跳转到内容

ak.schema.exact_current_results_read.v1

← Schemas

Arkret Exact Current Results Read
ak.schema.exact_current_results_read.v1 · file: schemas/exact-current-results-read.schema.json

Exact authorized Relation, moderation or Agent interaction current read at one governing-Station cut. It is non-enumerating and binds never-written to the exact selector. Includes the original issuer-only exact owned_agent capability_grant read, including ineffective and terminal rows; no never_written for grants. Also supports an exact Agent/Applet Policy CAS read by the scope-authorized policy setter, including authoritative never_written; not policy enumeration. Also supports an exact Agent/Applet Policy CAS read by the scope-authorized policy setter, including authoritative never_written; not policy enumeration. Also supports an exact Agent/Applet Policy CAS read by the scope-authorized policy setter, including authoritative never_written; not policy enumeration. Also supports an exact Agent/Applet Policy CAS read by the scope-authorized policy setter, including authoritative never_written; not policy enumeration.

* $ · oneOf[2]
Exact authorized Relation, moderation or Agent interaction current read at one governing-Station cut. It is non-enumerating and binds never-written to the exact selector. Includes the original issuer-only exact owned_agent capability_grant read, including ineffective and terminal rows; no never_written for grants. Also supports an exact Agent/Applet Policy CAS read by the scope-authorized policy setter, including authoritative never_written; not policy enumeration. Also supports an exact Agent/Applet Policy CAS read by the scope-authorized policy setter, including authoritative never_written; not policy enumeration. Also supports an exact Agent/Applet Policy CAS read by the scope-authorized policy setter, including authoritative never_written; not policy enumeration. Also supports an exact Agent/Applet Policy CAS read by the scope-authorized policy setter, including authoritative never_written; not policy enumeration.
oneOf · oneOf[0] · object · $ref #/$defs/exact_current_results_read_request
One exact, non-enumerating selector in one Realm. The caller cannot supply a revision, stream or governance Station.
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* selector · oneOf[6] · $ref #/$defs/exact_current_result_selector
oneOf · oneOf[0] · object · $ref #/$defs/relation_exact_current_selector
* kind · const "relation"
enum: "relation"
* primary_conflict_domain · object · $ref ./relation.schema.json#/$defs/relation_primary_conflict_domain
The unique typed-current-result subject for one directly writable Relation domain. Realm comes from the Event envelope and Circle is not a key component. domain_kind MUST equal the matching relation-kind-registry.json shape's registered primary_conflict_domain: tuple keys on (relation_kind, from_ref, to_ref), while from keys on (relation_kind, from_ref). truth_source shapes have no directly writable Relation domain.
allOf · allOf[0] · ?
* domain_kind · string (enum)
enum: "tuple" "from"
* relation_kind · string
The current Relation's create-locked relation_kind. It MUST resolve to a directly writable relation-kind-registry.json shape whose registered primary_conflict_domain equals domain_kind; a derived_projection shape is rejected with schema_violation (reason=relation_kind_contains_derived / relation_kind_watches_derived).
* from_ref · $ref #/$defs/relation_endpoint · $ref #/$defs/relation_endpoint
to_ref · $ref #/$defs/relation_endpoint · $ref #/$defs/relation_endpoint
Present exactly when domain_kind=tuple. A from domain already identifies the single current Relation for the from_ref, so carrying to_ref there would create a second spelling of the subject.
oneOf · oneOf[1] · object · $ref #/$defs/moderation_state_exact_current_selector
* kind · const "moderation_state"
enum: "moderation_state"
* target_ref · string · $ref ./event-payload.schema.json#/$defs/object_ref
pattern: ^((?:ak:realm:[A-Za-z0-9_-]{44}|ak:(circle|space|actor_profile|strand|message|morph|relation|view|event|grant|invite|call|report):[A-Za-z0-9_-]{44}|ak:(policy|blob):[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12})|ak:blob:(sha256|blake3):[0-9a-f]{64}|did:[^\s]+|(sha256|blake3):[0-9a-f]{64})$
oneOf · oneOf[2] · object · $ref ./typed-current-result.schema.json#/$defs/agent_interaction_result/properties/selector
* kind · const "agent_interaction"
enum: "agent_interaction"
* agent_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
oneOf · oneOf[3] · object · $ref ./typed-current-result.schema.json#/$defs/capability_grant_result/properties/selector
* kind · const "capability_grant"
enum: "capability_grant"
* grant_id · string · $ref ./common-ids.schema.json#/$defs/grant_id
pattern: ^ak:grant:[A-Za-z0-9_-]{44}$
oneOf · oneOf[4] · object · $ref ./typed-current-result.schema.json#/$defs/calendar_schedule_source_result/properties/selector
* kind · const "calendar_schedule_source"
enum: "calendar_schedule_source"
* strand_id · string
pattern: ^ak:strand:[A-Za-z0-9_-]{44}$
oneOf · oneOf[5] · object · $ref ./typed-current-result.schema.json#/$defs/policy_result/properties/selector
* kind · const "policy"
enum: "policy"
* policy_id · string · $ref ./event-payload.schema.json#/$defs/policy_set_state_payload/properties/policy_id
pattern: ^ak:policy:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
oneOf · oneOf[1] · oneOf[2] · $ref #/$defs/exact_current_results_read_outcome
One authorized same-cut answer. never_written is an affirmative Station result, never an inference from omission, timeout or invisibility.
oneOf · oneOf[0] · object · $ref #/$defs/exact_current_result_present
* status · const "present"
enum: "present"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* governance_generation · integer
* effective_stream_head · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* entry · oneOf[6] · $ref #/$defs/exact_current_result_entry
oneOf · oneOf[0] · object · $ref ./typed-current-result.schema.json#/$defs/relation_result
The single Relation current value for one registered primary conflict domain (zh/models/relation.md section 6). Realm comes from the accepted Event envelope. The value retains its event-derived RelationId and immutable domain identity; create/update/tombstone all address this same subject and use exact revision CAS.
