved in-scope nodes and evaluates parent integrity according to the requested fragment policy.</t>
      <t>A JEP implementation MAY invoke JAC <tt>fragment</tt> validation from JEP <tt>chain</tt> mode.</t>
      <t>JAC context names are profile-local and are not new JEP validation modes.</t>
      </section>
      <section anchor="validation-checks"><name>JAC Checks</name>
      <t>The initial JAC-2 check identifiers are:</t>
      <ul spacing="normal">
        <li><tt>https://humanjudgment.org/jep/profiles/jac/2#profile-binding</tt></li>
        <li><tt>https://humanjudgment.org/jep/profiles/jac/2#dependency-extension</tt></li>
        <li><tt>https://humanjudgment.org/jep/profiles/jac/2#parent-reference</tt></li>
        <li><tt>https://humanjudgment.org/jep/profiles/jac/2#parent-resolution</tt></li>
        <li><tt>https://humanjudgment.org/jep/profiles/jac/2#parent-integrity</tt></li>
        <li><tt>https://humanjudgment.org/jep/profiles/jac/2#duplicate-parent</tt></li>
        <li><tt>https://humanjudgment.org/jep/profiles/jac/2#self-dependency</tt></li>
        <li><tt>https://humanjudgment.org/jep/profiles/jac/2#cycle</tt></li>
        <li><tt>https://humanjudgment.org/jep/profiles/jac/2#fragment-consistency</tt></li>
        <li><tt>https://humanjudgment.org/jep/profiles/jac/2#completeness-assumption</tt></li>
      </ul>
      <t>Check statuses use the JEP conformance vocabulary:</t>
      <ul spacing="normal">
        <li><tt>pass</tt></li>
        <li><tt>fail</tt></li>
        <li><tt>not_checked</tt></li>
        <li><tt>not_applicable</tt></li>
        <li><tt>unsupported</tt></li>
        <li><tt>indeterminate</tt></li>
      </ul>
      <t>A verifier MUST NOT report an unperformed JAC check as <tt>pass</tt>.</t>
      </section>
      <section anchor="link-checks"><name>Required Link Checks</name>
      <t>For <tt>link</tt> context, the required JAC checks are:</t>
      <ul spacing="normal">
        <li><tt>profile-binding</tt></li>
        <li><tt>dependency-extension</tt></li>
        <li><tt>parent-reference</tt></li>
        <li><tt>duplicate-parent</tt></li>
        <li><tt>self-dependency</tt></li>
      </ul>
      <t><tt>parent-resolution</tt> and <tt>parent-integrity</tt> are required only when the requested link-validation policy requires parent material or exact-artifact checking.</t>
      <t><tt>cycle</tt> is not required for isolated link validation.</t>
      </section>
      <section anchor="fragment-checks"><name>Required Fragment Checks</name>
      <t>For <tt>fragment</tt> context, the required checks are:</t>
      <ul spacing="normal">
        <li>all required <tt>link</tt> checks for every in-scope JAC event;</li>
        <li><tt>parent-resolution</tt> for every parent that the requested fragment policy says must be resolved;</li>
        <li><tt>parent-integrity</tt> for every resolved parent carrying an exact-artifact pin or digest-record reference;</li>
        <li><tt>cycle</tt>;</li>
        <li><tt>fragment-consistency</tt>;</li>
        <li><tt>completeness-assumption</tt>.</li>
      </ul>
      <t>If a required parent cannot be resolved and no required check has failed, JAC overall status is <tt>indeterminate</tt>.</t>
      <t><tt>fragment-consistency</tt> passes only when each included JEP Event Identity maps to one non-conflicting unsigned event content, all resolved parent identities are consistent with their references, and multiple artifacts for one Event Identity are treated as one logical node.</t>
      <t><tt>completeness-assumption</tt> passes when the verifier reports <tt>partial</tt>, or when an explicitly selected completeness profile authorizes <tt>complete-under-profile</tt> and all checks required by that profile pass.</t>
      </section>
      <section anchor="completeness"><name>Completeness Statement</name>
      <t>A JAC result MUST report one of:</t>
      <ul spacing="normal">
        <li><tt>partial</tt></li>
        <li><tt>complete-under-profile</tt></li>
      </ul>
      <t>The default is <tt>partial</tt>.</t>
