«OntoUML Advisor» Open the app →

OntoUML Advisor

A modelling assistant that helps you build sound conceptual models — and checks every step as you go.

1. Introduction

A conceptual model captures how a domain is put together: the kinds of things that exist in it, and the ways they relate. A hospital's model has patients, doctors, admissions, diagnoses; a library's has books, copies, loans, members. Getting that picture right — precise, consistent, and faithful to the real world — is the hard, valuable part of a great many software and data projects.

OntoUML is a modelling language designed for exactly this. Where an ordinary diagram lets you draw a box called "Student" and move on, OntoUML asks a sharper question: what sort of thing is a Student, really? Is "student" something a person simply is, permanently — or a role they play for a while and later leave behind? A model that answers those questions means one thing and one thing only, which is what lets people (and machines) reason about it with confidence.

That precision is powerful, and it is also easy to get subtly wrong. The rules that make an OntoUML model sound are interconnected: a single choice about one concept quietly constrains its parents, its children, and everything it connects to. Kept in your head, that web of consequences eventually slips — and the model silently stops meaning what you think it means.

The OntoUML Advisor carries that web for you. You build your model in plain conversation with an AI assistant — Claude or ChatGPT — and behind every change the Advisor re-checks the whole model and tells you, immediately, what your last move just broke and what it just fixed. Modelling becomes a dialogue in which each step is answered by its consequences, before you have moved on and forgotten why you made it.

Three things make it more than an automatic checker:

You do not need to be an OntoUML expert to start. A guided flow walks you through classifying each concept by asking simple questions, and a review flow reads back the whole model and talks you through anything worth a second look. This page then goes deeper: §2 is the complete, precise catalogue of every check the Advisor performs — and, in §2.7, of the ones it does not perform yet — for readers who want the formal detail; §3–§4 describe the features and what you can ask the Advisor to do; §5 shows how to connect it to your AI assistant.


2. The checks, formally

This section is a precise reference and assumes familiarity with OntoUML and its foundational ontology. Newcomers can skip it: the guided workflows in §4 apply these rules for you and explain each one in context as it comes up.

Every check falls into one of two kinds, and the Advisor never blurs them:

Error Question
What it means a violated constraint — the model is ill-founded a legal but statistically suspicious structure
Speech act a verdict a question only the modeller can settle
What the Advisor does reports it, and may offer a correction asks, and proposes nothing until you answer — it never silently "fixes" one

Throughout, a concept is treated as fully classified when it, and everything it depends on, has been given a recognized OntoUML classification — the precondition under which the deeper rules can be evaluated at all. Checks that need that precondition apply only where it holds; this is the "stays quiet when it cannot be sure" commitment in practice.

Sources

Every check below is traceable to one of four bodies of reference, and each carries its own citation in the finding it produces — that attributability is the point, not a formality.

These sources do not agree on every point, and the Advisor does not paper over the differences: where it takes a contested reading, the finding says which one and why. Where the natures involved cannot yet be determined, it takes none and stays silent.

2.1 Classification (9)

These ensure every element is a genuine OntoUML element — one the language can actually interpret — before any deeper rule tries to read it. Source: the OntoUML specification (every model element carries a stereotype from the metamodel).

class-without-stereotype · warning A class that bears no stereotype. Without one it has no ontological nature — we cannot tell whether its instances obey a principle of identity, whether the type is essential or contingent, or whether it denotes an object, a link, or a property. Everything that depends on it becomes unreadable too.

class-with-unknown-stereotype · warning A class whose stereotype is not part of OntoUML 2 (for example one inherited from an older version). To the current language this is as unreadable as no stereotype at all — the intent is present, but the vocabulary must be brought up to date.

relation-without-stereotype · warning A relation with no stereotype. A relation's stereotype is what it asserts — a dependence, a part-whole tie, a factual link. Without it, the relation carries no ontological commitment.

relation-with-unknown-stereotype · warning A relation whose stereotype is not part of OntoUML 2. Until it is brought up to date, the language cannot know what the relation asserts.

enumeration-without-literals · warning An enumeration that lists fewer than two values. Empty, it admits none, so every attribute typed by it is uninstantiable. With exactly one it is no better off: every instance of every such attribute necessarily holds that value, so the attribute draws no distinction and records nothing — a constant wearing the shape of a type.

