Skip to content

XAO, the Xybern Authority Ontology, version 0.9 (public draft)

Status: draft 0.9. Becomes 1.0 when customers run it in production and the formats have not changed for one release. Reference implementation: package/xybern_api/xao/. SDK mirror: xybern.xao (pure, offline). Vectors: vectors/authority_slice.json, vectors/invariants.json, vectors/xal.json, vectors/passport.json, vectors/negotiation.json, vectors/genome.json.

Purpose

XAO defines what authority is made of, so that a decision, its proof, a simulation, a text serialisation and a partner's view of the same authority are all readings of one model. It is a resolution layer over an implementation's own records, not a storage schema: an implementation conforms by producing Authority Slices of this shape and by holding the invariants.

The eight primitives

Primitive Definition Required fields in a slice
Principal the party that acts, or on whose behalf an action is taken kind (agent, person, external), id; optional department_id, on_behalf_of, root_principal, trust_state, passport
Capability a kind of action the principal can attempt action_type, family (the first token of the action type before _ . : /); optional tool, scopes
Resource what the action touches, as a class and a hashed instance, never an inventory class; optional instance_hash, connector, labels
Intent why the action is attempted optional mission_id, objective, session_id, outcome, alignment
Authority a permission held, whatever object implements it list of {kind, id, issuer, grants{action_families, scopes, argument_bounds, budgets, resources}, not_before, expires_at, status, depth}
Constraint a limit on an authority or an action list of {kind, ...}: budget, decay, lease, window, precedent
Effect what the action would do (expected) and did (actual) {kind, irreversible, external, spend, records, data_classes, signals, summary, effect_hash}
Evidence what proves the decision {decision_id, receipt, stamp_id, vault_entry_id}, slice_hash

Authority is an interface: warrants, delegation grants, roles, boundaries, temporal windows, break-glass records and Charter rules each implement it by answering the same questions. Warrants remain the signature object; the others are resolved into the slice by reference.

The Authority Slice

xybern-authority-slice-v1 (see authority-slice-v1.md) is the eight primitives resolved for one request, plus context (session, arguments' shape, time), invariants (checked, held, violations) and decision_outcome. It is resolved before any rule runs and stored with the decision; the receipt carries it; the stamp names its hash.

The invariants

Eight properties hold for every slice. They are defined once and published as xao-invariants-v1 vectors (holds / violated over plain inputs).

Id Property Inputs
INV-001 no widening child, parent grants
INV-002 validity window not_before, expires_at, now
INV-003 revocation is global status
INV-004 a person's hold stands delegate_decision, principal_decision, self_resolution
INV-005 argument bounds grants, action_type, metadata
INV-006 resource coverage grants, resource
INV-007 accountable issuer issuer
INV-008 mission service mission, action_type, metadata

A conforming checker exposes check_invariant(invariant_id, inputs) -> bool and reaches the expected outcome on every vector.

Serialisations

Form Format Use
a request's authority xybern-authority-slice-v1 decisions, receipts, time travel
an agent xybern-passport-v1 (XAP) discovery, offline verification
a workspace's authority as text xybern-xal-v1 (XAL, JSON Schema xal-v1.schema.json) review, versioning, apply, export
authority held xybern-warrant-v1 delegation, sessions, negotiation
authority between two parties xybern-negotiation-v1 Session Warrants
the structure of a refused path xybern-genome-pattern-v1 the network's learned refusals (no identifiers, no content)

Mapping to standards

AuthZEN: subject is Principal, action is Capability with its properties as arguments, resource is Resource, context is Intent and session. A2A: the Agent Card is the passport; a task is authorised under a negotiated warrant. MCP: a tool is a Capability with a typed schema; a server is a Resource with labels.

Conformance

An implementation conforms to XAO 0.9 when it produces slices with the required fields, holds the eight invariants at decision time, and passes the invariant vectors with its own checker. It conforms to the formats when it passes the bundle's 56 vectors.