* selector · object
* kind · const "relation"
enum: "relation"
* primary_conflict_domain · object · $ref ./relation.schema.json#/$defs/relation_primary_conflict_domain
The unique typed-current-result subject for one directly writable Relation domain. Realm comes from the Event envelope and Circle is not a key component. domain_kind MUST equal the matching relation-kind-registry.json shape's registered primary_conflict_domain: tuple keys on (relation_kind, from_ref, to_ref), while from keys on (relation_kind, from_ref). truth_source shapes have no directly writable Relation domain.
allOf · allOf[0] · ?
* domain_kind · string (enum)
enum: "tuple" "from"
* relation_kind · string
The current Relation's create-locked relation_kind. It MUST resolve to a directly writable relation-kind-registry.json shape whose registered primary_conflict_domain equals domain_kind; a derived_projection shape is rejected with schema_violation (reason=relation_kind_contains_derived / relation_kind_watches_derived).
* from_ref · $ref #/$defs/relation_endpoint · $ref #/$defs/relation_endpoint
to_ref · $ref #/$defs/relation_endpoint · $ref #/$defs/relation_endpoint
Present exactly when domain_kind=tuple. A from domain already identifies the single current Relation for the from_ref, so carrying to_ref there would create a second spelling of the subject.
* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind · const "realm"
enum: "realm"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object
* kind · const "circle"
enum: "circle"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
oneOf · oneOf[2] · object
* kind · const "sidecar"
enum: "sidecar"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* sidecar_id · string · $ref ./common-ids.schema.json#/$defs/sidecar_id
pattern: ^ak:sidecar:[A-Za-z0-9_-]{44}$
* revision · $ref #/$defs/revision · $ref #/$defs/revision
* value · object · $ref ./relation.schema.json
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
id · string
Present on the materialised object. MUST be absent from the create Event payload: zh/models/common-fields.md derives it from the create Event's own event_id (retyped), so a payload-supplied id would be a second, forgeable truth.
pattern: ^ak:relation:[A-Za-z0-9_-]{44}$
* schema · const "ak.schema.relation.v1"
enum: "ak.schema.relation.v1"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
scope_circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
Optional intra-Realm Circle (models/circle.md) defining this Relation fact's effective scope, supplied in the submit payload. For confidential_discussion_of it points to the private Strand's Circle. For structural relations the resulting effective_scope MUST NOT be wider than the narrowest participating endpoint scope (circle.md §6.1). Sidecar context mappings are native sidecar.context typed results, not Relation objects.
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
effective_scope · $ref #/$defs/effective_scope · $ref #/$defs/effective_scope
Read-only immutable effective scope of this Relation fact, materialized from the accepted Event.scope_ref after the receiver verifies it against scope_circle_id and endpoint pre-state (circle.md §6.1-§6.2). For structural relations it MUST NOT be wider than the narrowest participating endpoint scope. It remains immutable across any later scope rebind and MUST NOT appear in actor-supplied content payload (reason=effective_scope_reducer_managed).
* relation_kind · string
Relation semantic. The standard kind vocabulary (kind list, cardinality class, truth-source class, weak_semantic flag) is machine-indexed in artifacts/registry/relation-kind-registry.json; detailed dedupe/scope/conflict semantics in models/relation.md §3-§6. Cross-Realm constraint: the current governance Station's authoritative reducer MUST resolve both endpoints and reject structural relations 'contains' and 'belongs_to' when either endpoint realm differs from this Relation realm, with failed_precondition reason cross_realm_structural_relation and zero commit/projection effect; producer or SDK prechecks are non-authoritative. weak_semantic=true kinds per the registry MAY cross Realm subject to two-sided authorization. Stays a free string so extension profiles can add kinds; unregistered kinds are opaque edges (unknown_relation_kind), never container/visibility semantics.
* from_ref · $ref #/$defs/relation_endpoint · $ref #/$defs/relation_endpoint
* to_ref · $ref #/$defs/relation_endpoint · $ref #/$defs/relation_endpoint
rank · $ref #/$defs/rank · $ref #/$defs/rank
Top-level rank string for ordered relations (e.g. contains-list-strand position). Encoding follows the ak.rank.lexofractional.v1 grammar in zh/conformance/encoding.md section 9.1. Aligned with Space.rank so all rank-bearing canonical objects expose rank at the top level instead of fields.rank.
fields · object
Edge metadata. MUST NOT contain a 'rank' key — rank moved to the top level in v1 to align with Space.rank.
state · string (enum)
Relation state. 'tombstoned' covers both deletion and redaction; the originating reason is preserved on the ak.relation.tombstone / ak.redaction event, not on the materialized object.
enum: "active" "tombstoned"
state_changed_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
Reducer-derived timestamp of the most recent state transition. MUST be set when state != 'active'; MUST be the created_at of the corresponding ak.relation.tombstone / redaction Event. Aligns with Space.state_changed_at and the common-fields rule in models/common-fields.md §3.