enumeration-with-attributes · error An enumeration that also declares attributes. An enumeration is exhausted by its list of values: to know which value something has is to know everything it can tell you. An attribute would give each value an inside — parts readable independently of the value itself — which is a structured value space, and that is what a «datatype» is.

literals-outside-enumeration · error Enumerated values on something that is not an enumeration. To list values is to say that these, and nothing else, are the things of this type. Anything but an enumeration has an open extension — new instances may come into being — so listing values on it asserts a closure the stereotype denies.

class-restricted-to-incompatible · error A class whose declared ontological natures its stereotype does not admit — a «kind» declared to classify relators, or a «subkind» spanning two natures where a sortal must commit to one. A stereotype is not a label: it settles what sort of thing the instances are, so the two statements contradict each other and neither can be relied on. The damage does not stop at the class: declared natures are inherited by every subtype that states none, so one bad value silently misinforms every parthood and relation judgement below it. Building such a class through the Advisor is refused outright; this reports the ones that arrive by import.

non-sortal-not-abstract · warning A general type — one meant to span several identities — left concrete where the model marks others abstract. Nothing is a business partner simpliciter: whatever is one is one by being a person, or an organization, or something else that carries its own criterion of identity. So nothing instantiates such a type directly, and marking it abstract is how the model says so.

The condition in italics is deliberate and narrower than the reference rule. The marker has no "not stated" value, and most tools write the unticked default on every class they export — so read naively, this check reports tooling boilerplate rather than anything you decided. It therefore asks first for evidence that this model uses abstractness on general types at all, and speaks only where some of them are marked and others are not. That is an inconsistency you can act on; a model that never uses the marker is told nothing.

2.2 Specialization: identity, rigidity and taxonomy (14)

Source: Guizzardi 2005, Ontological Foundations for Structural Conceptual Models, ch. 4; for the three checks on specialization between relations, Fonseca et al., Relations in Ontology-Driven Conceptual Modeling, ER 2019, §2, and UML 2.5.1 §11.5 and §9.5.3.

sortal-without-identity-provider · error A sortal with no ultimate type behind it. Every sortal classifies individuals that obey a principle of identity, supplied by a single ultimate type («kind», «collective», «quantity», «relator», «mode», «quality»). With none, "the same individual over time" is undefined and the type classifies nothing determinate.

sortal-with-multiple-identity-providers · error A sortal inheriting from more than one ultimate type. An individual obeys a single principle of identity; requiring two incompatible criteria of sameness leaves the type necessarily empty.

ultimate-sortal-specializes-ultimate-sortal · error An ultimate type that specializes another ultimate type. An ultimate type defines a principle of identity and cannot inherit a second; if the specialization is intended, the subtype is a «subkind», which inherits the principle without supplying a new one.

non-sortal-specializes-sortal · error A non-sortal specializing a sortal. A non-sortal gathers individuals of different identities; inheriting one sortal's single principle would empty it of its purpose.

rigid-specializes-anti-rigid · error A rigid (or semi-rigid) type specializing an anti-rigid one. The rigid type applies necessarily, the anti-rigid one only contingently; an instance would have to both survive the change and perish with it. The contradiction is immediate.

generalization-widens-natures · error A subtype whose ontological natures the supertype does not admit — a «relator» specializing a «kind», a link that is also an object. A generalization says every instance of the subtype is an instance of the supertype, and nature is not a label but a claim about what sort of thing an individual is: an object, a link, a property, an occurrence, and nothing is two of these. Invisible to the identity and rigidity checks above, since a «relator» and a «kind» are both rigid sortals. Where a type's natures cannot yet be determined, nothing is reported — a deliberate divergence from the reference implementations, which treat an undetermined nature as an error in its own right.

class-is-its-own-ancestor · error A class reachable from itself through generalizations, with its own message for the simpler slip of a class declared to specialize itself. Every type on such a circle is a subtype of the next and, going round, of itself, so their extensions coincide exactly and none of the specializations asserts anything. The damage is not only ontological: every check that walks the taxonomy looking for an identity provider or an anti-rigid ancestor gives up on a circular chain, so one cycle silences much of the rest of the engine.

generalization-metatype-mismatch · error A generalization between a class and a relation. A class denotes a type of individual, a relation a type of link between individuals; the containment a generalization asserts is not false between them but unstatable, and nothing further can be concluded until both ends are of the same metatype.

