spec v0.2 draft · nineteen names on one page · drawn from the specification's data model
The data model as one picture. Read it left to right: the organisation and what it provides, the
pseudonymous worker and every record that hangs off that pseudonym, the shared definitions those records
point at, and on the right the report used for employer-visible aggregate results.
figure · the entity map, drawn for v0.1 and unchanged in v0.2seventeen entities · two reserved names
Individual instrument results are never employer-visible. Only the expressly classified individual-employer fields may be disclosed at individual grain under the specification's independent-legal-basis condition. The diagram does not grant permission to disclose a record.
one pseudonym, five records
Absence, occupational health, adjustment, observation and instrument
result all hang off WorkerPseudonym: opaque, per employer, banded demographics only. Nothing individual
is ever employer-visible at that grain.
one vocabulary for both sides
What a survey measures and what a benefit targets are tagged with the same
ConstructDomain, so provision and measurement can finally be read against each other.
Crosswalk maps it to the HSE Management Standards, ISO 45003 and the WHIU's reserved namespace.
one door out
Absence, outcomes, observations and benefit usage reach the employer only through
AggregateReport, with its floor, interval and suppression metadata, and from there into a
BenchmarkRelease with its composition disclosed.
The relationships are those of the specification's entity catalogue, section 2; the Mermaid source is
in the bundle. The entity table with each purpose and cardinality is on
Inside the standard; field tables, privacy classes and code lists are in the
full specification.