      <t><tt>complete-under-profile</tt> MUST NOT be reported unless an explicitly selected profile defines the closed-world or complete-log assumptions and all required checks for those assumptions passed.</t>
      <t>JAC-2 alone never establishes real-world causal completeness.</t>
      </section>
      <section anchor="overall-status"><name>JAC Overall Status</name>
      <t>The JAC overall status is one of:</t>
      <ul spacing="normal">
        <li><tt>valid</tt></li>
        <li><tt>invalid</tt></li>
        <li><tt>indeterminate</tt></li>
      </ul>
      <t>For the requested JAC context:</t>
      <ul spacing="normal">
        <li><tt>invalid</tt> means the underlying required JEP validation is invalid or at least one required JAC check failed;</li>
        <li><tt>indeterminate</tt> means no required check failed but the underlying required JEP validation is indeterminate or at least one required JAC check is unsupported, not checked, or indeterminate;</li>
        <li><tt>valid</tt> means the underlying required JEP validation is valid and every required JAC check passed or was not applicable.</li>
      </ul>
      <t><tt>valid</tt> does not mean causally true or complete.</t>
      </section>
      <section anchor="validation-procedure"><name>Validation Procedure</name>
      <t>A fragment validator SHOULD:</t>
      <ul spacing="normal">
        <li>validate each in-scope JEP event under the requested JEP mode and profiles;</li>
        <li>process the critical JAC dependency extension;</li>
        <li>verify the JAC profile identifier;</li>
        <li>parse and validate all Parent Links;</li>
        <li>reject duplicate or self-dependencies;</li>
        <li>resolve required parent objects;</li>
        <li>verify Event Identity and optional Event Hash pins for JEP-event parents;</li>
        <li>verify digest integrity for available digest-record parents;</li>
        <li>construct the logical dependency graph;</li>
        <li>detect cycles over the resolved in-scope fragment;</li>
        <li>evaluate fragment consistency;</li>
        <li>evaluate the declared completeness assumption;</li>
        <li>return JEP results, JAC checks, JAC overall status, and completeness separately.</li>
      </ul>
      </section>
    </section>
    <section anchor="validation-example"><name>Validation Result Example</name>
      <sourcecode type="json"><![CDATA[
{
  "jac_status": "valid",
  "profile": "https://humanjudgment.org/jep/profiles/jac/2",
  "context": "fragment",
  "completeness": "partial",
  "subject_event": {
    "who": "did:example:agent-b",
    "id": "urn:uuid:018f4f8d-0000-7000-8000-000000000002"
  },
  "checks": {
    "https://humanjudgment.org/jep/profiles/jac/2#profile-binding": "pass",
    "https://humanjudgment.org/jep/profiles/jac/2#dependency-extension": "pass",
    "https://humanjudgment.org/jep/profiles/jac/2#parent-reference": "pass",
    "https://humanjudgment.org/jep/profiles/jac/2#parent-resolution": "pass",
    "https://humanjudgment.org/jep/profiles/jac/2#parent-integrity": "pass",
    "https://humanjudgment.org/jep/profiles/jac/2#duplicate-parent": "pass",
    "https://humanjudgment.org/jep/profiles/jac/2#self-dependency": "pass",
    "https://humanjudgment.org/jep/profiles/jac/2#cycle": "pass",
    "https://humanjudgment.org/jep/profiles/jac/2#fragment-consistency": "pass",
    "https://humanjudgment.org/jep/profiles/jac/2#completeness-assumption": "pass"
  },
  "warnings": [
    "fragment-is-partial"
  ],
  "errors": []
}
]]></sourcecode>
      <t>The result does not assert factual causality or complete history.</t>
    </section>
    <section anchor="verification-events"><name>Verification Events</name>
      <t>A JEP V event MAY record a JAC evaluation.</t>
      <t>The V event MUST satisfy JEP-Core V requirements.</t>
      <t>JAC-2 defines the following provisional profile-specific verification scopes:</t>
      <ul spacing="normal">
        <li><tt>https://humanjudgment.org/jep/profiles/jac/2#link-validation</tt></li>
        <li><tt>https://humanjudgment.org/jep/profiles/jac/2#fragment-validation</tt></li>
        <li><tt>https://humanjudgment.org/jep/profiles/jac/2#parent-integrity</tt></li>
        <li><tt>https://humanjudgment.org/jep/profiles/jac/2#cycle-check</tt></li>