abstract-taxonomy-mixed · error A generalization crossing the line between value spaces and the entities that have values. «abstract», «datatype» and «enumeration» model the structures in which qualities take their values — a colour, a date, a temperature scale — not types of endurant, and they do not share a taxonomy with them. Within the abstract side the same discipline holds one level down: a «datatype» is a determinate value space, so only another «datatype» refines it, whereas «abstract» is the open category that admits them all.

enumeration-specialized · error An «enumeration» given a subtype. An enumeration is its list of values and has no structure beyond them, so there is nothing for a subtype to add; what one could do is hold fewer of the values, and a type whose values are a subset of another's is a constraint on the first, not a kind of it. Note the asymmetry, which is deliberate: an enumeration may perfectly well sit under an «abstract».

perdurant-taxonomy-mixed · error Something that is not an «event» under an «event», or not a «situation» under a «situation». An endurant exists: it is wholly present whenever it is present, and persists through change. A perdurant occurs: it unfolds in time and has temporal parts, so it is never wholly present at any instant and cannot change, only differ from one of its own parts to the next. To be a subtype of an event is to be a kind of occurrence, and nothing that exists is one.

relation-generalization-stereotype-mismatch · error A relation specializing a relation of another stereotype. A relation stereotype names what makes the relation hold: a «comparative» holds in virtue of qualities of the relata alone, a «material» in virtue of a relator, the dependence stereotypes are existential dependences, the parthoods are told apart by the natures of their wholes, the event stereotypes by the natures of their ends. Those grounds partition relations, and a generalization says every link of the specific is a link of the general; across stereotypes that containment is contradictory. The rule is identity of stereotype, for all nineteen. Silent while either relation is unstereotyped, and nothing further is concluded about the generalization until the stereotypes agree. Declared upstream as generalization_incompatible_relation_type and never raised; the argument is the ER 2019 paper's, which places every stereotype in one cell of its internal/external and descriptive/non-descriptive distinctions.

relation-generalization-widens-end · error A specializing relation with an end that is neither the corresponding end of the general relation nor a subtype of it. Every pair the specific relates is a pair the general relates, so each member is an instance of the general's corresponding end. Equality is enough: a subset over the same pair of types is a specialization too. Ends correspond by position; only for «material» and «comparative», whose drawn direction is a convention, is a relation drawn the other way round read as such — a «mediation» runs from its relator and a parthood from its part, so crossing those is a defect. Judged on declared descent alone, so it does not wait for the ends to be classified. Declared upstream as generalization_inconsistent_specialization and never raised.

relation-generalization-loosens-cardinality · error A specializing relation whose end allows more than the corresponding end of the general. The links of the specific are links of the general, so no individual can have more of them than the general's end permits; a larger upper bound is a possibility the model's own supertype rules out, never witnessed and misleading on its own. Lower bounds are free — a subset need not cover — and are not judged. Checked only once the ends align, since the correspondence is what it compares.

2.3 Dependence: moments, relators, material relations (6)

Source: Guizzardi 2005, ch. 5 and §6.3; the OntoUML specification on «relator», «role» and «material»; RefOntoUML's constraints on «mediation».

relator-mediates-nothing · error A relator connected to no mediation at all. A relator is the binding of the entities it holds together; with none named, the model asserts a thing that exists in virtue of others and says which others nowhere.

relator-without-two-mediations · error A relator whose mediations do not oblige it to bind two entities — the sum of their minimum cardinalities falls below 2. The claim is about what must exist, not what may: mediations that are all optional describe something that could bind nothing at all, which is a mode, not a relator. Raising a lower bound is as much a fix as adding a mediation. Mediations declared on an ancestor relator count, as the specification requires.

role-without-relational-dependence · error A role bound by no relation its instances must necessarily stand in. A role's instantiation depends on a relation — student because enrolled, employee because under contract — and the dependence must be obligatory to be one at all: where the opposite end may be empty, nothing says when the role begins or ends. If the change is intrinsic instead, the type is a «phase». «mediation», «material» and the parthood relations all count; for a «historicalRole», so does «historicalDependence», since such a role is played in virtue of an event that is over.

