OntoClean meta-property markup — conditional, gated on the canonical-check CI meta-shape
Context and Problem Statement
ODR-0031 §R7(a) left one item as a held 3–3 split: should OPDA mark up the OntoClean meta-properties (rigidity ±R, identity ±I, dependence ±D, unity ±U) as a structured, annotation-graph-only owl:AnnotationProperty vocabulary per type? ADR-0045 scoped it out and routed it to a follow-up Reduced Council. Council session-042 (Queen Kendall; DA Baker — withdrawn; Guarino, Allemang) resolved it as conditional adoption. This ADR is its engineering realisation — and it is conditional: nothing is emitted unless the operator ratifies the gate.
The deliberation collapsed the 3–3 onto a single condition once a corpus fact was verified: the OntoClean signature already ships per-category in ADR-0045’s opda:UFOCategoryScheme skos:definitions (RelatorCategory ”(+R, +I, +D)”, SubstanceKindCategory ”(+R, +O)”, RoleCategory/RoleMixinCategory ”(−R, +D)” — 4 of 9; prose, per-category, no unity). So the question was never “prose vs structure” — it was “also structure it per-type, for a machine.” And the Working-Ontologist / DCMI answer is identical: you mark up what a machine reads. Today no CI gate, SPARQL query, or endpoint reads per-type ±R/±I/±D/±U (verified: eight gates, none OntoClean) — so absent a consumer the tags are decoration. Shipping the canonical-check gate is the act that creates the consumer.
Decision Drivers
- The gate is the condition, not an enhancement (all four voices, session-042). Ungated tags are latent decoration that no consumer exercises — the metadata FIBO/DCMI reject and the over-modelling SWWO Ch. 12 forbids.
- Atomicity. The tags and the gate that consumes them ship in the same commit or neither — the session-042 “gate + tags adopt together” disposition (echoing session-041’s “relocate AND gate, atomically”).
- Soundness vs over-modelling. A partial vector false-greens a completeness check (Guarino); a blanket vector tags ~30 classes whose category was never in question (Allemang). The scope that is both sound and disciplined is the subsumption lattice the check ranges over + its contrast set (Kendall).
- Truthfulness of the value set. ±R/±I moved OPDA bytes (the ODR-0011 §8a cascade is stated in ±R/±I terms); ±D is largely carried by the Relator/
foundstopology; ±U has adjudicated nothing — asserting it per type would claim a judgement the process never made (Baker + Allemang). So ±R/±I floor, ±D where a Relator decision turned on it, never ±U. - Quarantine intact. The gate is the ODR-0031 R3 tag-guard pattern: TBox-only, validates the meta-level, never instance-keyed — so it cannot re-fire the ODR-0030 Rule 1 quarantine trigger.
Considered Options
- Option A (chosen) — Conditional, gated, scoped markup. Emit the scoped ±R/±I (+conditional ±D) per-type
owl:AnnotationPropertytags and the TBox OntoClean meta-shape that consumes them, atomically; a seventh CI gate; a byte-identity re-pin. - Option B — Blanket full-quartet on every class. Rejected (session-042 Q2): over-models (~30 unread vectors), and ±U over-claims a judgement never made.
- Option C — Prose-only / reject. The no-gate fallback: if the operator declines the gate, keep the per-category
skos:definitionsignatures + the ODRs as the record. This is the disposition by default until the gate is ratified. - Option D — Extend ADR-0045. Rejected (Kendall + Allemang): ADR-0045 is a clean landed record with a byte-identity re-pin; a fresh concern belongs in a new ADR (this one).
Decision Outcome
Chosen option: “Option A — conditional, gated, scoped markup”, because session-042 converged that the meta-property markup earns its place only when a machine reads it, and the only honest way to ship the tags is to ship — in the same change-set — the gate that consumes them. If the operator does not ratify the gate, Option C (prose-only) stands and nothing is emitted.
