AV-2 Integrated Dictionary
Architecture data repository with definitions of all terms used throughout the architecture data and presentations.
Mithril in this model
| Kind | DM2 class | Count | Why |
|---|---|---|---|
| Operator |
Organization
|
1 | DM2 Organization: "A specific real-world assemblage of people and other resources organized for an on-going purpose." The named public operator of mithril.fund is one specific company, an individual — not a type. |
| Legal entity (twin) |
Organization
|
3 | DM2 Organization (an individual). The enterprise twin's LegalEntity / OperatorOrg records are specific legal persons, each with its own jurisdiction. |
| Organization account |
Organization
|
0 | DM2 Organization (an individual): each registered org is one did:webvh organization (com-<handle>.kotoba.cloud) with members. |
| Product vendor |
Organization
|
272 | DM2 Organization (an individual): each product record names the company that provides it. |
| VC fund |
Organization
|
8 | DM2 Organization (an individual): each fund record is one named firm with its own source URL. |
| Portfolio company |
Organization
|
6 | DM2 Organization (an individual): each record is one named company. |
| Legal body |
Organization
|
37 | DM2 Organization (an individual): courts, agencies, bar associations and prosecutors are specific bodies organized for an on-going purpose. |
| Threat actor group |
Organization
|
176 | DM2 Organization (an individual): an ATT&CK intrusion set is reported as one specific group of people acting for an on-going purpose. The record is a reported association, not an attribution made here. |
| Historical ransomware group |
Organization
|
219 | DM2 Organization (an individual): each Ransomwatch record names one group. The records are historical and unconfirmed, as the catalog labels them. |
| Organization type (account) |
OrganizationType
|
1 | DM2 OrganizationType: "A type of Organization." Every Mithril organization account has the same shape (roles, did:webvh, membership VCs); that shape is the type, the registered orgs its members. |
| Organization type (catalog) |
OrganizationType
|
4 | DM2 OrganizationType: the catalogs group organizations by kind (VC fund, portfolio company, intrusion set, historical group); each kind is a type of Organization. |
| Reference organization model |
OrganizationType
|
1 | DM2 OrganizationType: orgbrain's ontology describes a kind of company (its roles, authorities, processes) that a customer's org is compared against — a type, not a particular company. |
| Organization role |
PersonRoleType
|
4 | DM2 PersonRoleType: "A category of person roles defined by the role or roles they share that are relevant to an architecture." owner / admin / member / billing are categories of person roles; DM2 has no plain PersonRole class, and no individual person is published. |
| Job role (orgbrain) |
PersonRoleType
|
8 | DM2 PersonRoleType: CEO, CFO, IT Admin … are categories of person roles in the reference model (with a minimum headcount), not individuals. |
| Business process |
Activity
|
6 | DM2 Activity: "Work, not specific to a single organization, weapon system or individual that transforms inputs (Resources) into outputs (Resources) or changes their state." Each BPMN process is such work, defined for the reference organization. |
| Process task |
Activity
|
39 | DM2 Activity: each BPMN task is a unit of work, part of its process. |
| RACI task |
Activity
|
15 | DM2 Activity: each RACI task (annual budget, payroll run …) is recurring work with a responsible role. |
| Attack technique |
Activity
|
