ak.schema.moderation_queue_item.v1
ak.schema.moderation_queue_item.v1 · file: schemas/moderation-queue-item.schema.json * $ · object
* id ·
stringThe accepted ak.self.moderation.report Event id retyped to moderation_queue_item; services MUST NOT allocate an independent identifier. See governance/content-moderation.md section 3.3.
pattern:
^ak:moderation_queue_item:[A-Za-z0-9_-]{44}$* report · object · $ref ./event-payload.schema.json#/$defs/moderation_report_payload
Immutable payload projection from the accepted ak.self.moderation.report Event; never the service-operation request wrapper.
allOf · allOf[0] ·
?allOf · allOf[1] ·
?* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$effective_scope ·
$ref #/$defs/effective_scope · $ref #/$defs/effective_scopeGovernance boundary for the report. Defaults to the Realm scope when absent; Circle-scoped targets MUST resolve to the target Circle and route only to scoped moderators/admins.
* target_ref ·
$ref #/$defs/object_ref · $ref #/$defs/object_ref* report_reason_code ·
string (enum)enum:
"spam" "harassment" "hate_speech" "nsfw" "illegal" "misinformation" "other"description ·
string (arkret-short-text) · format=arkret-short-text · $ref string-profiles.schema.json#/$defs/short_textNFC multilingual short text. LF is allowed; CR, other C0/C1 controls, BOM, and bidi embedding/override controls are rejected.
pattern:
^[^\u0000-\u0009\u000B-\u001F\u007F-\u009F\u202A-\u202E\uFEFF]*$* reporter_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idprovenance ·
string (enum)Delivery provenance. Absent or "self" is a native self-authored report. "mimi_facade" is a service-attested report authored by the authorized receiving facade service after authenticating the source Provider and the reporter's claim and current authority. The facade never writes the reporter Actor as Event actor; source_provider_id is required only for mimi_facade.
enum:
"self" "mimi_facade"source_provider_id ·
$ref #/$defs/did_core_id · $ref #/$defs/did_core_idOrigin MIMI provider's service DID for a facade-mapped report. Required exactly when provenance is "mimi_facade"; forbidden otherwise.
evidence_refs · array<$ref #/$defs/object_ref>
items ·
$ref #/$defs/object_ref · $ref #/$defs/object_refevidence_package · object · $ref ./moderation-evidence.schema.json#/$defs/evidence_package
Canonical encrypted moderation evidence-package descriptor. target_refs names exactly the report target at admission; recipient_public_key_ref and encrypted_to MUST be byte-identical and resolve to an authorized moderator key for the report's exact effective scope. reporter_signature covers the descriptor and referenced ciphertext. The encrypted material MUST contain only reporter-visible evidence for target_refs and MUST NOT contain MLS epoch/exporter private material or unrelated plaintext.
* target_refs · array<$ref #/$defs/object_ref>
items ·
$ref #/$defs/object_ref · $ref #/$defs/object_ref* encryption ·
string* recipient_public_key_ref ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* encrypted_to_kid ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* ciphertext ·
stringBase64url without padding.
pattern:
^[A-Za-z0-9_-]+$* ciphertext_digest ·
$ref #/$defs/digest · $ref #/$defs/digestplaintext_digest ·
$ref #/$defs/digest · $ref #/$defs/digest* reporter_signature ·
stringfranking_proof · object · $ref ./moderation-evidence.schema.json#/$defs/franking_proof
Canonical receiving-service receipt used both inside a moderation report and as the complete payload of an ak.moderation.franking_proof durable Event. The local signature uses domain ak.franking_proof.signature.v1 and covers every member except signature. event_id names the encrypted Event whose receipt is proven; the enclosing proof Event has its own distinct Event.event_id.