mediation-mediated-end-optional · error A mediation whose mediated end may be empty — a lower bound of 0 on the entity side. A mediation is the existential dependence of the relator on what it connects, and dependence is not optional: an end that may stand empty says the relator exists whether or not anything is there, which is to say it does not depend on it, which is to say this is not a mediation. Either the entity is required and the bound is 1, or the link is something else — the agent of the act that created the relator, an attribute, a material relation of its own. This is RefOntoUML's own MediationConstraint2; relator-without-two-mediations sums the same bounds across a relator, and this one names the relation the fix belongs to.

characterization-bearer-not-exactly-one · error A characterization whose bearer end is not exactly 1..1. An intrinsic moment inheres in a single bearer and depends on it existentially — born with it, gone with it; any other cardinality describes a moment with no bearer, or one shared, which inherence rules out.

moment-without-characterization · warning A mode or quality that characterizes no bearer. A moment does not exist on its own; with no characterization naming its bearer, the model asserts a property that is the property of nothing.

2.4 Relations: what may sit at each end (4)

Source: the OntoUML specification's relationship pages, and Fonseca et al., Relations in Ontology-Driven Conceptual Modeling (ER 2019).

relation-end-inadmissible-nature · error A relation one of whose ends is of a nature that stereotype does not admit — a «participation» by something that does not occur, a «characterization» starting from a relator, a «triggers» between two endurants. Each of the eighteen relation stereotypes constrains the natures of both its ends, and those constraints are not a convention about how the relation is drawn: they are what makes the assertion intelligible at all. This single check covers all eighteen, including the whole perdurant family — participation, event parthood, manifestation, creation, termination, brings-about, triggers and historical dependence — and it stays silent wherever a nature cannot yet be determined.

derivation-not-from-relation-to-class · error A «derivation» that does not run from a relation to a class. A derivation is not a link between two entities but the statement that one relation holds because of something else in the model: its source is the relation being explained, its target the class whose instances explain it. Drawn between two classes it makes a different claim, not a weaker one.

derivation-truthmaker-not-relator · error A «material» relation derived from something that is not a relator. What makes a material relation true is a third thing that binds the relata — the marriage that makes two people married. That is what a relator is; anything else is not the kind of entity that could make a relation hold.

material-without-derivation · warning A «material» relation with no «derivation». A material relation is derived, not primitive: it holds because a relator exists and binds the relata. Reifying that relator is the move UFO exists to make — it is what gives the link a lifetime and properties of its own, so one can say when a marriage began. Asserted alone, the relation states the fact and withholds what makes it one. A warning rather than an error: the model is under-specified, not ill-founded, and every model passes through this state.

2.5 High-order types (6)

Ordinary types are instantiated by individuals: Lion has particular lions as its instances. A high-order type is instantiated by types: Species has Lion, Tiger and the rest as its instances, and the individual lions are two levels below it rather than one. The order of a class records which level it sits on — 1 for the ordinary case, 2 for a type whose instances are first-order types, and orderless for one that admits instances of any order.

These six checks are all versions of one demand: the order a class declares, the natures it declares, and the stereotype it carries must agree about which level it sits on. Each of them settles that same question, so none can be read as an independent label. Source: the OntoUML validator; and Guizzardi et al., Endurant Types in Ontology-Driven Conceptual Modeling (ER 2018).

class-order-incompatible-with-stereotype · error A stereotype that classifies individuals, on a class declared above the first order — or a «type» declared first-order. An ultimate sortal supplies a principle of identity for particular things, an «event» classifies occurrences, a «datatype» classifies values; none can have types as instances. Note what is deliberately absent: a «subkind», a «role», a «phase» or a general type may perfectly well be high-order, since each takes its subject matter from what it specializes.

class-order-incompatible-with-natures · error A class whose declared natures and declared order disagree. If everything falling under it is a type, its instances are one level up and it is not first-order. If it gathers types and individuals, its instances sit on more than one level, and no single order describes that — which is what orderless is for.

generalization-across-orders · error A specialization between classes of different orders. Instances of a first-order class are individuals, instances of a second-order one are types; those are not the same population, so the containment a generalization asserts is empty. What relates one level to the next is instantiation, not specialization — the difference between "a lion is a kind of animal" and "Lion is an instance of Species".

