The session root does not set additionalProperties: false, so a custom sibling of events validates today — an accident of drafting, not an extension point: no namespacing, no collision rule, no privacy placement, no consumer obligation. Meanwhile scholarly reporting needs to identify not the individual user but the institution whose access rights the session used (SAML entity ID, ROR ID). license_ref cannot carry that: it names the grant instance and works as an institutional proxy only within one issuer's namespace (5.2.3).
Proposed, drafted for the v1 release candidate: a session-level data object mirroring the event-level field (new 5.1.3), with one core container, access_context, holding a typed identifiers array. Core schemes are ror, saml_entity_id and isni; the vocabulary is open and consumers tolerate unknown schemes. Typed rather than free text so four publishers do not produce four encodings of the same institution; an array because access rights arrive through consortia, federated identity and proxies at once.
Privacy is the substantive design point. The identifier sits outside the 5.5 ladder, so it is gated by governing terms instead: emitters MUST NOT populate it unless the terms require it, and SHOULD pair it with intent or minimal turn data — institution plus query text approaches re-identification at a small subscriber. 5.5 gains a paragraph placing the container inside the privacy model.
Decided in the same change: terms_ref (#3) stays event-level only. Sessions legitimately span content under different terms, and this container is not a terms slot.
Where the content owner authenticated the session (origin/edge), it already knows the institution. The field earns its place where a third-party agent asserts the affiliation — which is where the claim is least verifiable. Corroborating an asserted affiliation is verification-layer work, outside core: a concrete first case for the evidence profile.
The session root does not set
additionalProperties: false, so a custom sibling ofeventsvalidates today — an accident of drafting, not an extension point: no namespacing, no collision rule, no privacy placement, no consumer obligation. Meanwhile scholarly reporting needs to identify not the individual user but the institution whose access rights the session used (SAML entity ID, ROR ID).license_refcannot carry that: it names the grant instance and works as an institutional proxy only within one issuer's namespace (5.2.3).Proposed, drafted for the v1 release candidate: a session-level
dataobject mirroring the event-level field (new 5.1.3), with one core container,access_context, holding a typedidentifiersarray. Core schemes areror,saml_entity_idandisni; the vocabulary is open and consumers tolerate unknown schemes. Typed rather than free text so four publishers do not produce four encodings of the same institution; an array because access rights arrive through consortia, federated identity and proxies at once.Privacy is the substantive design point. The identifier sits outside the 5.5 ladder, so it is gated by governing terms instead: emitters MUST NOT populate it unless the terms require it, and SHOULD pair it with
intentorminimalturn data — institution plus query text approaches re-identification at a small subscriber. 5.5 gains a paragraph placing the container inside the privacy model.Decided in the same change:
terms_ref(#3) stays event-level only. Sessions legitimately span content under different terms, and this container is not a terms slot.Where the content owner authenticated the session (
origin/edge), it already knows the institution. The field earns its place where a third-party agent asserts the affiliation — which is where the claim is least verifiable. Corroborating an asserted affiliation is verification-layer work, outside core: a concrete first case for the evidence profile.