Schema
Status
Phases 1–3 of the schema reconciliation are live and verified in production: a privacy fix, the Linked Art provenance remapping described below, and a set of JSON-LD type corrections. Phase 4 — renaming the artism: JSON-LD namespace prefix to art-official: and pointing @context at this site’s /ns/ — is pending, and was blocked on this site existing with a real, resolving /ns/ path. It can now proceed.
The core mechanism: confidence and source on every field
Every value in the schema is designed to carry two tags, applied consistently:
- Confidence — whether the value is confirmed or inferred
- Source — whether it came from conversation, image analysis, or background research
In the live implementation, this shows up in two related but distinct places:
provenanceConfidenceLayer— a genuineart-official:extension, a four-level enum applied to specific claims (see below)- A separate
confidence/sourcetagging pattern used during live cataloguing sessions (confirmed/inferred,conversation/image-analysis/knowledge-base), which is session-staging data — not necessarily copied onto final artwork fields at commit. These two systems are related but not identical.
Known vocabulary drift, worth naming honestly: the specced four-level enum for provenanceConfidenceLayer is documented-fact | credible-inference | institutional-assertion | speculation. Some live records instead use a simpler high/medium vocabulary that leaked in from the session-tagging system. This is a real, acknowledged inconsistency in the live data, not yet fully reconciled — stated plainly here rather than glossed over, consistent with the project’s own standard.
Provenance and ownership: the Linked Art remapping
This is the area with the most substantial recent change, and the one most worth documenting accurately.
Before reconciliation: ownershipHistory, salesRecord, and loanHistory were untyped JSON blobs with no schema-level enforcement, linked to each other only by an unenforced transactionId convention that nothing in the code actually validated.
After reconciliation, now live:
ownershipHistoryis a typed array of events:acquisition|transfer|consignment. Each row carries anactor(a relationship to a People record, or a private text field for undisclosed owners), aplace,dateAcquired/dateRelinquished, aclaimStatus, privatenotes, and an optionalsalegroup living on the same row.- The
transactionIdlinkage pattern is gone entirely. A sale is now the ownership-changing event itself, rather than a separately-tracked object that has to stay in sync with a matching ownership row. This removes a category of integrity bug — a sale and an ownership record silently drifting out of agreement — by construction, not by validation. salesRecordstill exists, but now serves a narrower, different purpose: a legacy ledger for edition/print-channel sales, not unique-work sales. Unique-work sales route throughownershipHistory[].saleinstead.loanHistoryis now a real relationship to an Events collection, not a raw numeric ID sitting in an untyped JSON blob. The public page correctly resolves and links the related event rather than printing a bare reference number.provenanceConfidenceLayerstays as the genuineart-official:extension layer on top of this — the event-chain model captures what happened, but has no general-purpose epistemic-confidence mechanism of its own. This is original protocol territory, not something reinvented unnecessarily.
Why this model rather than a blockchain-style chain of custody: a closed chain-of-custody record only works if every actor in the chain participates — the moment it reaches someone outside the system, it doesn’t just stop, it actively misleads by looking complete when it isn’t. The evidence-based, confidence-tagged event model used here makes incompleteness visible instead of hiding it.
Actor / identity model
People — collectors, curators, gallerists, co-exhibitors, organizers, institutions — resolve to a single shared People record rather than being re-typed as free text or embedded objects in every context they appear. This was a real, live inconsistency before reconciliation (some relations, like an event’s organiser or curator, were already proper relationships; others, like performance collaborators or talk co-speakers, were embedded free-text objects) — now unified.
- A
rolefield on each People record (curator|gallerist|organiser|artist|collector|critic|collaborator|publisher|educator|institution|other) determines how the actor is expressed in generated JSON-LD: an individual resolves toPerson, an institution resolves toOrganization. This logic previously always emittedPersonregardless of role — now corrected. - Venues remain free-text fields for now — a deliberate, acknowledged deferral, not an oversight. Very little venue data currently carries any authority identifier (Wikidata, TGN), so the cost of formalizing this into its own actor type hasn’t yet been worth it. Worth revisiting once more venue data exists.
