Authority Bundle, format v1 (draft)¶
Status: draft, XAO version 0.9. Produced by Oversee, Authority model, Authority Bundle and by GET /api/sentinel/enforcement/authority/model/bundle (workspace admins).
The Authority Bundle is the whole workspace as one signed document of the eight primitives: who acts, what authority is held and by whom, what can be done, what is touched, what it serves, what bounds it, what happened, and what proves it, with the findings the model raised and the invariants it holds to. A customer's own systems (a GRC tool, a SIEM, an archive) can hold the same model as the Authorisation Layer and check the document offline, without an account and without trusting Xybern.
| Key | Meaning |
|---|---|
format |
"xybern-authority-bundle-v1" |
xao_version |
The ontology version the bundle was shaped under |
workspace |
{id, name} |
exported_at, exported_by |
When and by whom |
charter |
{hash, signed_by, signed_at, mandates} of the Charter in force |
principal |
Every registered agent: {kind, id, name, framework, active, trust_state, acts_only_with_lent_authority, capabilities, fingerprint, did, registered_at, passport: {id, version, hash} or null} |
authority |
Every authority held by an active agent, once, as the Authority Slice publishes it (kind, id, issuer, grants, denies, not_before, expires_at, depth, parent_id, status, mode, constraints, intent_id) plus holders: the agents that hold it |
capability |
Every action type performed in the last 30 days or declared by an agent: {action_type, family, performed_by, declared_by, decisions_30d} |
resource |
Every resource class known or touched: {class, source, personal_data, touched_30d} |
intent |
Active and pending missions ({kind: "mission", id, agent_id, objective, status, mode, expires_at, hash}) and running sessions ({kind: "session", id, agent_id, label, status, budgets, started_at}) |
constraint |
Enabled rules ({kind: "rule", id, name, type, decision, action_types, agent_id, department_id, mode, priority, conditions_hash}), the communication default and rules, and the budgets on lent authority |
effect |
A summary of the last 30 days: decisions, by decision and by action type, all-time count, last decision time. Decisions themselves are separately signed receipts and are not repeated here |
evidence |
Counts of sealed receipts, stamps, attestations, co-authorisations and passports, the receipt format and where to verify one |
findings |
What the model says is missing, as on the page: {id, kind, primitive, severity, sentence, subjects} |
invariants |
The invariant catalogue: {id, name, version, statement, plain} |
names |
Agent id to name, so the document reads without a lookup |
public_keys |
The issuer's published keys {key_id, algorithm, public_key_pem, status} |
bundle_hash |
Hex SHA-256 of the canonical body without bundle_hash and signature |
signature |
{algorithm: "ecdsa-p256-sha256", signed: "bundle_hash", key_id, value}: ECDSA P-256 over SHA-256 of the bundle_hash hex string (UTF-8), DER, base64, the scheme the Provenance Vault uses for an entry hash |
Canonicalisation follows the open formats bundle: keys sorted at every level, separators , and :, UTF-8. A receiver recomputes bundle_hash from the body, finds signature.key_id among public_keys (or among the keys published at /v1/enforce/warrants/keys), refuses a revoked key, and verifies the signature over the hash string. Signing the hash rather than the body keeps the signed message short, so a hardware or cloud key that takes messages of a few kilobytes signs a bundle of any size. The dashboard does the same under For engineers, Check a bundle file, and POST /api/sentinel/enforcement/authority/model/bundle/verify with {bundle, use_published_keys} answers {valid, reason, bundle_hash, key_id}.
The bundle is a read-only export. Nothing in it grants authority: a warrant, a lending or a mandate is in force because of its own signed record, which the bundle names and hashes.