# Source register

Access date for all sources: 2026-09-22.

| ID | Primary or authoritative source | Material use | Limitation |
|---|---|---|---|
| S1 | JSON Schema, “JSON Schema Validation: A Vocabulary for Structural Validation of JSON,” Draft 2020-12, https://json-schema.org/draft/2020-12/json-schema-validation | Supports the limited distinction between validation assertions and annotations, including `default` as metadata and the default treatment of `format` as annotation rather than assertion. | Structural validation does not establish source truth, facility identity, operating authority, semantic compatibility or resulting business effect. Implementations vary. |
| S2 | OpenAPI Initiative, “OpenAPI Specification v3.2.1,” https://spec.openapis.org/oas/v3.2.1.html | Supports unique operation identifiers, required/optional parameter declarations, OpenAPI’s JSON Schema dialect and the limitation that schema checks do not catch every specification violation. | Interface-description standard, not an AI authorization system, self-storage operating standard or proof of runtime behavior. |
| S3 | OWASP GenAI Security Project, “LLM06:2025 Excessive Agency,” https://genai.owasp.org/llmrisk/llm062025-excessive-agency/ | Supports minimizing tool functionality, permissions and autonomy; human approval for high-impact actions; and downstream authorization rather than model-decided authority. | Community security guidance, not a regulatory standard, implementation validation, vulnerability finding or evidence about a named system. |
| S4 | National Institute of Standards and Technology, “Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile,” NIST AI 600-1, https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.600-1.pdf | Supports governance, change-management controls, monitoring, documentation and proportionate human oversight across generative-AI contexts. | Voluntary cross-sector profile. It does not prescribe the authored compatibility gate, approve an architecture or establish legal, safety, security or operational compliance. |

## Evidence boundary

The article proposes an architecture and operating record. It does not state that a named self-storage operator, facility, platform, provider or artificial-intelligence system uses the method. Basin Line Storage, its facilities, identifiers, tool versions, fields, approvals and outcomes are fictional. The package reports no deployment, customer, access change, message, dispatch, revenue, occupancy, performance, security, compliance, certification, acceptance, coverage or recognition result.