* created_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* created_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
updated_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
updated_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
oneOf · oneOf[1] · object · $ref ./typed-current-result.schema.json#/$defs/moderation_state_result
Registered projection of one moderated target. governance/content-moderation.md section 5.3 keys the set per target and folds several issuers' active records into one effective decision at read time; dismiss closes a report queue item and folds to none. payload.expected_revision of ak.moderation.decision.lift names this result's revision, which is why the lift is stale-checkable without the set carrying a lifecycle axis.
* selector · object
* kind · const "moderation_state"
enum: "moderation_state"
* target_ref · string · $ref ./event-payload.schema.json#/$defs/object_ref
pattern: ^((?:ak:realm:[A-Za-z0-9_-]{44}|ak:(circle|space|actor_profile|strand|message|morph|relation|view|event|grant|invite|call|report):[A-Za-z0-9_-]{44}|ak:(policy|blob):[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12})|ak:blob:(sha256|blake3):[0-9a-f]{64}|did:[^\s]+|(sha256|blake3):[0-9a-f]{64})$
* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind · const "realm"
enum: "realm"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object
* kind · const "circle"
enum: "circle"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
oneOf · oneOf[2] · object
* kind · const "sidecar"
enum: "sidecar"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* sidecar_id · string · $ref ./common-ids.schema.json#/$defs/sidecar_id
pattern: ^ak:sidecar:[A-Za-z0-9_-]{44}$
* revision · $ref #/$defs/revision · $ref #/$defs/revision
* value · $ref #/$defs/moderation_state_value · $ref #/$defs/moderation_state_value
oneOf · oneOf[2] · object · $ref ./typed-current-result.schema.json#/$defs/agent_interaction_result
* selector · object
* kind · const "agent_interaction"
enum: "agent_interaction"
* agent_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind · const "realm"
enum: "realm"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object
* kind · const "circle"
enum: "circle"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
oneOf · oneOf[2] · object
* kind · const "sidecar"
enum: "sidecar"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* sidecar_id · string · $ref ./common-ids.schema.json#/$defs/sidecar_id
pattern: ^ak:sidecar:[A-Za-z0-9_-]{44}$
* revision · $ref #/$defs/revision · $ref #/$defs/revision
* value · $ref #/$defs/agent_interaction_value · $ref #/$defs/agent_interaction_value
oneOf · oneOf[3] · object · $ref ./typed-current-result.schema.json#/$defs/capability_grant_result
Registered projection of one Capability Grant. The subject GrantId is derived by retyping the accepted ak.capability.grant Event id; the value is the complete projected grant, including reducer-inserted id and the registered derived members authority_depth / authority_root_refs (zh/authz/capabilities.md section 10).
* selector · object
* kind · const "capability_grant"
enum: "capability_grant"
* grant_id · string · $ref ./common-ids.schema.json#/$defs/grant_id
pattern: ^ak:grant:[A-Za-z0-9_-]{44}$
* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind · const "realm"
enum: "realm"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object
* kind · const "circle"
enum: "circle"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
oneOf · oneOf[2] · object
* kind · const "sidecar"
enum: "sidecar"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* sidecar_id · string · $ref ./common-ids.schema.json#/$defs/sidecar_id
pattern: ^ak:sidecar:[A-Za-z0-9_-]{44}$
* revision · $ref #/$defs/revision · $ref #/$defs/revision
* value · object · $ref ./capability-grant.schema.json
allOf · allOf[0] · ?
allOf · allOf[1] · ?
* id · string
pattern: ^ak:grant:[A-Za-z0-9_-]{44}$
* schema · const "ak.schema.capability.v1"
enum: "ak.schema.capability.v1"
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* issuer_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* subject · oneOf[2]
oneOf · oneOf[0] · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* account_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* service_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
* kind · const "condition"
enum: "condition"
* required_claims · array<object> · $ref ./grant-constraint.schema.json#/properties/required_claims
Conditional claim requirements. resource-selector-grammar.md §3.3 caps this array at 32 entries as a normative DoS guard; the schema enforces maxItems:32 so condition-selector grants cannot smuggle in unbounded claim objects.
items · …
recursion truncated at depth 8; see source schema for full shape
* actions · array<string>
items · string
Canonical action vocabulary. MUST be of the form ak.<segment>.<segment>... matching capabilities.md §5. Bare names without the ak. prefix are not permitted; consult capabilities.md before introducing new action names. Wildcards within a segment are not permitted in this schema; the resource selector controls scope, not action expansion.
pattern: ^ak\.[a-z0-9_]+(\.[a-z0-9_]+)*$
* resources · array<$ref ./resource-selector.schema.json>
items · object · $ref ./resource-selector.schema.json
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
* kind · string (enum)
enum: "realm" "space" "circle" "strand" "message" "morph" "object" "relation" "view" "event" "actor" "schema" "policy" "invite" "notification" "read_cursor" "blob" "*"
realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
space_id · string
pattern: ^ak:space:[A-Za-z0-9_-]{44}$
circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
object_kind · string
object_ref · string
Canonical object reference. Acceptable typed-id kinds match the v1 resource selector kind enum (see resource-selector-grammar.md §3.1). Notably MUST NOT include 'actor_profile' (use the 'actor' selector with did pattern), nor non-canonical 'board' / 'list' / 'card' / 'subject' / 'room' kinds — board / list / swimlane / calendar bucket are Space objects and MUST use the 'space' kind together with the 'allowed_space_kinds' constraint to restrict which Space kinds the grant covers.
