跳转到内容

ak.schema.realm_organization_operations.v1

← Schemas

Arkret Realm Organization-Relationship Read Operation DTOs
ak.schema.realm_organization_operations.v1 · file: schemas/realm-organization-operations.schema.json

Closed response DTO for the self-surface Realm organization-relationship read operation (ak.self.realm_organization.read.list.v1). Returns the projected ak.realm.organization statements (active / revoked / expired) for a Realm plus the declared owning_organization_ids hints that have no verified statement. The verified rows mirror the canonical realm_organization_payload field order; lifecycle_phase is reducer-derived. A row here is a projection only: an organization relationship is only verified when lifecycle_phase=verified_active, and actual Realm control still requires the corresponding Realm policy, governance-Station authority, capability, or service-binding Event. See spec/v1/zh/models/realm-and-space.md §2.3.0 and schemas/event-payload.schema.json#/$defs/realm_organization_payload.

* $ · anyOf[1]
Closed response DTO for the self-surface Realm organization-relationship read operation (ak.self.realm_organization.read.list.v1). Returns the projected ak.realm.organization statements (active / revoked / expired) for a Realm plus the declared owning_organization_ids hints that have no verified statement. The verified rows mirror the canonical realm_organization_payload field order; lifecycle_phase is reducer-derived. A row here is a projection only: an organization relationship is only verified when lifecycle_phase=verified_active, and actual Realm control still requires the corresponding Realm policy, governance-Station authority, capability, or service-binding Event. See spec/v1/zh/models/realm-and-space.md §2.3.0 and schemas/event-payload.schema.json#/$defs/realm_organization_payload.
anyOf · anyOf[0] · object · $ref #/$defs/realm_organization_relationship_list
* realm_id · string · $ref ./common-ids.schema.json#/$defs/realm_id
Retyped ak.realm.create Event token. It therefore carries the same fixed current-v1 0x01/SHA-256 content-address identity and is not selected by Realm state.
pattern: ^ak:realm:[A-Za-z0-9_-]{44}$
* relationships · array<$ref #/$defs/realm_organization_relationship_row>
Projected ak.realm.organization statement rows (verified_active and revoked_or_expired), latest-per-(organization_id, relationship).
items · object · $ref #/$defs/realm_organization_relationship_row
* statement_id · allOf[2]
allOf · allOf[0] · string · $ref #/$defs/non_empty_string
allOf · allOf[1] · ? · $ref string-profiles.schema.json#/$defs/non_typed_identifier_floor
Lexical floor of every identifier value category that does NOT own the ak: namespace (opaque_correlation, document_local_symbol, external_system_identifier, registry_catalog_symbol, unregistered_object_identifier); see common-fields.md 2.1. The negative lookahead IS the floor: it mechanically proves the value cannot be an ak: typed id, which maxLength alone can never prove, while admitting every other value the field already accepted. It deliberately constrains nothing else - the per-field convergence direction (a registered typed kind, or a tighter opaque profile) is decided per object family, so a pattern-only floor composes with whatever profile the field already carries instead of pre-empting it.
pattern: ^(?!ak:)
* organization_id · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$
* relationship · string (enum) · $ref #/$defs/relationship
enum: "owner" "governance" "sponsor" "directory_certifier"
* status · string (enum) · $ref #/$defs/status
enum: "active" "revoked"
* control_scopes · array<$ref #/$defs/control_scope>
items · string (enum) · $ref #/$defs/control_scope
enum: "official_badge" "realm_admin" "realm_authority" "moderation_policy" "retention_policy" "directory_listing" "plaintext_visible_service"
* issued_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
not_before · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
expires_at · oneOf[2] · $ref #/$defs/nullable_timestamp
oneOf · oneOf[0] · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
oneOf · oneOf[1] · null
supersedes_statement_id · allOf[2]
