accepted

    OntoClean meta-property markup — conditional, gated on the canonical-check CI meta-shape

    Context and Problem Statement

    ODR-0031 §R7(a) left one item as a held 3–3 split: should OPDA mark up the OntoClean meta-properties (rigidity ±R, identity ±I, dependence ±D, unity ±U) as a structured, annotation-graph-only owl:AnnotationProperty vocabulary per type? ADR-0045 scoped it out and routed it to a follow-up Reduced Council. Council session-042 (Queen Kendall; DA Baker — withdrawn; Guarino, Allemang) resolved it as conditional adoption. This ADR is its engineering realisation — and it is conditional: nothing is emitted unless the operator ratifies the gate.

    The deliberation collapsed the 3–3 onto a single condition once a corpus fact was verified: the OntoClean signature already ships per-category in ADR-0045’s opda:UFOCategoryScheme skos:definitions (RelatorCategory ”(+R, +I, +D)”, SubstanceKindCategory ”(+R, +O)”, RoleCategory/RoleMixinCategory ”(−R, +D)” — 4 of 9; prose, per-category, no unity). So the question was never “prose vs structure” — it was “also structure it per-type, for a machine.” And the Working-Ontologist / DCMI answer is identical: you mark up what a machine reads. Today no CI gate, SPARQL query, or endpoint reads per-type ±R/±I/±D/±U (verified: eight gates, none OntoClean) — so absent a consumer the tags are decoration. Shipping the canonical-check gate is the act that creates the consumer.

    Decision Drivers

    • The gate is the condition, not an enhancement (all four voices, session-042). Ungated tags are latent decoration that no consumer exercises — the metadata FIBO/DCMI reject and the over-modelling SWWO Ch. 12 forbids.
    • Atomicity. The tags and the gate that consumes them ship in the same commit or neither — the session-042 “gate + tags adopt together” disposition (echoing session-041’s “relocate AND gate, atomically”).
    • Soundness vs over-modelling. A partial vector false-greens a completeness check (Guarino); a blanket vector tags ~30 classes whose category was never in question (Allemang). The scope that is both sound and disciplined is the subsumption lattice the check ranges over + its contrast set (Kendall).
    • Truthfulness of the value set. ±R/±I moved OPDA bytes (the ODR-0011 §8a cascade is stated in ±R/±I terms); ±D is largely carried by the Relator/founds topology; ±U has adjudicated nothing — asserting it per type would claim a judgement the process never made (Baker + Allemang). So ±R/±I floor, ±D where a Relator decision turned on it, never ±U.
    • Quarantine intact. The gate is the ODR-0031 R3 tag-guard pattern: TBox-only, validates the meta-level, never instance-keyed — so it cannot re-fire the ODR-0030 Rule 1 quarantine trigger.

    Considered Options

    • Option A (chosen) — Conditional, gated, scoped markup. Emit the scoped ±R/±I (+conditional ±D) per-type owl:AnnotationProperty tags and the TBox OntoClean meta-shape that consumes them, atomically; a seventh CI gate; a byte-identity re-pin.
    • Option B — Blanket full-quartet on every class. Rejected (session-042 Q2): over-models (~30 unread vectors), and ±U over-claims a judgement never made.
    • Option C — Prose-only / reject. The no-gate fallback: if the operator declines the gate, keep the per-category skos:definition signatures + the ODRs as the record. This is the disposition by default until the gate is ratified.
    • Option D — Extend ADR-0045. Rejected (Kendall + Allemang): ADR-0045 is a clean landed record with a byte-identity re-pin; a fresh concern belongs in a new ADR (this one).

    Decision Outcome

    Chosen option: “Option A — conditional, gated, scoped markup”, because session-042 converged that the meta-property markup earns its place only when a machine reads it, and the only honest way to ship the tags is to ship — in the same change-set — the gate that consumes them. If the operator does not ratify the gate, Option C (prose-only) stands and nothing is emitted.

