{
 "@context": "https://schema.org",
 "@type": "Claim",
 "@id": "https://wulfkaal.github.io/positions/2026-08-26-009",
 "identifier": "kaal:position:2026-08-26-009",
 "additionalType": "https://wulfkaal.github.io/positions/schema.json#AffirmedPositionClaim",
 "name": "Integration Governance Settlement",
 "text": "Technical interoperability does not settle an institutional relation. Swales, Gooden, and Thaldar reach the same boundary through a scoping review of twenty-four data transfer agreements. The agreements identify the parties, state the purpose of the transfer, allocate duties, restrict processing, provide for audit, assign liability, and specify termination and dispute resolution. These clauses do more than document an exchange. They determine who acts, what the recipient may do, how compliance is assessed, who bears loss, and what follows from breach. The evidence independently extends Kaal's claim: a new integration needs a governance settlement before data or authority crosses the boundary.\n\nThe evidence is narrower than Kaal's claim. The review studies English-language agreements for health research. It treats the identity of legal parties rather than authentication of software components. It does not test sovereign agent runtimes or automated remedies. The institutional mechanism nevertheless transfers. A runtime should translate the agreement into executable fields: verified component identity, delegated authority, purpose and duration limits, assigned responsibility, audit rights, termination, and redress. An unset field is not a harmless implementation gap. It leaves a material term unresolved. The integration gate should therefore refuse execution until each field names an accountable actor and an enforceable consequence. Technical compatibility can open a channel. Only the prior settlement makes its use institutionally defensible.",
 "author": {
  "@type": "Person",
  "name": "Wulf A. Kaal",
  "identifier": "https://orcid.org/0009-0008-7840-1847"
 },
 "datePublished": "2026-08-26",
 "dateModified": "2026-08-26",
 "creativeWorkStatus": "Affirmed",
 "responseType": "extension",
 "keywords": [
  "institutional-design",
  "governance-design",
  "ai-and-agents",
  "data-governance",
  "identity",
  "authority",
  "accountability",
  "remedy"
 ],
 "scope_conditions": [
  "The response is limited to the exact full-text propositions and the one mapped Kaal claim.",
  "External evidence level: peer-reviewed scoping review with complete open full text.",
  "Mapping review tier: independent substantive scholarly-growth extension.",
  "The scoping review covers twenty-four publicly available English-language data transfer agreements and does not claim a universal contract template.",
  "The source concerns health-research data transfers rather than sovereign local agent runtimes or machine-to-machine integrations.",
  "Its treatment of identity concerns legal parties and authorized users, not cryptographic testing of a software component's identity.",
  "The article provides legal drafting guidance and clause prevalence, not an empirical test of automated remedies or runtime enforcement."
 ],
 "currentDebate": {
  "name": "The anatomy of a data transfer agreement for health research",
  "url": "https://doi.org/10.3389/fphar.2024.1332700"
 },
 "extends": {
  "identifier": "kaal:claim:7314479-009",
  "url": "https://wulfkaal.github.io/claims/7314479-009",
  "citation": "Wulf A. Kaal, Institutional Requirements for Sovereign Local Agent Runtimes (2026). SSRN: https://ssrn.com/abstract=7314479",
  "paper": "Wulf A. Kaal, Institutional Requirements for Sovereign Local Agent Runtimes",
  "authors": [
   "Wulf A. Kaal"
  ],
  "year": "2026",
  "ssrn": "https://ssrn.com/abstract=7314479",
  "source_pdf_sha256": "debace24a155ae924a155b1fafe98856d98cf83689feff2f87a32f1c06171ce6"
 },
 "isBasedOn": [
  {
   "@id": "https://wulfkaal.github.io/claims/7314479-009"
  },
  {
   "@type": "CreativeWork",
   "name": "The anatomy of a data transfer agreement for health research",
   "url": "https://doi.org/10.3389/fphar.2024.1332700"
  }
 ],
 "batch_id": "kaal-review:2026-08-26:scholarly-growth-7314479-009-reviewed-v2",
 "review_provenance": "https://wulfkaal.github.io/positions/by-claim/7314479-009.html",