498 | DM2 Activity: an ATT&CK technique is reported adversary work that changes the state of the systems it acts on; it is not specific to one group. |
| Authority |
Rule
|
6 | DM2 Rule: "A principle or condition that governs behavior; a prescribed guide for conduct or action." An authority (approve-spend, sign-contract …) is the condition under which a task may be done. |
| Security service |
Service
|
8 | DM2 Service: "A mechanism to enable access to a set of one or more capabilities, where the access is provided using a prescribed interface and is exercised consistent with constraints and policies as specified by the service description." Each of the eight services is offered through a documented interface with stated capabilities. |
| Service endpoint |
ServicePort
|
3 | DM2 ServicePort: "A part of a Performer that specifics a interaction component through which the Performer interacts with other Performers." POST /v1/security/govern | respond | recover are those interaction points. |
| External service |
Service
|
2 | DM2 Service: Stripe (billing) and Cloudflare (Workers, R2, Durable Objects, custom domains) are mechanisms giving Mithril access to capabilities through prescribed interfaces. |
| Capability |
Capability
|
31 | DM2 Capability: "The ability to achieve a Desired Effect under specified [performance] standards and conditions through combinations of ways and means [activities and resources] to perform a set of activities." Each service lists the abilities it provides. |
| Mithril platform |
System
|
1 | DM2 System: "A functionally, physically, and/or behaviorally related group of regularly interacting or interdependent elements." Mithril as a whole: the Workers, data stores and security products that serve mithril.fund. |
| Worker |
System
|
5 | DM2 System: each Cloudflare Worker is a deployed group of interacting code, bindings and routes. |
| Data store |
System
|
4 | DM2 System: an R2 bucket or a Durable Object class is a group of storage elements that a Worker regularly interacts with. |
| Security product |
System
|
10 | DM2 System: each Mithril security product (EDR, SIEM, CMDB …) is a group of engines, rules and an API that work together. |
| Market product |
System
|
374 | DM2 System: each catalogued commercial product (a scanner, an EDR suite …) is a system; the catalog records what it is, not how it performs. |
| Product category |
SystemType
|
45 | DM2 SystemType: "The Powertype of System." A category such as edr-xdr is a set of systems; its members are the products filed under it. |
| Resident bot |
System
|
2 | DM2 System: a Hermes profile is a model, tools, schedule and memory working together to act for the repository (support inbox, security watch). |
| Cloud agent |
System
|
0 | DM2 System: a desktop agent backed up to /v1/agents is persona, memory and model working together. The records belong to their owners and are never published, so there are no public instances. |
| Runtime control |
Rule
|
2 | DM2 Rule: "A principle or condition that governs behavior." A rate limit or the Biscuit root-key check governs what the edge admits. |
| Standard or framework |
Standard
|
7 | DM2 Standard: "A formal agreement documenting generally accepted specifications or criteria for products, processes, procedures, policies, systems, and/or personnel." ISO/IEC 27001, SOC 2, PCI DSS, NIST CSF 2.0, CIS Controls, CSA CCM, ISO/IEC 27701. |
| Regulation |
Rule
|
9 | DM2 Rule: a regulation (GDPR, HIPAA, DORA, APPI …) or a government authorization program (FedRAMP) is a prescribed guide for conduct issued by an authority, not a consensus standard. |
| CSF 2.0 subcategory |
Guidance
|