The change-set (on ratification):
| # | Change | Target |
|---|---|---|
| 1 | Emit opda:ontoCleanRigidity (+ opda:ontoCleanIdentity; opda:ontoCleanDependence where a Relator decision turned on it) as owl:AnnotationProperty, SKOS-sh:in-governed value sets (e.g. rigidity ∈ {rigid, anti-rigid, semi-rigid, non-rigid}; identity ∈ {supplies-IC, carries-IC, no-own-IC}), per type, in opda-annotations.ttl. Never opda:ontoCleanUnity. | emitters/ufo_categories.py (the annotation-graph emission point) |
| 2 | Scope the tags to the subsumption lattice the check ranges over + its contrast set (the tenureKind/VouchEvidence/RiskAssessment/evidence family + the Kinds they sit under), not blanket-every-class, not only the contested leaves; omit a tag where the value is already inherited category → scheme → signature | same |
| 3 | Emit the TBox OntoClean meta-shape — the canonical check “every −R type that is nonetheless rdfs:subClassOf something” + IC-incompatible subsumption — as a sh:Violation meta-shape (the ODR-0031 R3 tag-guard pattern: sh:targetSubjectsOf/SPARQL over the TBox, never sh:targetClass/sh:path on instance data), with opda:metaShapeJustification | emitters/shapes.py |
| 4 | Add a seventh CI check running the meta-shape over the class+annotation graph (the editorial pass; never the instance-validation union) | ci/three_graph_test.py (or a sibling) + tests |
| 5 | Re-pin byte-identity; all gates green | corpus re-emit |
| Atomic | (1)+(3) ship in the same commit or neither — tags without the consuming gate are decoration | — |
Consequences
- Good, because OPDA’s load-bearing OntoClean judgement becomes auditable and re-derivable — the canonical self-consistency check (a query no current artefact can run) ships as a green/red gate, and the per-type premise that produced each subclass-vs-facet verdict becomes queryable data, not unfalsifiable prose.
- Good, because it is separability insurance (Guarino): the OntoClean reasoning survives even if the UFO vocabulary is ever retired (the Devil’s Advocate’s own held Option-D exit), as structured data rather than evaporating prose.
- Good, because the quarantine holds:
owl:AnnotationProperty+ TBox-only meta-shape + the (existing) sixth gate mean nothing UFO/OntoClean-shaped reaches the reasoner or the instance validator. - Bad (accepted), because it is real build surface (a seventh gate + per-type tags) for an audit of a small, flat lattice; justified only by the gate that exercises it — which is why the atomic rule is load-bearing.
- Neutral, because scope is the one tension session-042 left bounded (Guarino full-vector-all-40 vs Allemang ±R/±I-<10): this ADR fixes it at the checked lattice + contrast set, ±R/±I floor, to be finalised against the actual subsumption edges at implementation.
Confirmation
- The seventh CI check runs the canonical OntoClean meta-shape over the TBox and is green; the existing six three-graph gates + byte-identity stay green.
- The
opda:ontoCleanRigidity/Identity/Dependencetags resolve only inopda-annotations.ttl(owl:AnnotationProperty; never in the classes/shapes graphs; never instance-keyed); noopda:ontoCleanUnityis emitted. - The canonical query “
SELECT ?sub ?super WHERE { ?sub rdfs:subClassOf ?super . ?super opda:ontoCleanRigidity 'anti-rigid' }” (an anti-rigid type subsuming anything) returns empty against the corpus. Its ±I sibling — the IC-incompatibility violation form “SELECT ?sub ?super WHERE { ?sub opda:ontoCleanIdentity 'supplies-IC' . ?sub rdfs:subClassOf ?super . ?super opda:ontoCleanIdentity 'supplies-IC' }” (a type supplying its own IC subsuming another own-IC supplier) likewise returns empty (check 9; see Amendments 2026-06-17). - Atomic gate-or-nothing: CI fails if the tags are present without the consuming meta-shape. Status
proposed; the operator ratifies adoption and decides whether to ship the gate — absent that, Option C (prose-only) stands.