 "publicationStatus": "public",
 "recordTypeNote": "Dated commentary position extending a scholarly corpus claim. Not a verbatim claim extracted from the paper.",
 "isPartOf": {
  "@id": "https://wulfkaal.github.io/positions/index.json"
 },
 "version": "1.0",
 "canonical_url": "https://wulfkaal.github.io/positions/2026-08-26-009",
 "canonicalForm": "https://wulfkaal.github.io/positions/2026-08-26-009.md",
 "candidateId": "kaal:response-candidate:2026-08-26:scholarly-growth-7314479-009-integration-governance-settlement-01",
 "evidenceLevel": "peer-reviewed scoping review with complete open full text",
 "reviewTier": "independent substantive scholarly-growth extension",
 "mappingConfidence": 0.94,
 "mappingAmbiguous": false,
 "mappingMethod": "independent substantive scholarly-growth one-to-one review",
 "mappingWhyRelevant": "The review independently identifies the institutional terms that govern a cross-boundary data transfer: the parties, purpose, rights and restrictions, duties, audit, liability, termination, and dispute resolution. Those terms correspond to Kaal's identity, authority, permitted-use, responsibility, and remedy categories, while the source remains limited to legal agreements in health research rather than component authentication or agent runtimes.",
 "sourceProvenance": {
  "source": "Frontiers in Pharmacology peer-reviewed scoping review with complete open full text",
  "sourceRecordId": "doi:10.3389/fphar.2024.1332700",
  "doi": "10.3389/fphar.2024.1332700",
  "canonicalUrl": "https://doi.org/10.3389/fphar.2024.1332700",
  "publicFullTextUrl": "https://www.frontiersin.org/journals/pharmacology/articles/10.3389/fphar.2024.1332700/pdf",
  "retrievedAt": "2026-08-27T05:45:44.344Z",
  "fullTextPdfSha256": "a55d0e518e74b7f7975d5c0c828668fc64ef8dd1c1c17604a4c1f5e9f12fabe9",
  "extractedTextSha256": "d3a3e86e7bdb29106c9e5c54211f140a0c011d42b31e0662b492560bddb53be1",
  "crossrefRecordSha256": "5d567e2c7bb39c970ccd23352774a42b82b97f126c087be1252df960347a6789",
  "primaryEvidenceReceiptSha256": "46e92e064e55ad632a4bf920cdec7d200598443f637e094833cf200976f48e55",
  "sourceProposition": "Swales, Gooden, and Thaldar identify parties, purpose, rights and restrictions, obligations and audit, liability, termination, and dispute resolution as recurring or recommended terms governing cross-boundary data transfers.",
  "sourcePropositionSha256": "898307fc8fa50ea3a1adc863beffc0691612a2720085f63c5f2204b425e833b2",
  "sourceEvidenceSetSha256": "b85c0434418dfe5ce437f1112a02fa0b857b4ae226b27feb4cfff003edce0629",
  "sourceEvidencePassages": [
   {
    "text": "All twenty-four DTAs provided information about the parties or a blank space in which information could be added",
    "locator": {
     "publication": "Frontiers in Pharmacology 15:1332700",
     "articlePage": 4,
     "section": "3.1 Introduction, definitions, and parties"
    },
    "sha256": "6f83cf01391bdab29dce7b055a7b5ee49407e7d1bb6170d27883365bd6e62d76"
   },
   {
    "text": "A purpose clause sets out the primary intention of the parties and articulates the nature of the agreement",
    "locator": {
     "publication": "Frontiers in Pharmacology 15:1332700",
     "articlePage": 4,
     "section": "3.2 Purpose"
    },
    "sha256": "7eab01710c34978df9193d3c3b41ac4e2edc531425b80ed93d0bccb6c1c89d18"
   },
   {
    "text": "Twenty-one of the DTAs that we examined contained a clause (or information) detailing the obligations or duties of the parties to the agreement",
    "locator": {
     "publication": "Frontiers in Pharmacology 15:1332700",
     "articlePage": 5,
     "section": "3.4 Obligations on parties"
    },
    "sha256": "36a0b5ede123afbaccc7bcfce1c288818d04ff4fe5c586d2cf439954748b2e4b"
   },
   {
    "text": "Most DTAs in our scoping review dealt with dispute resolution in some form",
    "locator": {
     "publication": "Frontiers in Pharmacology 15:1332700",
     "articlePage": 11,
     "section": "3.13 Dispute resolution"
    },
    "sha256": "4223dda78dedc77a68db6a2a7c330f3107ef651b4dd9b4daf43099b07b63bd23"
   }
  ],
  "workId": "work:doi:10.3389/fphar.2024.1332700",
  "workAuthors": [
   "Lee Swales",
   "Amy Gooden",
   "Donrich Thaldar"
  ],
  "workPublishedAt": "2024-08-27",
  "identityKeys": [
   "doi:10.3389/fphar.2024.1332700",