pattern: ^(?:ak:realm:[A-Za-z0-9_-]{44}|ak:(space|circle|strand|message|morph|relation|view|event|invite):[A-Za-z0-9_-]{44}|ak:(policy|blob):[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12})$
strand_id · string
pattern: ^ak:strand:[A-Za-z0-9_-]{44}$
message_id · string
pattern: ^ak:message:[A-Za-z0-9_-]{44}$
morph_id · string
pattern: ^ak:morph:[A-Za-z0-9_-]{44}$
morph_kind · string
relation_kind · string
relation_id · string
pattern: ^ak:relation:[A-Za-z0-9_-]{44}$
view_id · string
pattern: ^ak:view:[A-Za-z0-9_-]{44}$
event_id · string
pattern: ^ak:event:[A-Za-z0-9_-]{44}$
actor_id · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
schema_ref · string
policy_id · string
pattern: ^ak:policy:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
invite_id · string
pattern: ^ak:invite:[A-Za-z0-9_-]{44}$
blob_ref · string
pattern: ^ak:blob:(?:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}|(?:sha256|blake3):[0-9a-f]{64})$
match_scope · string (enum)
Authorization selector breadth. exact matches only the named resource; realm_wide is valid only for the registered resource kinds with an explicit realm_id. Neither current navigation ancestry nor creation ancestry expands authorization. Hierarchy traversal belongs to queries, not grant matching. The normative algorithm is zh/authz/resource-selector-grammar.md section 6.
enum: "exact" "realm_wide"
constraints · array<$ref ./grant-constraint.schema.json>
Constraints applied to this grant. Re-grant control MUST be expressed via constraint_kind='authority_control' and max_authority_depth (see capabilities.md §10). A top-level 'delegable' field is forbidden and MUST be rejected as schema_violation. With no authority_control constraint the grant cannot be re-granted (equivalent to max_authority_depth=0).
items · object · $ref ./grant-constraint.schema.json
allOf · allOf[0] · ?
allOf · allOf[1] · ?
allOf · allOf[2] · ?
allOf · allOf[3] · ?
allOf · allOf[4] · ?
allOf · allOf[5] · ?
allOf · allOf[6] · ?
allOf · allOf[7] · ?
allOf · allOf[8] · ?
allOf · allOf[9] · ?
allOf · allOf[10] · ?
allOf · allOf[11] · ?
allOf · allOf[12] · ?
allOf · allOf[13] · ?
allOf · allOf[14] · ?
constraint_id · string
Optional stable identifier of this constraint within the grant; used for diagnostics and overrides.
pattern: ^(?!ak:)
* constraint_kind · string (enum)
Constraint family discriminator. v1 collapses what were 15 types into 8 by absorbing narrowly-scoped types into their conceptual parent: edit_window → temporal; container_move → scope_limitation; rate_limiting + resource_limit → quota; approval_workflow + accountability + device_session → claim_based (with constraint_subkind); encryption_requirement + visibility_control → confidentiality (with constraint_subkind). Use the optional 'constraint_subkind' field to indicate the original specialization where evaluation logic differs.
enum: "temporal" "field_access" "kind_restriction" "scope_limitation" "authority_control" "quota" "claim_based" "confidentiality"
* effect · string (enum)
enum: "allow" "deny" "quarantine" "require_review"
evaluation_class · string (enum)
Cacheability/dependency hint for the authorization evaluator. stateless = pure function of (constraint, op, now); grant_local = depends on the grant object only; realm_state = depends on the exact Realm authority revision (membership, policy_version, etc.); external = depends on data outside that authority state (claim revocation status, rate-limit counts, async approval). Each constraint_kind has a canonical evaluation_class declared in constraint-schema.md §2.3; implementations MAY tighten (e.g. grant_local → stateless) but MUST NOT loosen (e.g. external as stateless). Auth evaluators SHOULD use this hint to gate fast-path caching.
enum: "stateless" "grant_local" "realm_state" "external"
constraint_subkind · string (enum)
Optional discriminator within a constraint_kind. Standard values: claim_based.{claim,approval,accountability}; quota.{rate,resource}; confidentiality.{encryption,visibility}; temporal.{window,edit_window,redact_window,session}; authority_control.{applet_authority}. Per constraint-schema.md §2.2, device/session binding is NOT an independent constraint_subkind: it is the claim_based constraint_subkind=claim sub-case expressed via an accepted PCR device issuer. Implementations MAY require constraint_subkind for these families and fail closed on unknown values.
enum: "claim" "approval" "accountability" "rate" "resource" "encryption" "visibility" "window" "edit_window" "redact_window" "session" "applet_authority"
applies_to_actions · array<string>
Optional restriction of a temporal constraint to specific capability actions (e.g. ['ak.message.revise.own', 'ak.message.redact.own']). Action mismatch is neutral in the effect fold: satisfied for effect=allow and not matched for deny/quarantine/require_review.
items · …
recursion truncated at depth 8; see source schema for full shape
not_before · $ref #/$defs/timestamp · $ref #/$defs/timestamp
expires_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
recurrence · object
Recurrence rule for temporal constraints. Used by constraint-schema.md §3.1.
frequency · …
recursion truncated at depth 8; see source schema for full shape
days · …
recursion truncated at depth 8; see source schema for full shape
window_start · …
recursion truncated at depth 8; see source schema for full shape
window_end · …
recursion truncated at depth 8; see source schema for full shape
timezone · …
recursion truncated at depth 8; see source schema for full shape
max_duration · string
ISO 8601 duration.