instantiation-across-orders · error An instantiation that does not go up exactly one level. Lion instantiates Species, and particular lions instantiate Lion; no individual lion instantiates Species, because Species has types as its instances and a lion is not a type. Skipping a level does not shorten the path — it asserts a membership of the wrong sort of thing. An orderless type sits on no level, so it can only instantiate another orderless type.

powertype-malformed · error A powertype whose instances are not declared to be types, or which carries a stereotype that can come and go. A powertype is more than a high-order type: Species has some animal types as instances, whereas the powertype of Animal has every subtype of Animal. So its instances are types; and being the totality of one base type's subtypes is not something a class does for a while and then stops doing, so the stereotype must be a permanent one.

powertype-with-several-base-types · error A powertype instantiated from two base types. Each names a different totality — every subtype of the one, every subtype of the other — and a single class is the powertype of neither.

2.6 Partitions, phases and categorizers (7)

Source: Guizzardi 2005, ch. 4; the OntoUML validator; and Guizzardi et al., Endurant Types in Ontology-Driven Conceptual Modeling (ER 2018) for categorizers.

phase-outside-partition · error A «phase» — or, on exactly the same argument, a «phaseMixin» — belonging to no disjoint and complete partition. The states of a type exhaust its possibilities and exclude one another: at any instant an instance is in exactly one of them, which is what a partition expresses. Standing alone, the type leaves open the one question a state must answer — what an instance is when it is not in this one. That a phase mixin spans several identity principles changes nothing: it is still a contingent state, and still one of a set.

generalization-set-mixed-stereotypes · warning A partition by state that also contains subtypes of another kind. Two criteria of division coexist without saying which prevails, and the completeness of the set becomes uninterpretable: complete with respect to which division? Applies to phase mixins on the same terms as to phases — the criterion is the state, not the identity principle.

generalization-set-mixed-generals · error A generalization set whose generalizations divide different general classes. Its disjointness and completeness are claims about one type's extension; with several, neither claim has a determinate subject — the flags are not false but unreadable. Every check that consults them, the phase-partition check included, declines to conclude about such a set until it is repaired, so a broken set cannot silently vouch for a phase.

A generalization set may also name a categorizer: the higher-order type whose instances are the subtypes in the set. Species categorizes the division of Animal into Lion, Tiger and the rest. It is the construct that ties an ordinary taxonomy to the high-order layer of §2.5, and everything below follows from that one sentence.

categorizer-not-high-order · error A categorizer whose instances are declared to be individuals rather than types. Its instances are the subtypes in the set, so a categorizer instantiated by individuals would sit one level below what it is supposed to be classifying.

categorizer-is-powertype · error A categorizer also declared a powertype. A powertype has all the specializations of its base type as instances; a categorizer has the ones gathered in this set. Asserting both says the set contains every possible subtype of the general class — not merely the ones modelled, but the ones nobody has thought of, which is far stronger than a complete partition.

categorizer-without-instantiation · error A categorizer the general class does not instantiate. To name a categorizer is to say the subtypes are its instances, and thereby that the general class is of the sort it classifies; the instantiation — Animal instantiates Species — is what records that. Without it the model asserts a categorizer and withholds the relation that connects the two levels it was introduced to connect.

categorizer-cardinality-contradicts-flags · error The set's disjointness and completeness disagreeing with the cardinality of that instantiation. The two state one fact twice: completeness says every instance of the general class falls under some subtype — which is to say it instantiates at least one categorizer instance, so the lower bound cannot be zero. Overlap says some instance falls under two subtypes at once — which is to say it instantiates more than one, so the upper bound cannot be one.

2.7 Parthood (8)

Source: Guizzardi 2005, ch. 6. Each of these speaks only on proof — it fires only when an end's nature is known to be incompatible, never when it is merely undetermined.

component-of-not-functional-complex · error A «componentOf» whose ends are not both functional complexes. «componentOf» expresses a part fulfilling a determinate function within a whole; for a member of a collective use «memberOf», for a portion of matter «subQuantityOf».

member-of-whole-not-collective · error A «memberOf» whose whole is not a collective. Membership is in a collective, whose members play the same undifferentiated role; a whole that differentiates its parts by function is a functional complex and wants «componentOf».

homogeneous-parthood-mismatch · error A «subCollectionOf» (resp. «subQuantityOf») whose ends are not both collectives (resp. quantities). These relations are homogeneous: a sub-collection is itself a collection, a portion of matter is itself matter — both ends share the whole's nature.

