ENTITY Documentation Portal
Developer manual · portable governed state

Global Passport API

The Global Passport is a portable envelope over existing ENTITY identity, rights, evidence and provenance. It is not a new sovereignty root and it does not make a domain package or standards mapping authoritative over the underlying Entity.

Conceptual input

ENTITY state + rights + evidence → Global Passport envelope → profile stack → standards mappings → continuous provenance/derivation → domain package

A passport should bind the exact underlying objects and evidence it represents. Profile and mapping metadata add context, policy and interpretation constraints; they must not silently create ownership, authority, compliance or external-world truth.

Profiles

Profiles are versioned configuration/constraint layers. A deployment can compose jurisdictional, industry, privacy, trust and technical profiles. The registry is versioned so a verifier can determine which profile semantics were in force when a passport was created.

Standards mappings

Mappings describe correspondence between ENTITY fields/claims and external standards. They do not redefine HL7 FHIR, DICOM, ISO 20022, FIX, LEI, OPC UA, Asset Administration Shell, NIST AI RMF, SPDX, CycloneDX, ROS 2, Open-RMF or any other external standard. The external standard remains authoritative for its own semantics.

Continuous provenance

When governed artifacts evolve, new passport derivations should point back to the source state/evidence rather than rewriting history. A later passport may supersede an earlier operational state, but historical signed passports remain independently verifiable.

Verification order

  1. Validate canonical serialization/schema requirements.
  2. Verify signatures and issuer/controller authority.
  3. Resolve the exact profile versions referenced by the passport.
  4. Verify embedded/referenced rights and evidence objects.
  5. Verify provenance/derivation links.
  6. Evaluate domain-specific conformance checks.
  7. Keep external-world conclusions outside the protocol unless supported by separate evidence.

Domain packages

Healthcare, Finance, Manufacturing, AI, Robotics and Defence/Public-Unclassified are deployable packages for the same Global Passport. Each package can include schemas, mappings, templates, fixtures, SDK material and a verifier. They do not create six passport protocols.

v3.4.2 relationship

BTDU can hold the governed information topology and exact object/evidence relationships that feed higher-level passports. The passport remains an ENTITY governance envelope; BTDU topology does not itself manufacture rights or entitlement.