DEEPBOM

Optional metadata & lineage

Connect data context to model evidence.

Keep clinical definitions in OMOP. Connect data releases, cohorts, code and external reports through the same Evidence Link IR used by the Web workspace, CLI and MCP tools.

Start in the workspace

  1. Analyze your model and open Analysis palette → Metadata.
  2. Select OMOP template. Enter an institution-scoped instance identifier and a specific data release identifier.
  3. Export one selected CDM_SOURCE row as JSON and choose Import CDM_SOURCE JSON. OMOP 5.4 and 5.5 profiles are supported. No database credentials or patient records are needed.
  4. Use Add a connected record for cohort definitions, feature contracts, code, runs or quality/evaluation reports. Choose their explicit relationship.
  5. If checking files, supply their relative filenames and expected SHA-256 values, then choose those files.
  6. Select Check connections. Navigate the record list and relationship diagram, inspect individual checks, then save Evidence Link IR or linked CycloneDX.

Use the generic template for non-OMOP datasets. Imported OMOP metadata starts with an association only; training, evaluation and calibration roles must be explicitly declared.

Use the CLI

npx -y deepbom@1.109.0 audit model.onnx --metadata-template omop -o metadata.json
# Fill metadata.json with your identifiers and selected CDM_SOURCE row.
npx -y deepbom@1.109.0 audit model.onnx --metadata metadata.json --evidence-files ./evidence --output-format json --section evidence_link_ir -o links.json
npx -y deepbom@1.109.0 audit model.onnx --metadata metadata.json --evidence-files ./evidence --output-format cyclonedx -o model-linked.cdx.json

Exit 2 means an observed contradiction; exit 3 means incomplete checks. Exit 0 means no observed contradiction in the assessed scope. None authenticates training lineage. The metadata template is deliberately incomplete until you supply your context.

Connect through MCP

For the local deepbom_audit tool, supply metadata_template: "omop" to start, or metadata and evidence_files paths under the allowed roots. Select section: "evidence_link_ir" for the connection result.

ChatGPT and Claude widgets offer the same metadata workspace. Their explicit report button shares only counts and digests. Metadata rows remain in the widget unless you choose to share an exported file. Host download controls and app metadata refresh requirements still apply.

Interpret the evidence

Model bindingExact model file and artifact-set identities; optional Model IR digest.
File consistencyExpected digest compared with the actual supplied bytes. A manifest digest is not a database digest.
Reference resolutionTyped relationships, missing endpoints, BOM document revision and component identity.
Declared meaningTraining provenance, run occurrence, cohort correctness and report conclusions remain unverified declarations.
Unmapped fieldsPreserved and counted; never silently treated as verified.

Standards and limits

This is a DEEPBOM import profile, not a new OMOP table or vocabulary. CycloneDX 1.7 export uses standard data components, model dataset references and formulation workflows, with explicit DEEPBOM evidence properties. SPDX references are retained but the new relationship projection does not yet export SPDX 3. No FAIR conformance, clinical suitability or publisher authenticity is established.

External references are never fetched. Metadata/BOM JSON is limited to 2 MiB, supporting files to 32 MiB each and 64 MiB total. Inspect exports before sharing institution metadata.

Download the common JSON Schema · Architecture and field mapping · OMOP CDM_SOURCE specification · CLI reference