sub-quantity-part-end-not-exactly-one · error A «subQuantityOf» whose part side is not exactly 1..1. A quantity is individuated by the matter it consists of, so a portion of it is a portion of that whole and of no other — the alcohol in this glass of wine is not the alcohol in another. Not "at most one", which would allow a super-quantity missing matter it is made of; not "several", which would put one portion inside two wholes at once.

sub-quantity-shared · error A «subQuantityOf» declared shareable. The same claim seen from the other side: a shared aggregation says the part may belong to several wholes, and the same matter in another whole would be another portion. Where the aggregation was never stated at all, nothing is reported — that is an absence of information, not a claim.

sub-collection-part-end-not-at-most-one · error A «subCollectionOf» whose part side admits more than one whole. A collective is individuated by what it collects, so a sub-collection under two collectives would be counted in the membership of both. Weaker than the quantity case: unlike a portion of matter, a sub-collection may belong to no collective at all, which is why this bounds the maximum and leaves the minimum free.

weak-supplementation · warning A whole whose parthood relations do not oblige it to have two parts, counting the minimum cardinalities across all of them. The one axiom every theory of parthood accepts: a whole with exactly one part is that part under a second name, and the relation asserts nothing. Computed per whole, never per relation — a car with a single engine is fine as long as it also has wheels. A warning rather than an error because the other parts may simply not be declared yet: only a reading that took the list of parts to be closed could call the model ill-founded.

parthood-cycle · error Parthood running in a circle that the cardinalities require — every step obliging the whole to have at least one part of the next type. An instance would need a part, which would need a part, without end, and parthood is well-founded. Every type on the circle has a necessarily empty extension. Note what is not reported: a recursive structure whose parts are optional, such as a folder that may contain folders, is a legitimate model and stays silent. What is impossible is requiring the descent — which is why a self-loop is neither privileged nor condemned here, only judged by the same test as any longer circle.

2.8 Suspicious patterns (20 questions)

The complete established catalogue of OntoUML anti-patterns, all twenty. Each is raised as a question, never a verdict — the structure is legal, and only you can say whether it is what you meant.

Two of them are drawn slightly tighter than the published condition, because the published one fires on most well-made models and an advisor that does that stops being read. Each says so below, with what was added and why.

Wherever a question below speaks of a relator, it means one by nature: a «relator», or a «subkind» or «phase» specializing one, whose own mediations are as much its own as its parent's are. A relator whose nature cannot yet be read — under an unclassified ancestor — is left alone.

RelOver — a relator that could join an entity to itself. Its mediated types may overlap, so nothing stops one individual from occupying two ends of the same relator — being both employer and employee of one contract, or married to itself. Is that possible here, and intended?

RelRig — a relator tied to a permanent type. Mediating a rigid type makes taking part in the link part of what the entity is, so it could not leave without ceasing to exist. Is this link truly essential to the entity, or merely something it takes on for a time? As in the reference implementation, the permanent type is a substantial — a «kind», «collective», «quantity», «subkind» or «category»; a relator that mediates another relator, a mode or a quality is not asked this. Nor is a mediation whose relator end is declared read-only: that is the modeller saying the link is essential, which is the answer.

FreeRole — a sub-role with nothing of its own to trigger it. It specializes a grounded role but adds no relation of its own, so it carries the exact same instantiation condition as its parent. What decides that an entity is in this sub-role rather than simply in the parent?

DepPhase — a phase that behaves like a role. It is connected to a relation, yet phases are meant to change through an intrinsic property. Does this change come from within the entity, or from a relation to something outside it?

UndefPhase — a phase partition with nothing to vary. Its parent has no intrinsic property at all, so nothing could ground the passage from one phase to the next. Which property does this change of phase actually rest on?

HomoFunc — a "whole" made of identical, interchangeable parts. A functional complex owes its cohesion to parts playing different roles; uniform, required-in-number parts look instead like a collection. Is this really a collective rather than a functional complex?

MixIden — a general type that gathers only one kind after all. A type meant to span several identities has subtypes that all share a single one, so it gathers nothing that one identity does not already. Which other kinds of entity should this type bring together?