      </ul>
      <t>A V event MUST identify its target through JEP <tt>ref</tt>.</t>
      <t><tt>what.result</tt> records the semantic result of the declared V scope. It MUST NOT be confused with the independent per-check status vocabulary used by a JAC validator.</t>
      <t>A V event MUST NOT imply chain completeness or causality beyond its declared scope.</t>
    </section>
    <section anchor="delegation-termination"><name>Interaction with Delegation and Termination</name>
      <t>JAC dependency edges do not create authorization.</t>
      <t>A D event that also carries JAC dependency links remains a JEP Delegation statement. Whether the delegation is authorized belongs to the applicable delegation or mandate profile.</t>
      <t>A T event that also carries JAC dependency links remains a JEP Termination statement.</t>
      <t>JAC-2 does not define automatic termination cascade.</t>
      <t>If a chain or domain profile requires a parent termination to change child eligibility, that profile MUST define:</t>
      <ul spacing="normal">
        <li>which edge relations propagate the effect;</li>
        <li>which termination scopes are relevant;</li>
        <li>whether propagation is prospective or retrospective;</li>
        <li>how unresolved descendants are handled;</li>
        <li>how conflicting termination declarations are handled.</li>
      </ul>
      <t>The existence of a JAC edge alone MUST NOT be treated as a termination propagation rule.</t>
    </section>
    <section anchor="domain-semantics"><name>Optional Domain Semantics</name>
      <t>Earlier JAC revisions defined extension identifiers for state, assignment, handoff, results, capability claims, input/output references, and declared breaks.</t>
      <t>JAC-2 removes those items from the narrow waist.</t>
      <t>Such semantics MAY be defined by separate profiles or domain specifications, but they MUST NOT be inferred from the baseline <tt>declared-dependency</tt> relation.</t>
      <t>A domain profile defining additional dependency relations or adjacent metadata SHOULD specify:</t>
      <ul spacing="normal">
        <li>identifier namespace;</li>
        <li>data model;</li>
        <li>relation semantics;</li>
        <li>graph-processing rules;</li>
        <li>conflict handling;</li>
        <li>validation checks;</li>
        <li>security considerations;</li>
        <li>privacy considerations;</li>
        <li>non-inference boundaries.</li>
      </ul>
    </section>
    <section anchor="conformance"><name>Conformance</name>
      <section anchor="conf-producer"><name>JAC-2 Producer</name>
      <t>A conforming JAC-2 Producer MUST:</t>
      <ul spacing="normal">
        <li>produce a JEP event conforming to the applicable JEP Producer requirements;</li>
        <li>include the JAC dependency extension;</li>
        <li>list it in <tt>ext_crit</tt>;</li>
        <li>use the JAC-2 profile identifier;</li>
        <li>use only defined Parent Reference forms;</li>
        <li>use Event Identity for logical JEP-event parents;</li>
        <li>use Event Hash only as an optional exact-artifact pin;</li>
        <li>reject self-dependency before signing;</li>
        <li>avoid duplicate parent links.</li>
      </ul>
      </section>
      <section anchor="conf-link"><name>JAC-2 Link Verifier</name>
      <t>A conforming JAC-2 Link Verifier MUST:</t>
      <ul spacing="normal">
        <li>perform or consume an actual JEP validation result;</li>
        <li>process the critical dependency extension;</li>
        <li>perform all required <tt>link</tt> checks;</li>
        <li>preserve independent check statuses;</li>
        <li>distinguish Event Identity from Event Hash;</li>
        <li>return <tt>indeterminate</tt> rather than success when a required check cannot be completed.</li>
      </ul>
      </section>
      <section anchor="conf-fragment"><name>JAC-2 Fragment Verifier</name>
      <t>A conforming JAC-2 Fragment Verifier MUST additionally:</t>
      <ul spacing="normal">
        <li>build graph nodes from logical Event Identity and digest-record identity;</li>