    The change-set (on ratification):

    #ChangeTarget
    1Emit opda:ontoCleanRigidity (+ opda:ontoCleanIdentity; opda:ontoCleanDependence where a Relator decision turned on it) as owl:AnnotationProperty, SKOS-sh:in-governed value sets (e.g. rigidity ∈ {rigid, anti-rigid, semi-rigid, non-rigid}; identity ∈ {supplies-IC, carries-IC, no-own-IC}), per type, in opda-annotations.ttl. Never opda:ontoCleanUnity.emitters/ufo_categories.py (the annotation-graph emission point)
    2Scope the tags to the subsumption lattice the check ranges over + its contrast set (the tenureKind/VouchEvidence/RiskAssessment/evidence family + the Kinds they sit under), not blanket-every-class, not only the contested leaves; omit a tag where the value is already inherited category → scheme → signaturesame
    3Emit the TBox OntoClean meta-shape — the canonical check “every −R type that is nonetheless rdfs:subClassOf something” + IC-incompatible subsumption — as a sh:Violation meta-shape (the ODR-0031 R3 tag-guard pattern: sh:targetSubjectsOf/SPARQL over the TBox, never sh:targetClass/sh:path on instance data), with opda:metaShapeJustificationemitters/shapes.py
    4Add a seventh CI check running the meta-shape over the class+annotation graph (the editorial pass; never the instance-validation union)ci/three_graph_test.py (or a sibling) + tests
    5Re-pin byte-identity; all gates greencorpus re-emit
    Atomic(1)+(3) ship in the same commit or neither — tags without the consuming gate are decoration—

    Consequences

    • Good, because OPDA’s load-bearing OntoClean judgement becomes auditable and re-derivable — the canonical self-consistency check (a query no current artefact can run) ships as a green/red gate, and the per-type premise that produced each subclass-vs-facet verdict becomes queryable data, not unfalsifiable prose.
    • Good, because it is separability insurance (Guarino): the OntoClean reasoning survives even if the UFO vocabulary is ever retired (the Devil’s Advocate’s own held Option-D exit), as structured data rather than evaporating prose.
    • Good, because the quarantine holds: owl:AnnotationProperty + TBox-only meta-shape + the (existing) sixth gate mean nothing UFO/OntoClean-shaped reaches the reasoner or the instance validator.
    • Bad (accepted), because it is real build surface (a seventh gate + per-type tags) for an audit of a small, flat lattice; justified only by the gate that exercises it — which is why the atomic rule is load-bearing.
    • Neutral, because scope is the one tension session-042 left bounded (Guarino full-vector-all-40 vs Allemang ±R/±I-<10): this ADR fixes it at the checked lattice + contrast set, ±R/±I floor, to be finalised against the actual subsumption edges at implementation.

    Confirmation

    • The seventh CI check runs the canonical OntoClean meta-shape over the TBox and is green; the existing six three-graph gates + byte-identity stay green.
    • The opda:ontoCleanRigidity/Identity/Dependence tags resolve only in opda-annotations.ttl (owl:AnnotationProperty; never in the classes/shapes graphs; never instance-keyed); no opda:ontoCleanUnity is emitted.
    • The canonical query “SELECT ?sub ?super WHERE { ?sub rdfs:subClassOf ?super . ?super opda:ontoCleanRigidity 'anti-rigid' }” (an anti-rigid type subsuming anything) returns empty against the corpus. Its ±I sibling — the IC-incompatibility violation form “SELECT ?sub ?super WHERE { ?sub opda:ontoCleanIdentity 'supplies-IC' . ?sub rdfs:subClassOf ?super . ?super opda:ontoCleanIdentity 'supplies-IC' }” (a type supplying its own IC subsuming another own-IC supplier) likewise returns empty (check 9; see Amendments 2026-06-17).
    • Atomic gate-or-nothing: CI fails if the tags are present without the consuming meta-shape. Status proposed; the operator ratifies adoption and decides whether to ship the gate — absent that, Option C (prose-only) stands.