Vision analysis
Every AI vision pass on an artwork image runs blind — no title, series, or date in the prompt, and the model is explicitly instructed not to identify the work even if it recognizes it. This keeps the vision layer an independent witness rather than an echo of already-known metadata.
A single field, unresolved, is mandatory on every pass — the machine-analogue of a viewer saying I don’t know what this is doing but I keep coming back to it. Per the protocol’s own stated philosophy, this is treated as the most valuable signal available, not a gap to smooth over.
The vision model itself is not a neutral instrument — see the white paper’s Open Questions for the full argument. The schema’s design (mandatory model/version/date tagging on every analysis) exists specifically so this conditioning is visible and can be weighed, not hidden.
Career-stage tiering
The full field set exists for every artist from day one but is filtered by relevance in the cataloguing dialogue rather than shown all at once. A Studio-tier artist is never asked about auction estimates or institutional loan history. As a practice moves through Market and Institutional stages, fields like sales records, resale delta, authentication history, and institutional dependency records activate. This is a dialogue-layer filter only — the underlying record always has room for the field, whether or not a given artist has been asked to fill it yet.
Interoperability
The schema does not invent a parallel vocabulary where an adequate one already exists.
- schema.org provides basic object identity and discovery — the layer general search engines and language models already parse.
VisualArtworkis the base type for all artworks. - Time-based works (video, audio, performance documentation) are typed with more than one applicable schema.org type at once — a video artwork carries both
VisualArtworkandVideoObject, inheriting schema.org’s own nativeduration(proper ISO 8601 format, e.g.PT4M),contentUrl, andencodingFormatproperties rather than reinventing them. This is now live and verified — previously, artwork JSON-LD was always typed asVisualArtworkalone, even for video works. - Event types are mapped to the correct specific schema.org subtype based on the actual event: solo/group exhibitions →
ExhibitionEvent, art fairs →Event, performances →PerformanceEvent, education →EducationEvent, publications/bibliography →PublicationEvent, screenings →ScreeningEvent. This mapping had several incorrect fallback cases before reconciliation (art fairs incorrectly mapped toExhibitionEvent; publications and screenings falling through to a generic default) — now corrected and verified. - No use of the Web Annotation Data Model (WADM) currently exists in the live codebase, despite being referenced in earlier planning documents as a future direction for viewer-response data.
- A small, purpose-built
art-official:namespace covers only what has no existing adequate equivalent: the intent/dialogue fields (intent,makingNote,directInspiration,consciousRejections,encounterNote,formalContributionAssessment),workContext, the embeddings and vision-analysis apparatus, and the provenance-confidence layer described above.
creator / identity resolution in JSON-LD
Artwork-page JSON-LD now correctly emits a full Person object for creator — name, alternateName, Wikidata identifier, and @id — rather than a bare @id-only pointer, the previous behavior. This reuses the same identity-resolution logic already correctly in place on the bio page and statement page, rather than maintaining a second, inconsistent implementation.
Privacy / field access
ownershipHistory, loanHistory, and provenanceConfidenceLayer are genuinely field-access-restricted now (artist-or-admin only) on the raw public REST API — a real gap existed previously where these fields were technically public-read with after-the-fact key-stripping, a meaningfully weaker guarantee than field-level access control. Public-facing pages still display a deliberately projected, narrower version of ownership data (collector-visible rows, public loans, non-speculation claims only — never private notes, sale financials, or evidence fields) via a server-side-only code path, not the raw API.
This matters for the broader honesty argument: the schema’s confidentiality guarantees are now real access-control guarantees, not display-layer conventions that a direct API query could bypass.
What this page does not claim
- No claim of WADM integration — not implemented.
- No claim that the four-level provenance-confidence enum is used consistently — some live records use the simpler
high/mediumvocabulary; this is known drift, not yet fully reconciled. - No claim that venues resolve to structured actor identities — they remain free text by deliberate, acknowledged deferral.
- No claim that
salesRecordhandles unique-work sales — that routes throughownershipHistory[].salenow;salesRecordis legacy edition/channel data only.