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
max_session_duration · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
inactivity_timeout · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
expires_after · string
ISO 8601 duration; used by approval_workflow constraint instead of expires_after_ms.
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
message_edit_window · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
message_redact_window · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
redact_after_window_allowed · boolean
condition · object
Conditional predicate for field_access and similar constraints. The `kind` value is a registered named condition from constraint-schema.md §4.1; unknown kinds MUST fail closed. Implementations MUST NOT introduce ad hoc string DSL predicates.
* kind · …
recursion truncated at depth 8; see source schema for full shape
allowed_write_fields · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
denied_write_fields · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
allowed_read_fields · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
denied_read_fields · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
sensitive_fields · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
sensitive_handling · string (enum)
enum: "redact" "hash" "omit"
allowed_object_kinds · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
denied_object_kinds · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
allowed_morph_kinds · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
denied_morph_kinds · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
allowed_space_kinds · array<string>
Allowed Space kinds (e.g. 'board', 'list', or profile-registered kinds like 'swimlane', 'calendar_bucket'). Reducer/profile MUST validate kind value.
items · …
recursion truncated at depth 8; see source schema for full shape
denied_space_kinds · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
allowed_facets · array<string (enum)>
items · …
recursion truncated at depth 8; see source schema for full shape
denied_facets · array<string (enum)>
items · …
recursion truncated at depth 8; see source schema for full shape
allowed_view_ids · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
allowed_strand_ids · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
denied_strand_ids · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
allowed_space_ids · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
denied_space_ids · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
allowed_circle_ids · array<$ref ./common-ids.schema.json#/$defs/circle_id>
Limits Circle-scoped capability actions to the listed Circle ids. Used by ak.circle.manage / ak.circle.member.manage style grants; unconstrained Realm-wide Circle management grants are not a normal permission shape.
items · …
recursion truncated at depth 8; see source schema for full shape
allowed_session_ids · array<string>
Limits applet interop-session operations to the listed applet-defined session correlation ids.
items · …
recursion truncated at depth 8; see source schema for full shape
allowed_view_kinds · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
allowed_view_renderers · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
denied_view_kinds · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
denied_view_renderers · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
allowed_relation_kinds · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
allowed_from_container_refs · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
allowed_to_container_refs · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
wip_limit_override · boolean
example: false
allowed_tracks · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
denied_tracks · array<string>
items · …
recursion truncated at depth 8; see source schema for full shape
blob_presign_scope · object
Scope limiter for ak.self.blob.command.presign.v1 grants: allowed purposes plus optional blob/realm restrictions.
* allowed_purposes · …
recursion truncated at depth 8; see source schema for full shape
blob_ref_pattern · …
recursion truncated at depth 8; see source schema for full shape
realm_ids · …
recursion truncated at depth 8; see source schema for full shape
allowed_data_labels · array<string>
Data classification labels this grant may read, export, transform, or send to external endpoints.
items · …
recursion truncated at depth 8; see source schema for full shape
allowed_endpoints · array<string>
Allowed outbound endpoint origins or deployment-approved endpoint patterns for applet / agent / connector operations.
items · …
recursion truncated at depth 8; see source schema for full shape
max_authority_depth · integer
Maximum remaining authority hops. Bounded by the canonical authority-chain depth ceiling (4) defined in zh/conformance/scalability-constraints.md §3 and zh/authz/capabilities.md §10.2; reducers MUST reject grants declaring a larger value at accept time rather than only truncating during DFS.
authority_path_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items · …
recursion truncated at depth 8; see source schema for full shape
authority_regrant_allowed · boolean
authority_scope · string (enum)
enum: "narrowing_only" "same_scope" "custom"
applet_id · string · $ref ./common-ids.schema.json#/$defs/applet_id
Stable canonical Applet installation identity. Applet service authority is carried separately by service_id.
pattern: ^ak:applet:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
executed_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
registration_epoch · string
authority_control(constraint_subkind=applet_authority) binding to the canonical Applet registration epoch.
pattern: ^sha256:[0-9a-f]{64}$
blob_max_bytes · integer
blob_presign_max_ttl_seconds · integer
Maximum TTL, in seconds, that this grant permits for ak.blob.presign. The service must clamp requested max_age_seconds to the smaller of this value and deployment policy.
max_total_blob_bytes · integer
max_artifact_bytes · integer
Maximum artifact size in bytes for applet / agent / export operations.
max_operations · integer
Maximum number of distinct accepted idempotency identities in one UTC epoch-aligned fixed period. Enforcement is a linearizable check-and-reserve at one logical quota authority shared by every node in the enforcing service; per-node duplicated budgets and overshoot are forbidden.
period · string
ISO 8601 duration. For quota constraints, a stricter conditional schema permits only a non-zero fixed-length week/day/hour/minute/second duration; year/month durations are forbidden so every authority derives the same UTC epoch-aligned window id.