allOf · allOf[0] · string · $ref #/$defs/non_empty_string
allOf · allOf[1] · ? · $ref string-profiles.schema.json#/$defs/non_typed_identifier_floor
Lexical floor of every identifier value category that does NOT own the ak: namespace (opaque_correlation, document_local_symbol, external_system_identifier, registry_catalog_symbol, unregistered_object_identifier); see common-fields.md 2.1. The negative lookahead IS the floor: it mechanically proves the value cannot be an ak: typed id, which maxLength alone can never prove, while admitting every other value the field already accepted. It deliberately constrains nothing else - the per-field convergence direction (a registered typed kind, or a tighter opaque profile) is decided per object family, so a pattern-only floor composes with whatever profile the field already carries instead of pre-empting it.
pattern: ^(?!ak:)
revokes_statement_id · allOf[2]
allOf · allOf[0] · string · $ref #/$defs/non_empty_string
allOf · allOf[1] · ? · $ref string-profiles.schema.json#/$defs/non_typed_identifier_floor
Lexical floor of every identifier value category that does NOT own the ak: namespace (opaque_correlation, document_local_symbol, external_system_identifier, registry_catalog_symbol, unregistered_object_identifier); see common-fields.md 2.1. The negative lookahead IS the floor: it mechanically proves the value cannot be an ak: typed id, which maxLength alone can never prove, while admitting every other value the field already accepted. It deliberately constrains nothing else - the per-field convergence direction (a registered typed kind, or a tighter opaque profile) is decided per object family, so a pattern-only floor composes with whatever profile the field already carries instead of pre-empting it.
pattern: ^(?!ak:)
realm_commit_ref · string · $ref #/$defs/digest
pattern: ^(sha256|blake3):[0-9a-f]{64}$
* issuer_role · string (enum) · $ref #/$defs/issuer_role
enum: "organization" "governance_service" "account_authority" "threshold_quorum"
delegation_ref · string · $ref #/$defs/non_empty_string
Resolved authorization.delegation_ref for delegated issuer roles (governance_service / account_authority).
* lifecycle_phase · string (enum) · $ref #/$defs/lifecycle_phase
Reducer-derived lifecycle phase of the projected statement. verified_active = latest accepted statement for (organization_id, relationship) is status=active and within its validity window. revoked_or_expired = the relationship has been revoked or is outside its not_before/expires_at window. Declared-only organization hints with no statement are carried in declared_organization_hint_ids, not as rows.
enum: "verified_active" "revoked_or_expired"
updated_at · string (date-time) · format=date-time · $ref #/$defs/timestamp
Canonical Arkret-owned absolute instant. UTC Z form with exactly three millisecond digits. Whole seconds MUST use .000Z; offsets, missing/finer fractions, lowercase separators, leap seconds, and invalid Gregorian calendar dates are forbidden. Shape validation by this pattern is supplemented by semantic date validation.
pattern: ^[0-9]{4}-(0[1-9]|1[0-2])-(0[1-9]|[12][0-9]|3[01])T([01][0-9]|2[0-3]):[0-5][0-9]:[0-5][0-9]\.[0-9]{3}Z$
* declared_organization_hint_ids · array<$ref #/$defs/did_core_id>
owning_organization_ids declared hints (realm-and-space.md §2.3.0) that have NO verified ak.realm.organization statement. These are unverified claims and MUST NOT be rendered as official / governed / endorsed.
items · string · $ref #/$defs/did_core_id
Canonical stable DID-derived identity core. The lowercase DID method name follows ak:did_core:, and the remaining method-adapter-defined core is opaque to generic consumers. The did:web v1 adapter uses the complete canonical method-specific-id, never a digest or truncated host. Principal-core and service-core equality is byte-for-byte equality of the complete did_core_id. Event actor and Realm membership equality instead use the complete closed ActorId, and account-scoped equality uses the complete AccountId; neither may be reduced to a principal core. A did_core_id is not a DID and cannot be resolved without a did or AuthenticatedServiceResolution.
pattern: ^ak:did_core:[a-z0-9]+:[^\s/?#]+$

Source