106 | DM2 Guidance: "An authoritative statement intended to lead or steer the execution of actions." A CSF 2.0 subcategory is an outcome statement NIST publishes to steer practice; it is part of the CSF standard. |
| Legislation |
Rule
|
4 | DM2 Rule: a statute or regulation (GDPR, NIS2, APPI, PDPA) is a prescribed guide for conduct. |
| Treaty |
Agreement
|
1 | DM2 Agreement: "A consent among parties regarding the terms and conditions of activities that said parties participate in." The Budapest Convention is agreed among its parties. |
| Standard (legal corpus) |
Standard
|
1 | DM2 Standard: the legal corpus files NIST CSF 2.0 as a framework — a formal, generally accepted specification. |
| Security specification |
Standard
|
1 | DM2 Standard: SCAP is a published family of specifications for exchanging configuration and vulnerability information. |
| Legal corpus |
Information
|
9 | DM2 Information: "the state of a something of interest that is materialized -- in any medium or form -- and communicated or received." A legislation portal or case-law database is a body of published information, not itself a rule. |
| Sanctions list |
Information
|
9 | DM2 Information: each list is a published body of designations (a CSV, XML or web page). The prohibition it carries is the issuing authority's regulation, which the catalog does not record — so the list is Information, not Rule. Aggregators (OpenSanctions) publish lists too. |
| Audit log |
Data
|
1 | DM2 Data: "Representation of information in a formalized manner suitable for communication, interpretation, or processing by humans or by automatic means." A lab audit log is machine-readable records. |
| Threat model |
Information
|
1 | DM2 Information: an authored threat-model scenario template is information about a situation; the catalog marks it as not evidence of an attack. |
| Published dataset |
Data
|
8 | DM2 Data: each catalog Mithril publishes (JSON blocks, JSON-LD, datoms) is information formalized for processing by automatic means. |
| Pedigree |
PedigreeInformation
|
8 | DM2 PedigreeInformation: "Information describing pedigree." Each dataset's provenance — the source URLs, evidence layers, fetch dates, upstream commits and file hashes it records, and prov:wasDerivedFrom on every security-data claim — is its pedigree. |
| Architectural description |
ArchitecturalDescription
|
53 | DM2 ArchitecturalDescription: "Information describing an architecture such as an OV-5 Activity Model document." Each page of this architecture surface, and the JSON-LD, describes Mithril's architecture. |
| DoDAF model |
ArchitecturalDescriptionType
|
52 | DM2 ArchitecturalDescriptionType: "The Powertype of ArchitecturalDescription." Each of the 52 official models (AV-1 … DIV-3) is a kind of architectural description; the page for it is an instance. |
| Country |
Country
|
5 | DM2 Country: "A political state or nation or its territory." |
| Geopolitical extent |
GeoPoliticalExtent
|
2 | DM2 GeoPoliticalExtent: "A geospatial extent whose boundaries are by declaration or agreement by political parties." The EU and the EEA are extents by agreement, not countries. |
| Logical location |
Location
|
1 | DM2 Location: "A point or extent in space that may be referred to physically or logically." The Cloudflare global edge, the twin's worker jurisdiction, is logical, not geopolitical. |
5 more kinds map to DM2 classes this model does not list; the full dictionary is on the overview. Integrated dictionary — the site mapping
Concepts with Mithril instances
| Concept | Code | Count | Examples |
|---|---|---|---|
Activity
|
o | 558 |
|
Agreement
|
o | 1 |
|
ArchitecturalDescription
|
o | 53 |
|
ArchitecturalDescriptionType
|
o | 52 |
|