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
burst · integer
Optional token-bucket capacity at the same logical quota authority, capped by max_operations and refilled at max_operations/period. It never increases the fixed-window total budget.
constraint_scope · string (enum)
Closed v1 quota counting scope. Unknown values are schema violations and MUST fail closed. Quota counters are actor-bound; the enum selects the additional slicing dimension: actor only, actor+space, actor+realm, or actor across all nodes/regions of the enforcing service's global quota domain. global is not an implicit federation-wide counter. Every node in the service domain MUST share one logical linearizable quota authority.
enum: "per_actor" "per_space" "per_realm" "global"
max_resources · integer
resource_kind · string
approval_required · boolean
approval_mode · string (enum)
The only approval mode of v1. The approved write MUST NOT take effect before the approval evidence is verified and accepted in the same transaction (zh/authz/constraint-schema.md section 9.2.7). There is no second mode and no path that first materializes a proposal object and then approves that object.
enum: "before_commit"
approval_actor_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items · …
recursion truncated at depth 8; see source schema for full shape
approval_relation · string (enum)
Responsibility classification of this grant explicit approval_actor_ids roster. It never creates a second dynamic roster or supplies action/scope capability. Missing explicit roster cannot satisfy approval.
enum: "responsible" "controller" "guardian" "realm_admin" "custom"
timeout · string
Positive fixed ISO 8601 duration (week/day/hour/minute/second, no calendar year/month). Each approval vote is valid only when the target covering committed_at <= that vote input.approved_at + timeout, inclusive and with zero tolerance. The same rule applies to Event and operation targets; receiver clocks and first-seen timestamps never anchor it. Omission adds no grant-local age limit.
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
approval_threshold · oneOf[2]
Closed executable vote threshold: majority means floor(N/2)+1, unanimous means N, and a positive integer is the exact quorum. N is the distinct eligible approver set at the accepting authority cut. Omission means unanimous. A missing or empty eligible set, or an integer greater than N, cannot satisfy approval. Repeated signatures by one approver count once. Parameterless quorum/custom strings are schema violations.
example: "unanimous"
oneOf · oneOf[0] · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · …
recursion truncated at depth 8; see source schema for full shape
accountability_required · boolean
guardian_approval_required · boolean
controller_approval_required · boolean
required_claims · array<object>
Conditional claim requirements. resource-selector-grammar.md §3.3 caps this array at 32 entries as a normative DoS guard; the schema enforces maxItems:32 so condition-selector grants cannot smuggle in unbounded claim objects.
items · …
recursion truncated at depth 8; see source schema for full shape
trusted_claim_issuer_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items · …
recursion truncated at depth 8; see source schema for full shape
claim_refresh_required · boolean
claim_max_age · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
allowed_history_access_values · array<string (enum)>
items · …
recursion truncated at depth 8; see source schema for full shape
redacted_history_allowed · boolean
encryption_required · boolean
min_encryption_level · string (enum)
confidentiality(constraint_subkind=encryption) static floor: the minimum content-encryption mechanism the grant requires. Pure static declaration evaluated as stateless unless cross-checked against the scope's current MLS activation state (see constraint-schema.md section 12).
enum: "none" "mls_rfc9420" "external"
plaintext_fallback_allowed · boolean
confidentiality(constraint_subkind=encryption) static flag: whether the grant permits plaintext in a scope that has no accepted ak.mls.genesis. After activation the flag cannot restore plaintext; the write MUST be rejected with mls_activation_irreversible. See constraint-schema.md §12.
audit_trail_required · boolean
confidentiality(constraint_subkind=encryption) static flag: whether the grant requires an audit trail (e.g. active Audit Applet Binding). See constraint-schema.md §12.
key_rotation_period · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
max_key_age · string
pattern: ^P(?:[0-9]+Y)?(?:[0-9]+M)?(?:[0-9]+W)?(?:[0-9]+D)?(?:T(?:[0-9]+H)?(?:[0-9]+M)?(?:[0-9]+S)?)?$
key_backup_required · boolean
approved_key_issuer_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
items · …
recursion truncated at depth 8; see source schema for full shape
depends_on_moderation_state · boolean
Cache-invalidation hint: when true, this grant's authorization decisions depend on the moderation_state typed current result (see capabilities.md §18.1) and the grant's cache entry MUST be invalidated when that typed current result changes. Default false: ordinary grants (ak.strand.update / ak.message.create / organization membership grants) do NOT take a cache hit on every moderation decision. v1 capabilities.md §18.1 lists three conditions where MUST be explicitly true (moderator-role grants, condition-selector subjects referencing moderation state, constraints referencing moderation queue / typed current result). Schema-side enforcement of condition (2) is in capability-grant.schema.json via if/then on actions[]; conditions (1) and (3) are reducer-side lint. Cache invalidation hint outside the eight constraint families; it does not participate in allow/deny evaluation and is documented in capabilities.md §6 / constraint-schema.md.
allowed_managed_actor_roles · array<string (enum)>
Ordinary authority_control permits only these accepted roles of the Applet bound by the parent applet_authority constraint; no arbitrary third-party regrant.