    More Information

    • Council provenance: session-042 (Reduced Council; the 3–3 convergence onto the gate condition; Baker WITHDRAWN; the verified “signature already ships per-category” + “no consumer today” findings).
    • Resolves: ODR-0031 §R7(a) (the held 3–3, now conditional adoption).
    • Depends on: ADR-0045 (the UFOCategoryScheme anchor + the sixth-gate / R3 tag-guard pattern this gate reuses); ODR-0027 (the OntoClean cascade the meta-properties are the input to); ODR-0011 §8a; ODR-0004 §3a.
    • External: Guarino & Welty, “An Overview of OntoClean” (Handbook on Ontologies 2nd ed., 2009, §3); Allemang, Hendler & Gandon, Semantic Web for the Working Ontologist 3rd ed. (2020), Ch. 12–13; DCMI Abstract Model + the dumb-down/one-to-one principles; W3C SHACL §4.6.

    Vote and Dissent

    Inherits the session-042 verdict — converged conditional adoption (Q1 4–0 gated · Q2 REVISE 4–0 scoped · Q3 4–0 gate-as-precondition · Q4 4–0 conditional). DA Baker WITHDRAWN on the gate condition (his withdrawal condition — “the canonical check ships as a running CI gate” — is exactly this ADR’s atomic rule). Held-as-live dissent (Baker): if the tags ever ship without the running gate (markup-as-decoration), revert to REJECT (DCMI one-to-one + dumb-down). Re-open / REJECT-path trigger: if the operator declines the gate, the disposition is REJECT-for-now — the per-category skos:definition signatures + the ODRs are the record — re-opening when a named consumer (a CI gate, an external reuse partner, or a second OntoClean check) needs the per-type vector as queryable data. Scope bound: Guarino (full vector / all ~40) vs Allemang (±R/±I / <10) — fixed here at the checked lattice + contrast set, ±R/±I floor.