* realm_id ·
string · $ref ./common-ids.schema.json#/$defs/realm_idRetyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern:
^ak:realm:[A-Za-z0-9_-]{44}$* event_id ·
string · $ref ./common-ids.schema.json#/$defs/event_idComplete Arkret Event cryptographic identity. The suffix is the canonical unpadded Base64URL encoding of exactly 33 octets: fixed current-v1 suite code 0x01 followed by all 32 octets of the SHA-256 Event digest. Regex validation is only lexical; receivers MUST decode, require 33 octets, require byte 0 == 0x01, canonical re-encode, and verify the full digest before use. Other registered digest suites remain available only to the typed domains that explicitly select them and MUST NOT appear in Event IDs.
pattern:
^ak:event:[A-Za-z0-9_-]{44}$* received_by ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$* verification_method ·
string · $ref ./common-ids.schema.json#/$defs/did_urlArkret verification-method DID URL profile (identity/did-usage-and-verification.md section 2.2): lowercase method name, no query, required fragment, fragment limited to ASCII [A-Za-z0-9._:-]. Every verification_method-family field and every kid/key_ref a schema declares to be a DID URL MUST resolve to exactly this definition; values compare byte-for-byte with no URI normalization or percent-decoding.
pattern:
^did:[a-z0-9]+:[^\s#?]+#[A-Za-z0-9._:-]+$* received_at ·
string (date-time) · format=date-time · $ref ./time.schema.json#/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$* replay_nonce ·
stringOpaque anti-replay nonce generated by the receiving service and covered by the proof signature.
pattern:
^[A-Za-z0-9_-]{16,256}$* signature ·
stringReceiving service signature over the canonical franking-proof transcript.
* status ·
string (enum)Authoritative moderation queue-item lifecycle. v1 is intentionally minimal: 'submitted' = report accepted and awaiting handling; 'resolved' = handling complete (terminal). The disposition (action taken vs no violation) lives on the separate ak.moderation.decision event. Additional intermediate states MAY be introduced in a later revision if a workflow phase needs them. See governance/content-moderation.md §3.3.
enum:
"submitted" "resolved"priority ·
string (enum)Local administrator workflow only: never carried in an Event payload, never part of the decision fold, never replicated across Stations, and never a capability. Omit when unassigned. See governance/content-moderation.md section 3.3.
enum:
"low" "normal" "high" "urgent"* visibility ·
string (enum)Read-side derivation over the accepted report and the target scope, in the order given in governance/content-moderation.md section 3.3: plaintext scope -> plaintext_evidence; evidence_package present -> encrypted_evidence; franking_proof only -> franking_proof_only; otherwise metadata_only. When evidence is withheld or trimmed for an unauthorized caller, this member MUST be downgraded to the evidence shape that caller can actually receive, and MUST NOT reveal whether the trimmed evidence exists. Never written by the reporter and never hard-filled with one default.
enum:
"metadata_only" "encrypted_evidence" "plaintext_evidence" "franking_proof_only"assigned_to_ids · array<$ref ./common-ids.schema.json#/$defs/did_core_id>
Local administrator workflow only; entries MUST already hold the matching moderation capability in this scope. Omit when unassigned. See governance/content-moderation.md section 3.3.
items ·
string · $ref ./common-ids.schema.json#/$defs/did_core_idCanonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern:
^ak:did_core:[a-z0-9]+:[^\s/?#]+$evidence_policy · object
Derived handling policy; omit when there is no material source. plaintext_allowed mirrors the plaintext-scope branch of visibility, franking_proof_verification_required mirrors whether the report payload carries a franking_proof. retention_expires_at and legal_hold are local retention policy and MUST NOT change the canonical decision. See governance/content-moderation.md section 3.3.
* plaintext_allowed ·
boolean* franking_proof_verification_required ·
booleanretention_expires_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$legal_hold ·
booleanaudit_refs · array<string>
Local administrator workflow only; entries MUST be Events the caller is already authorized to read. See governance/content-moderation.md section 3.3.
items ·
stringpattern:
^ak:event:[A-Za-z0-9_-]{44}$* created_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$updated_at ·
string (date-time) · format=date-time · $ref #/$defs/timestampCanonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern:
^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$Source
- registry row:
spec/v1/artifacts/registry/schema-registry.json - schema document:
spec/v1/artifacts/schemas/moderation-queue-item.schema.json