More Information
- Council provenance: session-042 (Reduced Council; the 3–3 convergence onto the gate condition; Baker WITHDRAWN; the verified “signature already ships per-category” + “no consumer today” findings).
- Resolves: ODR-0031 §R7(a) (the held 3–3, now conditional adoption).
- Depends on: ADR-0045 (the
UFOCategorySchemeanchor + the sixth-gate / R3 tag-guard pattern this gate reuses); ODR-0027 (the OntoClean cascade the meta-properties are the input to); ODR-0011 §8a; ODR-0004 §3a. - External: Guarino & Welty, “An Overview of OntoClean” (Handbook on Ontologies 2nd ed., 2009, §3); Allemang, Hendler & Gandon, Semantic Web for the Working Ontologist 3rd ed. (2020), Ch. 12–13; DCMI Abstract Model + the dumb-down/one-to-one principles; W3C SHACL §4.6.
Vote and Dissent
Inherits the session-042 verdict — converged conditional adoption (Q1 4–0 gated · Q2 REVISE 4–0 scoped · Q3 4–0 gate-as-precondition · Q4 4–0 conditional). DA Baker WITHDRAWN on the gate condition (his withdrawal condition — “the canonical check ships as a running CI gate” — is exactly this ADR’s atomic rule). Held-as-live dissent (Baker): if the tags ever ship without the running gate (markup-as-decoration), revert to REJECT (DCMI one-to-one + dumb-down). Re-open / REJECT-path trigger: if the operator declines the gate, the disposition is REJECT-for-now — the per-category skos:definition signatures + the ODRs are the record — re-opening when a named consumer (a CI gate, an external reuse partner, or a second OntoClean check) needs the per-type vector as queryable data. Scope bound: Guarino (full vector / all ~40) vs Allemang (±R/±I / <10) — fixed here at the checked lattice + contrast set, ±R/±I floor.
Amendments
- 2026-06-16 — RATIFIED
proposed→accepted(operator). The operator ratified the gate. All five change-set items implemented and green: (1)opda:ontoCleanRigidity/opda:ontoCleanIdentity/opda:ontoCleanDependencedeclaredowl:AnnotationPropertyinopda-annotations.ttl; per-type tags emitted for 8 scoped types (Relator, Transaction, Proprietorship, Role, Proprietor, RoleMixin, Buyer, Seller); (2) scope fixed at subsumption lattice + contrast set, ±R/±I floor, ±D for Relator family only, noopda:ontoCleanUnity; (3) TBox OntoClean meta-shape (OntoCleanAntiRigidSubclassing_MetaShape,sh:targetSubjectsOf opda:ontoCleanRigidity, SPARQL over TBox only, ODR-0031 R3 tag-guard pattern) emitted inopda-shapes.ttl; (4) check 8 added toci/three_graph_test.pyrunning the meta-shape over class+annotation graph only (never the instance-validation union), 7 new tests; (5) byte-identity re-pinned, all 8 three-graph CI gates green. Implementation note (canonical query): the ADR-0046 confirmation querySELECT ?sub ?super WHERE { ?sub rdfs:subClassOf ?super . ?super opda:ontoCleanRigidity "anti-rigid" }returns 3 results in the corpus (Buyer/Seller→RoleMixin, Proprietor→Role) — these are VALID anti-rigid-subclasses-anti-rigid cases, not violations. The VIOLATION form of the query (adding?sub opda:ontoCleanRigidity "rigid") returns EMPTY. Check 8 implements the violation form; the CI gate is green. Baker’s atomicity condition is met — gate + tags ship together. - 2026-06-16 — Meta-shape direction corrected (operator pre-commit verification). The
