Skip to content

Authority Slice, format v1 (draft)

Status: draft, XAO version 0.1. Example: spec/xybern-formats-v1/vectors/authority_slice.json.

The Authority Slice is everything one decision rested on, resolved before the decision and stored with it. It answers "what was decided about, under which authority, and which invariants held" in one document. It is not separately signed: it travels inside the receipt, whose vault entry seals it, and its hash is named on the stamp.

Key Meaning
format "xybern-authority-slice-v1"
xao_version The ontology version the slice was shaped under ("0.1")
principal {kind, id, department_id, on_behalf_of, root_principal}: who acted and for whom
capability {action_type, family, tool, scopes}
resource {class, instance_hash, source}: the public class of what was touched and a hash of the instance; never the account, recipient or path
intent {session_id, contract_id, commitment_id, mission_id, declared}
authorities Every authority held, each {kind, id, issuer, expires_at, depth, parent_id, status}; kinds: warrant, grant, authority_request, access_profile, temporal_window, breakglass, role, mandate
constraints The number of live rules that can speak to this action (the full form lists them)
context {charter_hash, charter_signed_by, charter_version, hour_bucket, weekday, resolved_at}
effect {action_type, argument_shape_hash, arguments_hash, resource_class, reversible}
evidence [{kind, id, hash, valid, detail}]: warrant proofs, stamps, commitments, attestations
invariants {checked, violations: [{invariant, version, holds, subject, reason}], held: [ids]}
slice_hash SHA-256 of the canonical slice as resolved, without slice_hash and errors

Canonicalisation follows the bundle: keys sorted, , and : separators, UTF-8. The stored (compact) form and the full form share slice_hash; the full form adds each authority's grants (action_families, scopes, argument_bounds, budgets, resources), the constraints as {kind, id, source, spec}, and the principal's roles.

A receiver reads the slice from the receipt and may check: that every authority of kind warrant verifies with the issuer's published keys (the receipt carries the warrant proof), that context.charter_hash matches the receipt's Charter, and that invariants.violations is empty for an allowed decision.