XAO, the Xybern Authority Ontology, version 0.9 (public draft)¶
Status: draft 0.9. Becomes 1.0 when customers run it in production and the formats have not changed for one release. Reference implementation: package/xybern_api/xao/. SDK mirror: xybern.xao (pure, offline). Vectors: vectors/authority_slice.json, vectors/invariants.json, vectors/xal.json, vectors/passport.json, vectors/negotiation.json, vectors/genome.json.
Purpose¶
XAO defines what authority is made of, so that a decision, its proof, a simulation, a text serialisation and a partner's view of the same authority are all readings of one model. It is a resolution layer over an implementation's own records, not a storage schema: an implementation conforms by producing Authority Slices of this shape and by holding the invariants.
The eight primitives¶
| Primitive | Definition | Required fields in a slice |
|---|---|---|
| Principal | the party that acts, or on whose behalf an action is taken | kind (agent, person, external), id; optional department_id, on_behalf_of, root_principal, trust_state, passport |
| Capability | a kind of action the principal can attempt | action_type, family (the first token of the action type before _ . : /); optional tool, scopes |
| Resource | what the action touches, as a class and a hashed instance, never an inventory | class; optional instance_hash, connector, labels |
| Intent | why the action is attempted | optional mission_id, objective, session_id, outcome, alignment |
| Authority | a permission held, whatever object implements it | list of {kind, id, issuer, grants{action_families, scopes, argument_bounds, budgets, resources}, not_before, expires_at, status, depth} |
| Constraint | a limit on an authority or an action | list of {kind, ...}: budget, decay, lease, window, precedent |
| Effect | what the action would do (expected) and did (actual) | {kind, irreversible, external, spend, records, data_classes, signals, summary, effect_hash} |
| Evidence | what proves the decision | {decision_id, receipt, stamp_id, vault_entry_id}, slice_hash |
Authority is an interface: warrants, delegation grants, roles, boundaries, temporal windows, break-glass records and Charter rules each implement it by answering the same questions. Warrants remain the signature object; the others are resolved into the slice by reference.
The Authority Slice¶
xybern-authority-slice-v1 (see authority-slice-v1.md) is the eight primitives resolved for one request, plus context (session, arguments' shape, time), invariants (checked, held, violations) and decision_outcome. It is resolved before any rule runs and stored with the decision; the receipt carries it; the stamp names its hash.
The invariants¶
Eight properties hold for every slice. They are defined once and published as xao-invariants-v1 vectors (holds / violated over plain inputs).
| Id | Property | Inputs |
|---|---|---|
| INV-001 | no widening | child, parent grants |
| INV-002 | validity window | not_before, expires_at, now |
| INV-003 | revocation is global | status |
| INV-004 | a person's hold stands | delegate_decision, principal_decision, self_resolution |
| INV-005 | argument bounds | grants, action_type, metadata |
| INV-006 | resource coverage | grants, resource |
| INV-007 | accountable issuer | issuer |
| INV-008 | mission service | mission, action_type, metadata |
A conforming checker exposes check_invariant(invariant_id, inputs) -> bool and reaches the expected outcome on every vector.
Serialisations¶
| Form | Format | Use |
|---|---|---|
| a request's authority | xybern-authority-slice-v1 |
decisions, receipts, time travel |
| an agent | xybern-passport-v1 (XAP) |
discovery, offline verification |
| a workspace's authority as text | xybern-xal-v1 (XAL, JSON Schema xal-v1.schema.json) |
review, versioning, apply, export |
| authority held | xybern-warrant-v1 |
delegation, sessions, negotiation |
| authority between two parties | xybern-negotiation-v1 |
Session Warrants |
| the structure of a refused path | xybern-genome-pattern-v1 |
the network's learned refusals (no identifiers, no content) |
Mapping to standards¶
AuthZEN: subject is Principal, action is Capability with its properties as arguments, resource is Resource, context is Intent and session. A2A: the Agent Card is the passport; a task is authorised under a negotiated warrant. MCP: a tool is a Capability with a typed schema; a server is a Resource with labels.
Conformance¶
An implementation conforms to XAO 0.9 when it produces slices with the required fields, holds the eight invariants at decision time, and passes the invariant vectors with its own checker. It conforms to the formats when it passes the bundle's 56 vectors.