Summary
draft-ietf-ivy-passive-network-inventory-01gives controllers a common YANG vocabulary for cables, child segments, endpoints, passive devices, ports, tags and locations. The draft also says these assets may have no management interface and leaves the methods for learning about them outside its scope.- A valid record therefore proves that a management system holds a structured claim, not that the physical object is present, correctly connected or ready for use. A separate observation-and-custody envelope should record how, when and by whom each consequential fact was established.
The quiet half of a network
Network management naturally privileges equipment that answers. A router exposes interfaces. A transceiver reports alarms. A controller can compare desired and operational state. Much of the path between those devices is quieter: ducts, cabinets, distribution frames, connectors, splitters, antennas, optical cables, individual fibre segments and splice points. They carry the service while offering no management session of their own.
The new IVY Working Group draft tries to make that quiet layer legible. Revision 00 became a working-group document on 9 September 2026, and revision 01 followed one day later. It is a Standards Track Internet-Draft, not an RFC or evidence that any operator has deployed the model. Its practical ambition is nevertheless clear: extend a network-wide inventory so that passive infrastructure can be described through a common interface rather than left in disconnected diagrams, spreadsheets and vendor systems.
That is useful work. A shared vocabulary can reduce translation between planning, field operations, assurance and higher-level controllers. It can expose relationships that were previously known only by a local naming convention. But common syntax does not eliminate the distance between an object and the claim made about it. For passive assets, that distance is the central governance problem.
What the model can say
The draft models cables, including ordered child cables that form a longer span. It can describe A and Z endpoints, cable type and role, length, fibre-core count, fibre type and attenuation. It also defines passive devices and ports, optional custom tags such as RFID or QR labels, and references to locations maintained by the related IVY location model.
These fields can answer valuable questions. Which segments supposedly form this route? What passive device should be in this enclosure? Which active component should sit at the far end? How many cores were recorded? Which cable was classified as access, distribution or backbone plant? A planning tool can combine those facts with topology and service data. A field team can start with a better map. An auditor can ask whether an asset exists in both the physical register and the service design.
Yet each answer contains an unstated verb: supposedly. The draft defines passive infrastructure as generally non-powered, non-communicating and not actively detectable or manageable. It explicitly says that the methods for learning about these devices are implementation-specific and outside scope. A row can be precise about length and endpoints while remaining silent about where the information came from.
The silence is not a reason to reject the model. It is a reason not to confuse the model with the evidence that populated it.
The controller is the last witness, not necessarily the first
The base IVY inventory document describes a read-only view of what a controller knows is actually installed. It also admits a familiar ambiguity: distinguishing an unreachable network element from one that has been removed depends on the discovery mechanism and sits outside that document. Passive assets make the same epistemic problem more severe. A cable cannot fail a heartbeat. A splitter cannot attest to its shelf. An unlit fibre does not announce whether it is spare, abandoned, cut or merely unused.
The controller may learn from a field survey, an as-built drawing, a contractor's completion package, a GIS database, a barcode scan, a work order or an inference from two active ports. Those sources are not equivalent.
A field inspection may establish present location but miss an underground route. An as-built file may capture design acceptance at a date while saying nothing about later emergency work. A label scan proves that a particular label was read; it does not prove the label was attached to the intended asset. An optical measurement can support continuity between endpoints without identifying every enclosure on the path. An inference from active equipment can show that some medium connects two ports while leaving the exact passive chain uncertain.
If all of those observations collapse into the same inventory fields, downstream users inherit confidence they cannot examine. The controller becomes the last witness in a long chain, and its tidy response can conceal how many human and technical transitions preceded it.
A UUID does not create custody
Identifiers are essential. The base model supplies a UUID, while the passive extension has cable and device identifiers and can carry custom tags. Stable names allow systems to join records without guessing. They can also create an illusion of permanence.
A UUID proves that one software object has a stable handle. An RFID or QR value proves, at most, that a tag value was recorded. Neither fact establishes that the tag is still attached, that two systems use it for the same physical item, or that the item remains in the recorded place. A replacement cable may inherit a label. One cable may acquire two tags after a merger. A contractor may refer to a whole sheath where the operator records individual segments. These are ordinary reconciliation problems, not accusations of negligence.
The right response is to preserve identity and observation separately. The inventory identifier says which claim is being discussed. The evidence record says what was observed, by what method, at what time and under which naming authority. When identities are merged or split, the history should survive rather than being overwritten by the latest convenient label.
Access control protects the statement, not its truth
The draft points to NETCONF and RESTCONF security and to the NETCONF Access Control Model. It warns that writable, creatable, deletable and readable nodes may be sensitive in some environments. Those are important controls. Physical routes, cabinet locations and connection maps can reveal operational vulnerabilities, and edit rights should be narrow.
But authorization answers a different question. It can show that an approved account submitted a change through a protected interface. It cannot show that the account holder saw the cable, that a contractor's drawing matched the final works or that a location reference remained current after a reroute. A perfectly authenticated stale statement is still stale.
This distinction matters because security dashboards often reward the evidence they can count. Transport encryption, access policy and change logs are visible. The missing field observation is harder to normalize. Governance fails when the measurable controls are allowed to stand in for the unmeasured fact.
The observation-and-custody envelope
Operators that use passive inventory for consequential decisions should attach a compact evidence envelope to each material claim or coherent group of claims. This is an editorial proposal, not a requirement in the IVY draft.
