Human-readable documentation of the Art/Official field structure — what is actually implemented and live, not the original spec. Where this page and any older planning document disagree, this page is correct. It reflects the state of bernardbolter.com, the reference implementation, as of August 2026.

Schema

Reflects the live, post-reconciliation state as of August 2026.

Status

Phases 1–3 of the schema reconciliation are live and verified in production: a privacy fix, the Linked Art provenance remapping described below, and a set of JSON-LD type corrections. Phase 4 — renaming the artism: JSON-LD namespace prefix to art-official: and pointing @context at this site’s /ns/ — is pending, and was blocked on this site existing with a real, resolving /ns/ path. It can now proceed.

The core mechanism: confidence and source on every field

Every value in the schema is designed to carry two tags, applied consistently:

In the live implementation, this shows up in two related but distinct places:

Known vocabulary drift, worth naming honestly: the specced four-level enum for provenanceConfidenceLayer is documented-fact | credible-inference | institutional-assertion | speculation. Some live records instead use a simpler high/medium vocabulary that leaked in from the session-tagging system. This is a real, acknowledged inconsistency in the live data, not yet fully reconciled — stated plainly here rather than glossed over, consistent with the project’s own standard.

Provenance and ownership: the Linked Art remapping

This is the area with the most substantial recent change, and the one most worth documenting accurately.

Before reconciliation: ownershipHistory, salesRecord, and loanHistory were untyped JSON blobs with no schema-level enforcement, linked to each other only by an unenforced transactionId convention that nothing in the code actually validated.

After reconciliation, now live:

Why this model rather than a blockchain-style chain of custody: a closed chain-of-custody record only works if every actor in the chain participates — the moment it reaches someone outside the system, it doesn’t just stop, it actively misleads by looking complete when it isn’t. The evidence-based, confidence-tagged event model used here makes incompleteness visible instead of hiding it.

Actor / identity model

People — collectors, curators, gallerists, co-exhibitors, organizers, institutions — resolve to a single shared People record rather than being re-typed as free text or embedded objects in every context they appear. This was a real, live inconsistency before reconciliation (some relations, like an event’s organiser or curator, were already proper relationships; others, like performance collaborators or talk co-speakers, were embedded free-text objects) — now unified.

Vision analysis

Every AI vision pass on an artwork image runs blind — no title, series, or date in the prompt, and the model is explicitly instructed not to identify the work even if it recognizes it. This keeps the vision layer an independent witness rather than an echo of already-known metadata.

A single field, unresolved, is mandatory on every pass — the machine-analogue of a viewer saying I don’t know what this is doing but I keep coming back to it. Per the protocol’s own stated philosophy, this is treated as the most valuable signal available, not a gap to smooth over.

The vision model itself is not a neutral instrument — see the white paper’s Open Questions for the full argument. The schema’s design (mandatory model/version/date tagging on every analysis) exists specifically so this conditioning is visible and can be weighed, not hidden.

Career-stage tiering

The full field set exists for every artist from day one but is filtered by relevance in the cataloguing dialogue rather than shown all at once. A Studio-tier artist is never asked about auction estimates or institutional loan history. As a practice moves through Market and Institutional stages, fields like sales records, resale delta, authentication history, and institutional dependency records activate. This is a dialogue-layer filter only — the underlying record always has room for the field, whether or not a given artist has been asked to fill it yet.

Interoperability

The schema does not invent a parallel vocabulary where an adequate one already exists.

creator / identity resolution in JSON-LD

Artwork-page JSON-LD now correctly emits a full Person object for creator — name, alternateName, Wikidata identifier, and @id — rather than a bare @id-only pointer, the previous behavior. This reuses the same identity-resolution logic already correctly in place on the bio page and statement page, rather than maintaining a second, inconsistent implementation.

Privacy / field access

ownershipHistory, loanHistory, and provenanceConfidenceLayer are genuinely field-access-restricted now (artist-or-admin only) on the raw public REST API — a real gap existed previously where these fields were technically public-read with after-the-fact key-stripping, a meaningfully weaker guarantee than field-level access control. Public-facing pages still display a deliberately projected, narrower version of ownership data (collector-visible rows, public loans, non-speculation claims only — never private notes, sale financials, or evidence fields) via a server-side-only code path, not the raw API.

This matters for the broader honesty argument: the schema’s confidentiality guarantees are now real access-control guarantees, not display-layer conventions that a direct API query could bypass.

What this page does not claim