items · …
recursion truncated at depth 8; see source schema for full shape
(^x_[a-z][a-z0-9_]{0,63}$) · any
* issued_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* status · string (enum)
Reducer-derived lifecycle status of this Grant (zh/authz/capabilities.md section 12.1). It is absent from the closed authoring body of ak.capability.grant and is materialised by the registered capability_status derivation, so an author-supplied value MUST be rejected rather than trusted. The two terminal values stay distinct because section 10.4 gives them different authorities: revoke is issuer or root-controller authority, relinquish is the target subject's own signature and MUST NOT require ak.capability.revoke. Collapsing them into revoked_at alone would erase which authority closed the Grant. A terminal value is final -- section 12.1 forbids resurrecting a closed grant_id -- and compaction MUST preserve it.
enum: "active" "revoked" "relinquished"
updated_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
updated_at · string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
revoked_by · oneOf[2] · $ref ./common-ids.schema.json#/$defs/actor_id
Complete protocol identity for an Event author or Realm member: account carries the exact AccountId for every Station-hosted principal; service identifies a service acting as itself. The discriminator is validated against accepted registration and admission evidence; it never authorizes itself. Account and service are distinct, and no comparison may fall back to a bare principal_id. Agent and integration classification, provisioning, controller binding and credential authorization are independently verified facts, not identity variants. Account actors at different Stations MUST NOT share or inherit authority merely because their principal_id, DID controller or signing key matches, including membership, capability, RealmCommit-signing and recovery authority.
oneOf · oneOf[0] · object
* kind · const "account"
enum: "account"
* account_id · $ref #/$defs/account_id · $ref #/$defs/account_id
oneOf · oneOf[1] · object
* kind · const "service"
enum: "service"
* service_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
revoked_at · $ref #/$defs/timestamp · $ref #/$defs/timestamp
* issuer_authority_refs · array<oneOf[3]>
The signed semantic authority lineage this grant was issued under. A root controller's grant anchors on the accepted Realm authority Event; any further grant anchors on grants its issuer already holds. These closed refs intentionally carry no producer-selected current-result revision, authorization-state digest, Station id or commit basis: the governing Station resolves their current typed results at acceptance, fails closed when current authority cannot be proved fresh, and records the accepting RealmCommit as the decision basis. Authorization is recomputed from these refs on every decision, so revoking an ancestor invalidates its descendants without a cascading write. The sole owned_agent ref is an explicit non-regrant exception; it pins ownership membership and continuously bounds the Agent by current controller authority.
items · oneOf[3]
oneOf · oneOf[0] · object
A grant the issuer holds. The issuer MUST be that grant's subject, and the ref MUST be active both at acceptance and evaluation time; its capability, resources and constraints all bound this child. Its current-result revision is an acceptance-time Station input, not a signed wire member.
* kind · …
recursion truncated at depth 8; see source schema for full shape
* grant_id · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · object
A committed authority root in the same Realm as the grant. It is terminal for cycle checks. The accepting Station verifies the named Event/controller/generation against durable current authority; the ref does not carry a Station-local commit wrapper.
* kind · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* authority_event_ref · …
recursion truncated at depth 8; see source schema for full shape
* authority_generation · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[2] · $ref #/$defs/owned_agent_authority_ref · $ref #/$defs/owned_agent_authority_ref
* authority_depth · integer
Reducer-derived absolute distance from the authority root: a realm_root ref counts 0, so a root controller's grant is 1 and a member's re-grant is 2. Derived from the refs, never author-declared, so it cannot be misreported — which is what makes it safe to answer 'how far did this authority spread' with a single field instead of a recursive join. Taken at issuance and not recomputed on revocation; a later chain may be shorter than the recorded value, which is the conservative direction for a max_authority_depth decision. A dedicated terminal owned_agent source has depth 1 and cannot become a parent grant.
* authority_root_refs · array<oneOf[2]>
Reducer-derived set of committed authority roots this grant ultimately descends from: direct realm_root refs plus the union of every parent grant's roots. Deduplicated on (realm_id, authority_event_ref, authority_generation) and sorted canonically by unsigned-byte order. For an owned_agent source the sole root is that exact owned_agent ref; it never confers Realm root-control authority.
items · oneOf[2]
oneOf · oneOf[0] · object
* kind · …
recursion truncated at depth 8; see source schema for full shape
* realm_id · …
recursion truncated at depth 8; see source schema for full shape
* authority_event_ref · …
recursion truncated at depth 8; see source schema for full shape
* authority_generation · …
recursion truncated at depth 8; see source schema for full shape
oneOf · oneOf[1] · $ref #/$defs/owned_agent_authority_ref · $ref #/$defs/owned_agent_authority_ref
(^x_[a-z][a-z0-9_]{0,63}$) · any
oneOf · oneOf[4] · object · $ref ./typed-current-result.schema.json#/$defs/calendar_schedule_source_result
* selector · object
* kind · const "calendar_schedule_source"
enum: "calendar_schedule_source"
* strand_id · string
pattern: ^ak:strand:[A-Za-z0-9_-]{44}$
* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind · const "realm"
enum: "realm"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object
* kind · const "circle"
enum: "circle"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
oneOf · oneOf[2] · object
* kind · const "sidecar"
enum: "sidecar"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* sidecar_id · string · $ref ./common-ids.schema.json#/$defs/sidecar_id
pattern: ^ak:sidecar:[A-Za-z0-9_-]{44}$
* revision · $ref #/$defs/revision · $ref #/$defs/revision
* value · $ref #/$defs/calendar_schedule_source_value · $ref #/$defs/calendar_schedule_source_value
oneOf · oneOf[5] · object · $ref ./typed-current-result.schema.json#/$defs/policy_result
Registered projection of one Policy document. models/governance-objects.md section 3.2: ak.policy.set is the only writer, its payload is {policy_id, value} for ordinary Policy/RecoveryPolicy, and {policy_id, expected_revision, value} for Agent/Applet management Policy with exact nullable CAS; value.schema selects the Policy or RecoveryPolicy family and semantic admission requires the outer policy_id to equal the document's own id verbatim. rules[] is a required non-empty member OF this value and the whole priority / default_effect evaluation of that section runs over it, so a rule is never a subject of its own. The separate ak.policy.rule Event kind that used to assert one rule at a time is deleted: it carried no policy_id, so its rule_id named nothing resolvable, and rule editing submits the whole authorized Policy document through ak.policy.set.