    Amendments

    • 2026-06-16 — RATIFIED proposed → accepted (operator). The operator ratified the gate. All five change-set items implemented and green: (1) opda:ontoCleanRigidity / opda:ontoCleanIdentity / opda:ontoCleanDependence declared owl:AnnotationProperty in opda-annotations.ttl; per-type tags emitted for 8 scoped types (Relator, Transaction, Proprietorship, Role, Proprietor, RoleMixin, Buyer, Seller); (2) scope fixed at subsumption lattice + contrast set, ±R/±I floor, ±D for Relator family only, no opda:ontoCleanUnity; (3) TBox OntoClean meta-shape (OntoCleanAntiRigidSubclassing_MetaShape, sh:targetSubjectsOf opda:ontoCleanRigidity, SPARQL over TBox only, ODR-0031 R3 tag-guard pattern) emitted in opda-shapes.ttl; (4) check 8 added to ci/three_graph_test.py running the meta-shape over class+annotation graph only (never the instance-validation union), 7 new tests; (5) byte-identity re-pinned, all 8 three-graph CI gates green. Implementation note (canonical query): the ADR-0046 confirmation query SELECT ?sub ?super WHERE { ?sub rdfs:subClassOf ?super . ?super opda:ontoCleanRigidity "anti-rigid" } returns 3 results in the corpus (Buyer/Seller→RoleMixin, Proprietor→Role) — these are VALID anti-rigid-subclasses-anti-rigid cases, not violations. The VIOLATION form of the query (adding ?sub opda:ontoCleanRigidity "rigid") returns EMPTY. Check 8 implements the violation form; the CI gate is green. Baker’s atomicity condition is met — gate + tags ship together.
    • 2026-06-16 — Meta-shape direction corrected (operator pre-commit verification). The OntoCleanAntiRigidSubclassing_MetaShape SPARQL + sh:message + justification as first emitted checked anti-rigid ⊑ rigid (the valid direction — Student ⊑ Person), inconsistent with check 8 and with OntoClean. Corrected to the violation form rigid ⊑ anti-rigid — an anti-rigid type cannot subsume a rigid one (Person ⊑ Student forbidden; Guarino & Welty 2009 §3) — so the shipped meta-shape and the check-8 CI gate now enforce the identical, correct invariant. Both empty against the corpus; gates green; byte-identity re-pinned.
    • 2026-06-17 — ±I IC-incompatibility limb implemented (operator). Change-set item 3 named “IC-incompatible subsumption” as part of the consuming TBox meta-shape; the original implementation shipped only the ±R rigidity limb (OntoCleanAntiRigidSubclassing_MetaShape + check 8). This amendment adds the ±I identity-criterion sibling, giving the opda:ontoCleanIdentity tags their own consuming TBox meta-shape + CI gate, wired exactly like the ±R limb: (a) builder build_ontoclean_identity_tbox_meta_shape in emitters/shapes.py emits OntoCleanIncompatibleIdentitySubclassing_MetaShape (sh:targetSubjectsOf opda:ontoCleanIdentity — TBox/tag-keyed, ODR-0031 R3 tag-guard, NEVER instance-keyed; sh:Violation; opda:metaShapeJustification); (b) check 9 check_ontoclean_identity_tbox in ci/three_graph_test.py runs it over the class+annotation graph only (the editorial pass — never the instance-validation union). Incompatibility predicate (the correct OntoClean direction): a type that supplies its own identity criterion (opda:ontoCleanIdentity "supplies-IC") MUST NOT be rdfs:subClassOf another "supplies-IC" type — two independent own-identity suppliers carry distinct, incompatible ICs, so the subsumption would force the subclass to bear two rival own-ICs on the same instances (Guarino & Welty 2009 §3: a sortal cannot subsume a different sortal). The carries-IC ⊑ supplies-IC direction (the real Transaction/Proprietorship ⊑ Relator edges — the subclass inherits the super’s supplied IC) and no-own-IC ⊑ * (Roles/RoleMixins borrowing identity from a bearer — Proprietor ⊑ Role, Buyer/Seller ⊑ RoleMixin) are both VALID. The violation form SELECT ?sub ?super WHERE { ?sub opda:ontoCleanIdentity "supplies-IC" . ?sub rdfs:subClassOf ?super . ?super opda:ontoCleanIdentity "supplies-IC" } returns EMPTY against the corpus (Relator is the only supplies-IC type and it subclasses nothing tagged). Non-vacuity is proven by a positive control: unit test test_ontoclean_identity_supplies_subclasses_supplies_fails constructs a synthetic supplies-IC ⊑ supplies-IC edge and asserts the gate FLAGS it; three negative-control tests assert the gate PASSES the valid carries-IC ⊑ supplies-IC, no-own-IC ⊑ no-own-IC, and no-own-IC ⊑ supplies-IC directions (mirroring the ±R limb’s tests). This mirrors the ±R limb’s sole rigid ⊑ anti-rigid violating pairing with the sole supplies-IC ⊑ supplies-IC one. Baker’s held “no-decoration” dissent on the ±I tags is thereby addressed — the opda:ontoCleanIdentity per-type tags now have a running consumer (the atomicity condition that the gate, not the tag, is the act that earns the markup). No generator-version bump (the ±R limb likewise shipped at opda-gen 1.0.1 without bumping — the convention is no bump for an added OntoClean meta-shape). Corpus delta: opda-shapes.ttl +1 node shape (365 → 366); all nine three-graph CI gates green; byte-identity re-pinned; make ci, baspi5 round-trip (27 passed), and emit-exemplar-reports byte-identity all green.

    ← Back to ADR Corpus  |  View source

    ADRs are MADR-format architecture decisions. A superseded ADR is replaced by a later record rather than edited in place.

    Comments

    Loading comments…