   "pdf:a55d0e518e74b7f7975d5c0c828668fc64ef8dd1c1c17604a4c1f5e9f12fabe9",
   "proposition:898307fc8fa50ea3a1adc863beffc0691612a2720085f63c5f2204b425e833b2"
  ],
  "claimMappings": [
   {
    "claimId": "kaal:claim:7314479-009",
    "claimUrl": "https://wulfkaal.github.io/claims/7314479-009",
    "rank": 1,
    "confidence": 0.94,
    "method": "independent substantive scholarly-growth one-to-one review",
    "whyRelevant": "The review independently identifies the institutional terms that govern a cross-boundary data transfer: the parties, purpose, rights and restrictions, duties, audit, liability, termination, and dispute resolution. Those terms correspond to Kaal's identity, authority, permitted-use, responsibility, and remedy categories, while the source remains limited to legal agreements in health research rather than component authentication or agent runtimes.",
    "ambiguous": false
   }
  ],
  "substantiveReview": {
   "reviewedAt": "2026-08-27T05:45:44.344Z",
   "sourceIdentityVerified": true,
   "authorIndependenceVerified": true,
   "kaalReferenceFoundInSource": false,
   "temporalIndependence": "The article was published in 2024, before Kaal's 2026 paper.",
   "canonicalPublicStatusVerified": true,
   "peerReviewedStatusVerified": true,
   "retractionOrSupersessionFound": false,
   "propositionFidelityVerified": true,
   "mechanismCorrespondence": "cross-boundary data transfer is governed by explicit parties, purpose and restrictions, duties and audit, liability, termination, and dispute resolution",
   "compatibleScope": "organizational health-research data transfers, limited because the source does not study software-component authentication or sovereign local agent runtimes",
   "responseWordingDefensible": true,
   "oneToOneExtendsMapping": true,
   "exactSupportingQuotesVerified": true,
   "nonOverlap": {
    "candidateIdMatches": false,
    "canonicalUrlMatches": false,
    "propositionHashMatches": false,
    "priorPositionForClaim": false
   },
   "limitations": [
    "The scoping review covers twenty-four publicly available English-language data transfer agreements and does not claim a universal contract template.",
    "The source concerns health-research data transfers rather than sovereign local agent runtimes or machine-to-machine integrations.",
    "Its treatment of identity concerns legal parties and authorized users, not cryptographic testing of a software component's identity.",
    "The article provides legal drafting guidance and clause prevalence, not an empirical test of automated remedies or runtime enforcement."
   ],
   "rejectionReasonsRecorded": true
  },
  "contentMap": {
   "proposition": "Cross-boundary integration requires an explicit governance settlement before data or authority moves.",
   "evidenceLayer": "peer-reviewed scoping review with complete open full text",
   "strongestLimitation": "The source studies health-research agreements and legal parties, not software-component authentication or agent runtimes.",
   "consequence": "A runtime should translate institutional terms into enforceable integration fields.",
   "requestedAction": "Refuse execution while any identity, authority, use, responsibility, or remedy field remains unresolved."
  },
  "stylePack": {
   "profile": "M1 early sole-author baseline v1.2.0",
   "verifiedProfileWorks": [
    "1428387",
    "2150377",
    "2267560"
   ],
   "sameRegisterPassagePackAvailable": true,
   "limitation": "The short public position permits only bounded stylometric comparison."
  },
  "m1Validation": {
   "status": "M1-PASS-WITH-LIMITS",
   "deterministicGate": "pass",
   "hardFailures": 0,
   "warnings": 0,
   "words": 216,
   "reason": "The publication-bound position passed strict and public deterministic controls against a five-passage, three-work style pack. Its short length limits stylometric comparison."
  }
 },
 "userAffirmation": "Authorized under public authority SHA-256 87aad20196a753015a36d970f742c885eb763efdbada4869949bfffe3298130c and event supersession SHA-256 7d47ef36085c4dce590f287c986e4106f3bf35a7da5a25322d6fc3d4abf456d4. Publication remains receipt-bound to successful workflows and exact live-byte verification.",
 "sha256": "10f0cfe7c395a1dba78c36999737123d0c77b0d9c2ce28f20fc93e50f52c5d39"
}
