Skip to content

Authority Lineage, format v1 (final)

Status: final, version 1. Example: spec/xybern-formats-v1/vectors/lineage.json.

The lineage is computed at decision time from the objects in force and stored with the decision; it is never reconstructed later. It answers "on whose authority did this action rest" and travels inside the receipt (authorisation.lineage).

Key Meaning
format "xybern-lineage-v1"
computed_at ISO 8601 UTC
accountable {"kind": human / system / none, "id", "via", "charter_hash"}: the human who signed the Charter version in force, or an honest statement that none exists
charter {"hash", "signed_by", "signed_at", "mandate_count"}
mandates The mandates whose rules spoke: {mandate_id, outcome_text, level}
access_profile, intent_contract, temporal_window, breakglass, federation The narrowing or widening objects that applied; intent_contract.via = "warrant_chain" when reached through delegation
delegation, principal The grant chain root to leaf and whether the principal's own authority was evaluated
agent {agent_id, name, did, credential_fingerprint, identity_verified}
session, commitment, authority_request The runtime session, the declared-intent commitment, the human-granted authority
warrant {warrant_id, valid, body_hash, depth, chain, grant_id, reason, budget, contract_id}
flow {labels, description, matched_values, provenance, declared}: what class of data the action carried and which source introduced it
collective_limits The shared counters every sequence rule saw
action {decision_id, action_type, decision}

A receiver checks a lineage by its canonical SHA-256 against the receipt's vault entry; the lineage itself is not separately signed.