BinOver — a relation whose two ends could be the same individual. The end types are the same, one specializes the other, or they share a supertype with nothing declared disjoint — so the relation may hold between something and itself. Can one entity sit at both ends here, and is that intended?

PartOver — one part, several wholes that may be the same thing. The whole types overlap, so one individual can be several of them at once and hold the same part more than once over. Can one individual be several of these wholes — and should it then hold this part several times?

WholeOver — one whole, several part types that may be the same thing. The mirror image: one individual can fill two distinct part positions inside a single whole — the same person as both pilot and navigator of one flight. May one individual play two of these part roles at once?

RelComp — a relation that may already follow from another. A first relation reaches several instances of a type, and a second relates those instances to one another — the classic shape of a relation that ought to be derived rather than asserted. Is one of these the composition of the other?

RelSpec — a narrower relation that does not say it is one. Both its ends are subtypes of the corresponding ends of another relation of the same kind, yet no specialization, subsetting or disjointness is declared between them. Is this relation a specialization of that one — and if so, why is it not modelled?

Tighter than published: the two relations must carry the same stereotype (a relation can only specialize one it is compatible with) and at least one end must narrow strictly — where both relations connect the very same types, neither is the specialization of the other, and the catalogue discourages its own remedies in that case.

MultDep — a type depending on several unrelated links at once. Two relators mediate it, and neither specializes the other, so every instance must bear both dependencies together. Are these dependencies genuinely independent, or is this one role conflating several?

RepRel — the same individuals bound twice over. Every mediation allows more than one instance of the relator per entity, so the cardinalities permit two marriages between the same two people. Can that happen — and if so, what distinguishes them?

GSRig — one division doing two jobs. A permanent type is divided into subtypes some of which are essential to their instances and some merely contingent — what a thing is and what it happens to be doing, in one set. Do these subtypes really partition the same thing?

MixRig — a mixin that does not mix. Its subtypes are all permanent, or all contingent, so the one distinction the «mixin» stereotype exists to draw goes undrawn — it is a «category» or a «roleMixin». Which other instances is this mixin meant to gather?

HetColl — a collection whose members are not alike. Members of two or more different types are, on the face of it, not interchangeable — each is there for its own reason, which is what a functional complex is. Are these members really interchangeable?

DecInt — a type that may be only the overlap of its parents. It specializes two types that are instantiable in their own right and already exhausted by the subtypes they declare, so its extension is no more than what they have in common. Is this a type in its own right, or an intersection that should be derived?

ImpAbs — a count that cannot be broken down. An end admits several instances of a type whose subtypes are known and exhaustive, so the model says how many in total and nothing about how many of each — "2..4 wheels" cannot say that exactly one is the spare. How many of each subtype may be connected, or is the abstraction deliberate?

Tighter than published: the published condition needs only that the type have two subtypes, which matches a great deal of perfectly good modelling. We additionally require the subtypes to be declared complete — the model has claimed to know them all, and so is in a position to count them one by one.

UndefFormal — a comparison with nothing to compare. A comparative relation holds in virtue of the intrinsic properties of its relata; neither end has any, on itself or on an ancestor, so nothing in the model could ever settle whether it holds. Which qualities is this comparison supposed to rest on?

Note: the catalogue names this for «formal», which OntoUML 2 split into «comparative» and «material». «comparative» is the half that inherits this grounding condition; a model still carrying a literal «formal» is reported by relation-with-unknown-stereotype instead.

2.9 Planned — not yet implemented

Nothing in this subsection runs today. These checks are on the roadmap; the Advisor does not report any of them, and a model that would violate one will pass in silence.

They are published here because silence is easy to misread as approval. §2.1–§2.7 are a subset of OntoUML, not the whole of it, and you are entitled to know where the coverage currently stops. §2.8, the anti-pattern catalogue, is now complete.

Parthood

Specialization and taxonomy

Classes


3. What makes the advice trustworthy


4. What you can ask it to do

You never call these directly — your AI assistant does, on your behalf, as the conversation calls for it. They are listed so you know what the Advisor is capable of.

Build and change the model — each answers with the findings it changed, and can record your reason: create a class, set or change a stereotype, rename, delete, add a generalization, group generalizations into a set, add a relation, set a cardinality, mark one end of a relation as depended upon, add an attribute, add an enumeration value, and undo.

