Skip to content

Authority Bundle, format v1 (draft)

Status: draft, XAO version 0.9. Produced by Oversee, Authority model, Authority Bundle and by GET /api/sentinel/enforcement/authority/model/bundle (workspace admins).

The Authority Bundle is the whole workspace as one signed document of the eight primitives: who acts, what authority is held and by whom, what can be done, what is touched, what it serves, what bounds it, what happened, and what proves it, with the findings the model raised and the invariants it holds to. A customer's own systems (a GRC tool, a SIEM, an archive) can hold the same model as the Authorisation Layer and check the document offline, without an account and without trusting Xybern.

Key Meaning
format "xybern-authority-bundle-v1"
xao_version The ontology version the bundle was shaped under
workspace {id, name}
exported_at, exported_by When and by whom
charter {hash, signed_by, signed_at, mandates} of the Charter in force
principal Every registered agent: {kind, id, name, framework, active, trust_state, acts_only_with_lent_authority, capabilities, fingerprint, did, registered_at, passport: {id, version, hash} or null}
authority Every authority held by an active agent, once, as the Authority Slice publishes it (kind, id, issuer, grants, denies, not_before, expires_at, depth, parent_id, status, mode, constraints, intent_id) plus holders: the agents that hold it
capability Every action type performed in the last 30 days or declared by an agent: {action_type, family, performed_by, declared_by, decisions_30d}
resource Every resource class known or touched: {class, source, personal_data, touched_30d}
intent Active and pending missions ({kind: "mission", id, agent_id, objective, status, mode, expires_at, hash}) and running sessions ({kind: "session", id, agent_id, label, status, budgets, started_at})
constraint Enabled rules ({kind: "rule", id, name, type, decision, action_types, agent_id, department_id, mode, priority, conditions_hash}), the communication default and rules, and the budgets on lent authority
effect A summary of the last 30 days: decisions, by decision and by action type, all-time count, last decision time. Decisions themselves are separately signed receipts and are not repeated here
evidence Counts of sealed receipts, stamps, attestations, co-authorisations and passports, the receipt format and where to verify one
findings What the model says is missing, as on the page: {id, kind, primitive, severity, sentence, subjects}
invariants The invariant catalogue: {id, name, version, statement, plain}
names Agent id to name, so the document reads without a lookup
public_keys The issuer's published keys {key_id, algorithm, public_key_pem, status}
bundle_hash Hex SHA-256 of the canonical body without bundle_hash and signature
signature {algorithm: "ecdsa-p256-sha256", signed: "bundle_hash", key_id, value}: ECDSA P-256 over SHA-256 of the bundle_hash hex string (UTF-8), DER, base64, the scheme the Provenance Vault uses for an entry hash

Canonicalisation follows the open formats bundle: keys sorted at every level, separators , and :, UTF-8. A receiver recomputes bundle_hash from the body, finds signature.key_id among public_keys (or among the keys published at /v1/enforce/warrants/keys), refuses a revoked key, and verifies the signature over the hash string. Signing the hash rather than the body keeps the signed message short, so a hardware or cloud key that takes messages of a few kilobytes signs a bundle of any size. The dashboard does the same under For engineers, Check a bundle file, and POST /api/sentinel/enforcement/authority/model/bundle/verify with {bundle, use_published_keys} answers {valid, reason, bundle_hash, key_id}.

The bundle is a read-only export. Nothing in it grants authority: a warrant, a lending or a mandate is in force because of its own signed record, which the bundle names and hashes.