The envelope should first identify the asset and the exact fields it supports. Evidence for a location is not automatically evidence for fibre count, attenuation or endpoint connectivity. It should name the observation class: direct field inspection, tag scan, accepted as-built record, optical test, work-order closure, controller inference or another locally defined method.
Next come custody and time. Record the observing team or system at the minimum granularity needed for accountability, the observation time, the source artefact or protected digest, the naming authority in use and the point at which the result entered the shared inventory. If a contractor supplied the evidence and an operator accepted it, preserve both acts. Acceptance is a governance decision, not a retroactive transformation of supplied material into direct observation.
The envelope should then state scope and confidence. Was the enclosure opened? Were both endpoints observed? Was the underground route inferred from plans? Did the test establish continuity without physical identity? What freshness rule applies to this asset class? A cable in a controlled facility and a roadside cabinet exposed to repeated civil works need not share one inspection interval.
Finally, record reconciliation. A later observation may confirm, narrow or contradict the earlier claim. The inventory needs a visible discrepancy state, an owner, a bounded resolution date and references to decisions made while uncertainty remained. Correcting the current row should not erase the fact that a capacity plan, repair dispatch or audit relied on its previous state.
Presence, availability and authority are different
One physically present asset can be unavailable for service. A dark fibre may exist but be assigned elsewhere. A splitter may be installed but outside the operator's maintenance responsibility. A cable may connect the right buildings while individual cores terminate differently from the recorded plan. Conversely, a planned object can be legitimate inventory for construction without being present yet.
This is where status labels need discipline. Planned, installed, observed, accepted, in service, reserved, damaged, retired and removed describe different events and authorities. Treating them as one lifecycle sequence can make a commercial reservation look like physical readiness or make a completed work order look like independent inspection.
The minimum shared record should avoid claiming more than its evidence supports. Local systems may add richer state, but each promotion should identify the actor and basis. A planner can authorize construction. A contractor can report completion. An operator can accept the work. A technician can observe the asset. A service controller can confirm traffic. None of those acts silently performs the others.
Why tidy inventory acquires power
Once passive plant enters a normalized interface, it becomes attractive input for automation. Capacity models count available strands. Restoration tools select alternate paths. Procurement reconciles installed assets with invoices. Dig coordination identifies vulnerable corridors. Security teams restrict access to sensitive location data. Regulators and insurers may ask for evidence of resilience or maintenance.
Every use increases the cost of an unqualified row. The first-order harm is a wasted visit or an incorrect plan. The second-order harm appears when several systems copy the same assertion and seem to corroborate one another. The third-order harm arrives when a commercial, safety or regulatory decision can no longer reconstruct the observation from which the assertion began.
Replication is not independent evidence. Five databases that inherited one as-built drawing remain one source. A useful inventory service should expose lineage well enough that consumers can distinguish corroboration from multiplication.
Evidence need not become exposure
Accountability does not require publishing precise cable routes, enclosure photographs, access credentials or named staff. The evidence envelope can use protected references, role identifiers, coarse disclosure classes and cryptographic digests. Public or cross-organisational views may show that a field observation exists, its age, confidence class and accountable owner without revealing operationally sensitive detail.
That minimization is part of the design, not a later privacy patch. Passive inventory can reveal where physical disruption would have disproportionate effect. A system that improves internal truth while enlarging unnecessary external exposure has solved only half the problem.
A model should make its knowledge boundary visible
The current draft is openly unfinished. Its relationship-to-inventory, relationship-to-topology and operational-considerations sections have not yet been completed. That is normal for a new working-group document. It is also the right moment to ask how a consumer will distinguish modeled fact from evidence class, confidence and age.
The shared standard does not need to prescribe one inspection practice for every operator and asset. Heng Lu's minimum-specification principle points toward a narrower role: establish enough common structure to exchange the claim and its knowledge boundary, while leaving inspection cadence, acceptance roles and risk thresholds to accountable local institutions.
The Policy Mirror supplies the language test. “The inventory contains this cable,” “a contractor reported this cable,” “a technician observed its label,” “an optical test found continuity,” and “the operator may allocate this fibre” are not interchangeable sentences. A trustworthy interface should not make them look interchangeable merely because they can share one identifier.
Passive infrastructure will always depend more heavily on human custody than equipment that can speak for itself. The answer is not to wait for every duct and splice to become instrumented. It is to carry the observation with the record, keep uncertainty visible and require a fresh decision when the evidence is too old for the consequence at hand. A cable entry makes the network legible. Only evidence makes the entry usable as proof.
Sources
- Current passive network inventory draft
- Document history
- Revision 01 text
- Revision 00 text
- Official 00–01 diff
- Base network inventory draft record
- Base network inventory revision 18
- Network inventory location draft record
- Network inventory location revision 06
- RFC 8348: A YANG Data Model for Hardware Management
- RFC 8341: Network Configuration Access Control Model
- RFC 8342: Network Management Datastore Architecture
- RFC 8795: YANG Data Model for Traffic Engineering Topologies
- Heng Lu: The Policy Mirror
- Heng Lu: Minimum Initial Specification, Localized Future Decision, Voluntary Adoption
- Heng Lu: On Why BTW Media Exists
Member Briefing
Deeper Profile Context
Sign in with the right membership level to unlock the full briefing and source notes.
Only for Strategic Circle
Strategic Circle
Open to all readers. Unlock profile briefings after joining and signing in.
Join Strategic CircleOnly for Leadership Alliance
Leadership Alliance
For qualified IP-asset owners and management; sign in to unlock alliance briefings.
Join Leadership Alliance