Capability
|
o | 31 |
|
Country
|
o | 5 |
|
Data
|
o | 9 |
|
GeoPoliticalExtent
|
df | 2 |
|
Guidance
|
df | 106 |
|
Information
|
dfo | 19 |
|
Location
|
dfo | 1 |
|
Organization
|
o | 722 |
|
OrganizationType
|
o | 6 |
|
PedigreeInformation
|
dfo | 8 |
|
PersonRoleType
|
o | 12 |
|
Rule
|
dfo | 21 |
|
Service
|
o | 10 |
|
ServicePort
|
o | 3 |
|
Standard
|
df | 9 |
|
System
|
o | 396 |
|
SystemType
|
o | 45 |
|
Relations
| Concept | Code | Count | Examples |
|---|---|---|---|
WholePartType
|
ifo | 164 |
|
couple
|
if | 657 |
|
describedBy
|
dfo | 69 |
|
individualResourceInLocation
|
o | 3 |
|
servicePortDescribedBy
|
o | 3 |
|
typeInstance
|
ifo | 891 |
|
Concepts without Mithril instances (136)
-
ActivityTypeo -
AdaptabilityMeasureo -
AdaptabilityMeasureTypeo -
AgreementTypeo -
BeforeAfterTypedfo -
Conditiono -
ConditionTypeo -
CoupleTypeif -
DescriptionSchemedfo -
DomainInformationo -
DomainInformationTypeo -
EndBoundaryTypedfo -
Facilityo -
FacilityTypeo -
FacilityTypeTypeo -
FunctionalStandardo -
FunctionalStandardTypeo -
GeoFeatureo -
GeoFeatureTypeo -
GeoFeatureTypeTypeo -
GeoPoliticalExtentTypedf -
GeoPoliticalExtentTypeTypedf -
GuidanceTypedf -
Individualif -
IndividualPerformerdfo -
IndividualPersonRoleo -
IndividualResourcedf -
IndividualTypeif -
IndividualTypeTypeif -
InformationTypedfo -
Installationo -
InstallationTypeo -
InstallationTypeTypeo -
Lineo -
LineTypeo -
LineTypeTypeo -
LocationTypedfo -
LocationTypeTypedfo -
MaintainabilityMeasureo -
MaintainabilityMeasureTypeo -
Materielo -
MaterielTypeo -
Measuredfo -
MeasureOfEffecto -
MeasureOfEffectTypeo -
MeasureTypedfo -
MeasureTypeUnitsOfMeasuredfo -
MeasureableSkillo -
MeasureableSkillTypeo -
Namenp -
NameTypedf -
NamingSchemenp -
NeedsSatisfactionMeasureo -
NeedsSatisfactionMeasureTypeo -
OrganizationTypeTypeo -
OrganizationalMeasureo -
OrganizationalMeasureTypeo -
OverlapTypedfo -
PedigreeInformationTypedfo -
PerformanceMeasureo -
PerformanceMeasureTypeo -
Performerdfo -
PerformerTypedfo -
PersonRoleTypeTypeo -
PhysicalMeasureo -
PhysicalMeasureTypeo -
PlanarSurfaceo -
PlanarSurfaceTypeo -
PlanarSurfaceTypeTypeo -
PortTypeo -
Powertypeif -
Propertydf -
PropertyTypedf -
RealPropertydf -
RealPropertyTypedf -
RealPropertyTypeTypedf -
Representationdfo -
RepresentationSchemedfo -
RepresentationTypedf -
Resourcedfo -
ResourceTypedfo -
RuleTypedfo -
SecurityAttributesGroups -
SecurityAttributesGroupTypes -
ServiceLeveldfo -
ServiceLevelTypedfo -
ServicePortTypeo -
ServiceTypeo -
Signdf -
SignTypedf -
SignTypeTypedf -
SingletonActivityo -
SingletonIndividualTypedf -
SingletonResourcedfo -
Skillo -
SkillTypeo -
StandardTypedf -
StartBoundaryTypedfo -
Surfaceo -
SurfaceTypeo -
SurfaceTypeTypeo -
TechnicalStandardo -
TechnicalStandardTypeo -
TemporalBoundaryTypedfo -
TemporalWholePartTypedfo -
Thingifo -
TupleTypeif -
Typeif -
beforeAfterdfo -
descriptionSchemeInstancedfo -
endBoundarydfo -
individualPersonRolePartOfIndividualPerformero -
measureOfIndividualdf -
measureOfIndividualEndBoundarydfo -
measureOfIndividualStartBoundarydfo -
measureOfTypedf -
measureOfTypeConditiono -
measureOfTypeEndBoundaryTypedfo -
measureOfTypeStartBoundaryTypedfo -
namedBydfo -
namingSchemeInstancedfo -
overlapdfo -
powertypeInstanceif -
propertyOfIndividualdf -
propertyOfTypedf -
representationSchemeInstancedfo -
representedBydfo -
resourceInLocationTypeo -
rulePartOfMeasureTypeo -
skillOfPersonRoleTypeo -
startBoundarydfo -
superSubTypeifo -
temporalBoundarydfo -
temporalWholePartdfo -
tupleif -
wholePartifo
The model concept codes (o, n, np, s, df, dfo, if, ifo) are shown verbatim: the DoD workbook publishes no legend for them, and none is assigned here.