        <li>resolve parents required by the selected fragment policy;</li>
        <li>verify required exact-artifact and digest pins;</li>
        <li>detect baseline <tt>declared-dependency</tt> cycles;</li>
        <li>report fragment completeness explicitly;</li>
        <li>avoid inferring omitted parents or real-world causes from a valid fragment.</li>
      </ul>
      </section>
    </section>
    <section anchor="security"><name>Security Considerations</name>
      <t>A valid JAC chain result does not establish factual causality.</t>
      <t>Implementations MUST consider:</t>
      <ul spacing="normal">
        <li>Event Identity/Event Hash confusion;</li>
        <li>duplicate or conflicting Event Identity reuse;</li>
        <li>self-dependency;</li>
        <li>dependency cycles;</li>
        <li>forged or substituted digest records;</li>
        <li>unresolved parents;</li>
        <li>omitted parents;</li>
        <li>selective export of a misleading fragment;</li>
        <li>profile confusion;</li>
        <li>unknown critical extensions;</li>
        <li>false complete-log assumptions;</li>
        <li>semantic inflation from dependency to causality;</li>
        <li>authorization inference from dependency;</li>
        <li>termination-cascade inference from dependency.</li>
      </ul>
      <t>Exact artifact pins MUST be verified when required by the validation context.</t>
      <t>A verifier MUST NOT treat a URI retrieval location as integrity identity.</t>
      <t>A verifier MUST NOT convert missing or unavailable parent material into proof that no parent exists.</t>
    </section>
    <section anchor="privacy"><name>Privacy Considerations</name>
      <t>Dependency graphs can reveal:</t>
      <ul spacing="normal">
        <li>actor relationships;</li>
        <li>organizational structure;</li>
        <li>workflow topology;</li>
        <li>task dependencies;</li>
        <li>receipt relationships;</li>
        <li>tool or resource usage;</li>
        <li>timing and coordination patterns;</li>
        <li>hidden participants through correlation.</li>
      </ul>
      <t>Implementations SHOULD minimize stable identifiers when they are not needed for interoperability.</t>
      <t>Digest references can still enable correlation and dictionary attacks.</t>
      <t>Partial exports MAY be used to reduce disclosure, but partial exports MUST NOT be presented as complete histories unless an applicable completeness profile supports that claim.</t>
    </section>
    <section anchor="non-inference"><name>Non-Inference Boundary</name>
      <t>JAC-2 records declared dependency structure.</t>
      <t>A successful JAC validation MUST NOT be presented, by itself, as proof:</t>
      <ul spacing="normal">
        <li>that a declared dependency is a real-world cause;</li>
        <li>that all causes or parents were disclosed;</li>
        <li>that the fragment is complete;</li>
        <li>that a parent authorized a child;</li>
        <li>that a child correctly followed a parent;</li>
        <li>that a delegation chain is valid;</li>
        <li>that termination propagated;</li>
        <li>that an assignment or handoff was valid;</li>
        <li>that a result was correct;</li>
        <li>that responsibility, fault, or liability belongs to any actor;</li>
        <li>that a legal or regulatory requirement was satisfied.</li>
      </ul>
      <t>External profiles MAY use JAC evidence when making such determinations, but those conclusions remain outside JAC-2.</t>
    </section>
    <section anchor="iana"><name>IANA Considerations</name>
      <t>This document requests no IANA actions.</t>
      <t>The JAC-2 profile identifier, dependency-extension identifier, JAC check identifiers, and JAC verification-scope identifiers are publisher-controlled HTTPS URI identifiers.</t>
      <t>Future specifications MAY define registries if deployment experience shows that a stable shared registry is needed.</t>
    </section>
    <section anchor="changes"><name>Changes from -02</name>
      <t>Major changes from <tt>draft-wang-jac-02</tt>:</t>
      <ul spacing="normal">