OntoCleanAntiRigidSubclassing_MetaShapeSPARQL +sh:message+ justification as first emitted checkedanti-rigid ⊑ rigid(the valid direction —Student ⊑ Person), inconsistent with check 8 and with OntoClean. Corrected to the violation formrigid ⊑ anti-rigid— an anti-rigid type cannot subsume a rigid one (Person ⊑ Studentforbidden; Guarino & Welty 2009 §3) — so the shipped meta-shape and the check-8 CI gate now enforce the identical, correct invariant. Both empty against the corpus; gates green; byte-identity re-pinned. - 2026-06-17 — ±I IC-incompatibility limb implemented (operator). Change-set item 3 named “IC-incompatible subsumption” as part of the consuming TBox meta-shape; the original implementation shipped only the ±R rigidity limb (
OntoCleanAntiRigidSubclassing_MetaShape+ check 8). This amendment adds the ±I identity-criterion sibling, giving theopda:ontoCleanIdentitytags their own consuming TBox meta-shape + CI gate, wired exactly like the ±R limb: (a) builderbuild_ontoclean_identity_tbox_meta_shapeinemitters/shapes.pyemitsOntoCleanIncompatibleIdentitySubclassing_MetaShape(sh:targetSubjectsOf opda:ontoCleanIdentity— TBox/tag-keyed, ODR-0031 R3 tag-guard, NEVER instance-keyed;sh:Violation;opda:metaShapeJustification); (b) check 9check_ontoclean_identity_tboxinci/three_graph_test.pyruns it over the class+annotation graph only (the editorial pass — never the instance-validation union). Incompatibility predicate (the correct OntoClean direction): a type that supplies its own identity criterion (opda:ontoCleanIdentity "supplies-IC") MUST NOT berdfs:subClassOfanother"supplies-IC"type — two independent own-identity suppliers carry distinct, incompatible ICs, so the subsumption would force the subclass to bear two rival own-ICs on the same instances (Guarino & Welty 2009 §3: a sortal cannot subsume a different sortal). Thecarries-IC ⊑ supplies-ICdirection (the realTransaction/Proprietorship ⊑ Relatoredges — the subclass inherits the super’s supplied IC) andno-own-IC ⊑ *(Roles/RoleMixins borrowing identity from a bearer —Proprietor ⊑ Role,Buyer/Seller ⊑ RoleMixin) are both VALID. The violation formSELECT ?sub ?super WHERE { ?sub opda:ontoCleanIdentity "supplies-IC" . ?sub rdfs:subClassOf ?super . ?super opda:ontoCleanIdentity "supplies-IC" }returns EMPTY against the corpus (Relatoris the onlysupplies-ICtype and it subclasses nothing tagged). Non-vacuity is proven by a positive control: unit testtest_ontoclean_identity_supplies_subclasses_supplies_failsconstructs a syntheticsupplies-IC ⊑ supplies-ICedge and asserts the gate FLAGS it; three negative-control tests assert the gate PASSES the validcarries-IC ⊑ supplies-IC,no-own-IC ⊑ no-own-IC, andno-own-IC ⊑ supplies-ICdirections (mirroring the ±R limb’s tests). This mirrors the ±R limb’s solerigid ⊑ anti-rigidviolating pairing with the solesupplies-IC ⊑ supplies-ICone. Baker’s held “no-decoration” dissent on the ±I tags is thereby addressed — theopda:ontoCleanIdentityper-type tags now have a running consumer (the atomicity condition that the gate, not the tag, is the act that earns the markup). No generator-version bump (the ±R limb likewise shipped atopda-gen 1.0.1without bumping — the convention is no bump for an added OntoClean meta-shape). Corpus delta:opda-shapes.ttl+1 node shape (365 → 366); all nine three-graph CI gates green; byte-identity re-pinned;make ci, baspi5 round-trip (27 passed), andemit-exemplar-reportsbyte-identity all green.
Comments
Loading comments…
Sign in to post a comment