Ontology — Generative System Model.
Domain, standard, and legal vocabularies — sourced into GSM, ready to enforce.
Why it matters
What Ontology changes for you.
The published, versioned catalogue of vocabularies and governance content sourced into GSM-compatible schemas: domain and standard semantics, legal vocabularies, evaluable Directives and Norms, and executable Mechanisms. Surfaced in ITIP through the Ontology Catalogue & Composer.
Day-one governance, not a blank page.
TOGAF, ISO 25000-series, GDPR, NIS2, and more — over a hundred sourced schemas you attach instead of authoring from scratch. The expertise is already in the catalogue.
Delivered by TOGAF · ISO 25010 · ISO 25012 · GDPR · NIS2 · SCAP
The authority’s own taxonomy, clause by clause.
Each ontology package preserves its source model’s own structure and every sourced Directive and Norm cites the clause it derives from — provenance you can hand to an auditor.
Ontologies that compose, not collide.
A quality model, an architecture framework, and a regulation govern the same subject without schema conflicts — they compose through the GSM governance layer into one coherent fabric.
Delivered by HTTP · gRPC · GraphQL · Kafka · AMQP · JDBC · WebSocket · IT
Every claim carries where it came from.
Sourced provenance vocabulary types the attribution of a governed claim — who or what asserted it travels with the definition instead of being reconstructed later.
Delivered by PROV
Maintained as the real world changes.
The catalogue is continuously updated as standards, regulations, and legal texts evolve — the organization using it always governs against current requirements, not a frozen snapshot.
Delivered by Catalogue update stream · DORA · SAFe · ITIL
Features
What Ontology does.
HTTP
HTTP interaction semantics sourced as typed Archetypes — methods, status, caching, content negotiation, machine-readable.
TOGAF
Enterprise-architecture vocabulary sourced as typed Archetypes — organized by the framework’s own taxonomy, clause by clause.
IT
The IT-domain vocabulary and semantics ITIP governs with — structures, mechanisms, interactions, typed.
ISO 25010
The software quality model sourced as typed Archetypes — quality characteristics as machine-readable vocabulary.
ISO 25012
The data quality model sourced as typed Archetypes.
PROV
Provenance vocabulary — the Attribution facet (`wasAttributedTo`) sourced as a typed Archetype.
gRPC
gRPC interaction vocabulary sourced as typed Archetypes — reserved, to be sourced.
GraphQL
GraphQL interaction vocabulary sourced as typed Archetypes — reserved, to be sourced.
Kafka
Kafka interaction vocabulary sourced as typed Archetypes — reserved, to be sourced.
AMQP
AMQP interaction vocabulary sourced as typed Archetypes — reserved, to be sourced.
JDBC
JDBC interaction vocabulary sourced as typed Archetypes — reserved, to be sourced.
WebSocket
WebSocket interaction vocabulary sourced as typed Archetypes — reserved, to be sourced.
GDPR
Regulation vocabulary plus evaluable Directives and Norms, each citing the clause it derives from.
NIS2
Directive vocabulary plus evaluable Directives and Norms with clause provenance.
SCAP
Security content automation vocabularies — identification schemes made machine-readable.
DORA
Digital operational resilience regulation sourcing — planned.
SAFe
Scaled-agile framework sourcing — planned.
ITIL
IT service-management framework sourcing — planned.
Catalogue update stream
The catalogue is continuously re-sourced as standards, regulations, and legal texts evolve — you govern against current requirements, not a frozen snapshot.
Roadmap
- v0.1 ✓ In active development
- v1.0 MVP/GA — HTTP, TOGAF, IT, ISO 25010, ISO 25012, and PROV complete & validated
- v1.x Remaining protocols (gRPC, GraphQL, Kafka, AMQP, JDBC, WebSocket) · GDPR · NIS2 · SCAP · DORA · SAFe · ITIL (unordered)
Ordered intent, not delivery commitments or dates — per the canonical Milestones & Versions register.