Three further properties of a class are not settled by its stereotype, and can be set on their own: whether it is abstract (it has no direct instances — every general type that spans several identities is), its order (an ordinary type is instantiated by individuals; a higher-order one, such as Species, is instantiated by types), and whether it is a powertype (a higher-order type having every specialization of one base type as an instance).

Two further things can be said that the stereotypes alone do not say. A relation end can be marked as one the other end existentially depends on: on a part end that is what makes the part essential — a portion of wine belongs to its quantity necessarily, since separating it destroys the whole and makes a new one. And an attribute of an event can be marked «begin» or «end»: not a start date on a record, but the instant at which the occurrence itself comes into being, and the one at which it ceases to. An endurant has no beginning in that sense — it is created by an event, which is a different claim.

Read and get advice:

Capability What it gives you
Render model the whole model as compact, readable text
Draw the model a class diagram, with the classes a finding names styled apart — the diagnosis as a picture rather than a list
Find elements search by name or stereotype
Describe element one element's detail, findings, and history
Validate the complete diagnosis of the model
Explain the reason, source, and possible fixes behind one finding
Apply fix carry out a proposed correction
Why the recorded intent behind an element
Possible relations the relations that are admissible between two concepts, and why
Profile model how much of the model carries each stereotype, beside the same share across the 195 catalogue models — what stands out, with what usually explains it

Guided workflows. Two flows do the heavy lifting for newcomers:

The Advisor supplies the method; your assistant conducts the conversation.


5. Using it with your AI assistant

The Advisor is a hosted service. You do not install or run anything — you connect your AI assistant to it once, sign in, and start modelling in plain language.

It works with any assistant that supports remote MCP connectors, including Claude (Desktop, Web, and Code) and ChatGPT.

The production endpoint is:

https://onto-uml-advisor.semantical.cc/mcp
  1. Add the connector. In your assistant's settings, add a new remote/custom connector and point it at https://onto-uml-advisor.semantical.cc/mcp.
  2. Sign in. The connector will send you through a normal sign-in the first time. Your identity is what keeps your models private and separate from everyone else's.
  3. Start modelling. Ask the assistant to create a project, then describe your domain. Invoke Classify a concept to be walked through each new type, and Review the model whenever you want a full pass. Every change comes back with what it broke and what it fixed.

That is the whole setup: one connector, one sign-in, then a conversation. The Advisor watches every step so that the model you finish with is one you can trust.


6. Looking at your model yourself

A conversation is a good way to build a model and a poor way to take one in at a glance. The Advisor also serves a page for that:

https://onto-uml-advisor.semantical.cc/app

Sign in with the same account your assistant uses, and you get your models laid out to be read: the diagram, with the classes a finding names marked apart, so the diagnosis is a picture rather than a list; every finding with the reasoning behind it and the source it rests on; the model's own contents, every type and relation, grouped the way the theory groups them; and, for any element you pick, what it is and why it is there — the reason recorded at the moment it was created.

When a model has nothing wrong with it, the page says so and says what looked: how many UFO constraints and how many suspicious patterns were checked against it, and that none holds. An all-clear means nothing unless you know what was examined.

And it keeps the account of how the model was built. Every change your assistant makes is recorded with the reason given at the time, and the journal lays those out in order — not a log of operations, but the thinking, in the words it was written in. It is the answer to “why on earth did I model it like that?”, six months later, when nobody remembers.

Beside each decision is what it did to the model: what it repaired, and what it broke. That is the Advisor’s own answer at the moment the change was made, kept exactly as it was given rather than worked out again afterwards — the catalogue of checks grows, and a later reckoning would credit your decision with advice nobody had yet given you. Entries made before the Advisor began keeping this say so, rather than appearing to have broken nothing.

Each entry can also be opened to show what the change did to the model itself — which types, relations and generalizations were added, removed or altered, in words — and the model as it stood just before and just after, as the same text your assistant reads. This is read from the model’s own history only when you ask, so the account stays fast. It is the third fact of a decision, beside why it was made and what the Advisor said.

The page only reads. Nothing on it changes a model. Every edit goes through your assistant, where it is recorded with the reason for it — and a change made through a web form would have no reason to record, which would leave a hole in the very history this page exists to show you.

Your model stays here. The diagram is drawn in your own browser: it is never sent to a diagram service, and this page loads nothing from anywhere else.