You run a programme office against a date you did not set. Before the quarter your programme plan names an event repository, there is one fact worth checking with your own eyes, because every vendor conversation you are about to have either survives it or dies on it — and it takes ten minutes, because the specifications are public.
EPCIS 2.0 §7.2.2 defines an event in five dimensions: what, when, where, why, and how. Read the list. No performer is among them.
That is the whole claim, so here it is again with the section numbers in your hand rather than ours. The standard's event answers what (the EPCs or quantities observed), when (event time), where (read point and business location), why (business step, disposition, the transaction context), and how (sensor and condition data, new in 2.0). The party fields the standard does provide are organisation-grain: EPCIS §7.3.6.4 and CBV 2.0 §7.4.3 carry source and destination as parties to a business transfer, and CBV §8.7.1 identifies such a party by PGLN — a Party Global Location Number. A company's number.
So the standard can say, completely and conformantly: a company received a case at a dock at 06:12. It cannot say which person or which agent, standing at that dock at 06:12, performed the receiving — under whose authority, at what attestation grade. Not because anyone filled the field in badly, but because there is no field. A company doing a process is fully answered. A worker — or a software agent, or a robot — doing a task is structurally absent.
Structural absence is not a data-quality problem
This distinction decides how you evaluate every product in the category. A data-quality problem is fixable inside the standard: better discipline, better validation, a sharper implementation guide. A structural absence is not. There is no combination of conformant EPCIS 2.0 fields that answers "who performed this event" at the grain of a person or an agent — the specification's own party vocabulary tops out at the organisation. Any vendor telling you their EPCIS repository "captures who did it" is telling you one of three things: they stamp an org identifier and call it a who, they store a free-text initials column outside the record, or they have extended the standard and should be able to show you exactly where and how. Ask which. The answer sorts the category in one question.
The extension path, for the record, is the standard's own: EPCIS §6.3, §9.1 and §10.1.3 provide for namespaced user extensions that ride inside a conformant event. That is the sanctioned door — a superset of the standard that remains conformant, because the projection still validates against GS1's official pinned schema. Superset without conformance is a fork; conformance without the missing dimension is the status quo. The claim worth buying is both at once.
The answer, named — in two grains
Here is the shape of the answer, named plainly so you can hold every vendor to it — including us.
An event on this record carries two distinct identities that the standard has no room for. who is the attested observer: the human, the agent, or the embodied agent that performed the observation. capturedBy is the warrantor account: the party that stands behind the capture — whose key opened the door. They are never the same field and never collapse, because an agent may observe under an account it does not own, and a regulator asks both questions separately: who did it, and who stands behind the record. The observer identity resolves through id.org.ai — Agent. Human. Thing. — the same grain for a person, a piece of software, and a forklift.
And the third piece, easy to miss and load-bearing: party and organisation grain are derived at read time from grant chains, never stamped on the event. The event records what happened; who may read it as theirs is computed when they read it. That single property is what keeps ten years of history true through a reorg — a consequence worked in full in Reorg-Proof Records — and what keeps the observer's identity from collapsing into whichever company employed them that quarter. The two grains themselves are walked, scenario by scenario, in who Is Not capturedBy.
Why this lands on the programme office
Your symbology decision is made. Your data-pool decision is made. The decision your programme plan has not made is the event layer — where what your marks make readable actually gets recorded — and the missing performer is the fact that decides it. Every downstream question your programme will be asked in the next three years lands on it: the mock recall that stalls at a boundary because the record says a company received a case and nobody can say who; the audit that wants custody, not inventory; the customer mandate that asks you to prove a handoff, not assert one. The written read for the whole programme sits atop the Sunrise 2027 brief for brand owners — this post is the one fact underneath it.
The engineering half of the same fact — how a performer rides conformantly in a namespaced extension, validated against the pinned official schema — is written for your platform team at epcis.dev, the developer door of this same record.
The homework close
Do not take our word for any of this. EPCIS 2.0 §7.2.2 — the five dimensions. EPCIS §7.3.6.4, CBV 2.0 §7.4.3 and §8.7.1 — organisation-grain parties, identified by PGLN. EPCIS §6.3, §9.1, §10.1.3 — the extension path. Ten minutes, the specs are public, don't take our word for it.
Then bring the question to every vendor on your shortlist: show me the field where the performer lives, and show me the projection validating against the official schema afterward. The vendors who can answer both deserve the next meeting.
When the check is done, the door here is the get-started interview: your email first, then a short interview that branches on your answers — the manufacturer branch asks how you found out about your last quality problem at a co-packer and how long it took to know which lots, who holds your GTIN records today, and what already sits on your 2026 or 2027 plan with a date. We answer in writing.