        <li>aligned JAC with JEP-Core 0.7, JEP Profiles-01, and JEP Conformance-01;</li>
        <li>removed the HJS technical dependency from JAC-Core and aligned optional receipt references with JEP Receipt Profile;</li>
        <li>introduced JAC-2 as an incompatible profile revision;</li>
        <li>replaced <tt>https://jac.org/chain</tt> with publisher-controlled JEP namespace identifiers;</li>
        <li>replaced the single <tt>based_on</tt> field with a <tt>parents</tt> array supporting zero or more parent dependencies;</li>
        <li>changed logical JEP parent identity from Event Hash to Event Identity;</li>
        <li>retained Event Hash only as optional exact signed-artifact pinning;</li>
        <li>introduced explicit <tt>jep-event</tt> and <tt>digest-record</tt> Parent Reference forms;</li>
        <li>defined empty <tt>parents</tt> as a declared JAC root without claiming a real-world first cause;</li>
        <li>prohibited duplicate parent links and self-dependency;</li>
        <li>defined baseline dependency direction and acyclicity;</li>
        <li>defined open-world partial-fragment semantics;</li>
        <li>defined unresolved-parent behavior;</li>
        <li>defined <tt>link</tt> and <tt>fragment</tt> validation contexts without creating new JEP validation modes;</li>
        <li>defined independent JAC checks and <tt>valid</tt> / <tt>invalid</tt> / <tt>indeterminate</tt> result semantics;</li>
        <li>added explicit <tt>partial</tt> versus <tt>complete-under-profile</tt> completeness reporting;</li>
        <li>removed state, assignment, handoff, result, capability, input/output, and declared-break extensions from the JAC narrow waist;</li>
        <li>removed nonce and legacy replay assumptions;</li>
        <li>removed examples that used pre-0.7 JEP field semantics;</li>
        <li>clarified that JAC edges do not create authorization or termination cascade;</li>
        <li>changed IANA language to request no action.</li>
      </ul>
    </section>
  </middle>
  <back>
    <references>
      <name>References</name>
      <references>
        <name>Normative References</name>
        <reference anchor="JEP">
          <front><title>Judgment Event Protocol (JEP)</title><author initials="Y." surname="Wang" fullname="Yuqiang Wang"/><date year="2026" month="September" day="26"/></front>
          <seriesInfo name="Internet-Draft" value="draft-wang-jep-judgment-event-protocol-07"/>
        </reference>
        <reference anchor="JEP-PROFILES">
          <front><title>JEP Profiles and Interoperability</title><author initials="Y." surname="Wang" fullname="Yuqiang Wang"/><date year="2026" month="September" day="26"/></front>
          <seriesInfo name="Internet-Draft" value="draft-wang-jep-profiles-01"/>
        </reference>
        <reference anchor="JEP-CONFORMANCE">
          <front><title>JEP Conformance and Test Suite</title><author initials="Y." surname="Wang" fullname="Yuqiang Wang"/><date year="2026" month="September" day="26"/></front>
          <seriesInfo name="Internet-Draft" value="draft-wang-jep-conformance-01"/>
        </reference>
        <reference anchor="JEP-RECEIPT">
          <front><title>JEP Receipt Profile: Verifiable Behavior and Evidence Receipts</title><author initials="Y." surname="Wang" fullname="Yuqiang Wang"/><date year="2026" month="September" day="26"/></front>
          <seriesInfo name="Internet-Draft" value="draft-wang-jep-receipt-profile-00"/>
        </reference>
        <reference anchor="RFC2119">
          <front><title>Key words for use in RFCs to Indicate Requirement Levels</title><author initials="S." surname="Bradner"/><date year="1997" month="March"/></front>
          <seriesInfo name="BCP" value="14"/><seriesInfo name="RFC" value="2119"/>
        </reference>
        <reference anchor="RFC8174">
          <front><title>Ambiguity of Uppercase vs Lowercase in RFC 2119 Key Words</title><author initials="B." surname="Leiba"/><date year="2017" month="May"/></front>
          <seriesInfo name="BCP" value="14"/><seriesInfo name="RFC" value="8174"/>
        </reference>
      </references>
    </references>
  </back>
</rfc>