* selector · object
* kind · const "policy"
enum: "policy"
* policy_id · string · $ref ./event-payload.schema.json#/$defs/policy_set_state_payload/properties/policy_id
pattern: ^ak:policy:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$
* source_stream_ref · oneOf[3] · $ref ./realm-commit.schema.json#/$defs/stream_ref
Closed visibility-stream selector. Realm, each Circle and each Sidecar have independent continuous positions so hidden scopes do not leak through global gaps.
oneOf · oneOf[0] · object
* kind · const "realm"
enum: "realm"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
oneOf · oneOf[1] · object
* kind · const "circle"
enum: "circle"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* circle_id · string · $ref ./common-ids.schema.json#/$defs/circle_id
pattern: ^ak:circle:[A-Za-z0-9_-]{44}$
oneOf · oneOf[2] · object
* kind · const "sidecar"
enum: "sidecar"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* sidecar_id · string · $ref ./common-ids.schema.json#/$defs/sidecar_id
pattern: ^ak:sidecar:[A-Za-z0-9_-]{44}$
* revision · $ref #/$defs/revision · $ref #/$defs/revision
* value · $ref #/$defs/policy_value · $ref #/$defs/policy_value
oneOf · oneOf[1] · object · $ref #/$defs/exact_current_result_never_written
* status · const "never_written"
enum: "never_written"
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* governance_generation · integer
* effective_stream_head · object · $ref ./realm-commit.schema.json#/$defs/stream_head
* stream_ref · $ref #/$defs/stream_ref · $ref #/$defs/stream_ref
* stream_position · integer
* commit_id · string · $ref ./common-ids.schema.json#/$defs/realm_commit_id
Content-addressed identity of a closed unsigned RealmCommit body. The suffix uses the fixed v1 digest suite and the same canonical 33-octet token encoding as Event IDs.
pattern: ^ak:realm_commit:[A-Za-z0-9_-]{44}$
* selector · oneOf[3]
oneOf · oneOf[0] · object · $ref #/$defs/relation_exact_current_selector
* kind · const "relation"
enum: "relation"
* primary_conflict_domain · object · $ref ./relation.schema.json#/$defs/relation_primary_conflict_domain
The unique typed-current-result subject for one directly writable Relation domain. Realm comes from the Event envelope and Circle is not a key component. domain_kind MUST equal the matching relation-kind-registry.json shape's registered primary_conflict_domain: tuple keys on (relation_kind, from_ref, to_ref), while from keys on (relation_kind, from_ref). truth_source shapes have no directly writable Relation domain.
allOf · allOf[0] · ?
* domain_kind · string (enum)
enum: "tuple" "from"
* relation_kind · string
The current Relation's create-locked relation_kind. It MUST resolve to a directly writable relation-kind-registry.json shape whose registered primary_conflict_domain equals domain_kind; a derived_projection shape is rejected with schema_violation (reason=relation_kind_contains_derived / relation_kind_watches_derived).
* from_ref · $ref #/$defs/relation_endpoint · $ref #/$defs/relation_endpoint
to_ref · $ref #/$defs/relation_endpoint · $ref #/$defs/relation_endpoint
Present exactly when domain_kind=tuple. A from domain already identifies the single current Relation for the from_ref, so carrying to_ref there would create a second spelling of the subject.
oneOf · oneOf[1] · object · $ref ./typed-current-result.schema.json#/$defs/agent_interaction_result/properties/selector
* kind · const "agent_interaction"
enum: "agent_interaction"
* agent_account_id · object · $ref ./common-ids.schema.json#/$defs/account_id
Complete protocol identity for a principal at one Station, including human, Agent, Applet-managed Ghost and integration accounts. It does not imply a human login, provisioning workflow, credential class or authorization. Equality is byte-for-byte equality of both canonical did_core_id components; neither component may be inferred from a DID Document, route, session audience, current service, handle, or local database key. Accounts with the same principal_id at different station_id values are permanently distinct. Principal equality MUST NOT establish account equivalence or any permission inheritance, merging, delegation, substitution or recovery relationship. Account-scoped authority requires independent authorization for the exact AccountId. Permanent loss of a Station does not permit its accounts or PCR lineages to migrate to or revive at another Station; Realm takeover and RealmCommit recovery do not waive this boundary. See models/common-fields.md section 4.2.
* principal_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
* station_id · $ref #/$defs/did_core_id · $ref #/$defs/did_core_id
oneOf · oneOf[2] · object · $ref ./typed-current-result.schema.json#/$defs/policy_result/properties/selector
* kind · const "policy"
enum: "policy"
* policy_id · string · $ref ./event-payload.schema.json#/$defs/policy_set_state_payload/properties/policy_id
pattern: ^ak:policy:[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$

Source