Code tutorial 6 - tested
Encrypt bytes and enforce one-use purpose access
Store encrypted bytes, grant one bounded RESEARCH/READ use, consume it, then prove a second use fails closed.
Verified against: ENTITY main commit
5be325437a63c2efaee0dc3caaae9ab0cd0773d9. The run uses disposable tutorial state only.Watch the tutorial
This browser-safe video is a terminal replay built from the exact published source and recorded execution for tutorial 6. The full source and transcript remain available below for reproduction.
Run it yourself
$env:ENTITY_ROOT="C:\path\to\ENTITY" python vault_purpose_access.py
Download/view the exact Python example - Recorded terminal transcript - Execution record
Exact source used
from pathlib import Path
import importlib.util, hashlib, os, shutil, time
ROOT=Path(os.environ.get("ENTITY_ROOT", Path.cwd())).resolve()
STATE=ROOT/".tutorial-test-state"/"vault-purpose-access"
if STATE.exists(): shutil.rmtree(STATE)
def load_source(path,name):
spec=importlib.util.spec_from_file_location(name,ROOT/path); mod=importlib.util.module_from_spec(spec); spec.loader.exec_module(mod); return mod
identity_mod=load_source("src/01_Core_Runtime/identity/canonical_identity.py","entity_identity")
vault_mod=load_source("src/08_Data_Vaults/canonical_encrypted_vault.py","entity_vault")
privacy_mod=load_source("src/35_Global_Infrastructure/privacy_provenance.py","entity_privacy")
identity=identity_mod.EntityIdentityVault(STATE)
owner=identity.create("Tutorial Owner","organization"); reader=identity.create("Tutorial Reader","person")
vault=vault_mod.EncryptedDataVault(STATE)
item=vault.put_bytes(owner["entity_id"],b"confidential tutorial payload",media_type="text/plain",classification="PRIVATE")
assert vault.read_bytes(owner["entity_id"],item["vault_object_id"]) == b"confidential tutorial payload"
access=privacy_mod.PurposeBoundAccessRegistry(STATE,identity)
grant=access.grant(owner["entity_id"],reader["entity_id"],item["vault_object_id"],purposes=["RESEARCH"],actions=["READ"],expires_at_ms=int(time.time()*1000)+60000,max_uses=1)
use_hash=hashlib.sha256(b"tutorial-read-session").hexdigest(); use=access.authorize_use(grant["grant_id"],reader["entity_id"],"RESEARCH","READ",use_hash)
assert use["authorized"] is True and use["remaining_uses"] == 0
second="NOT_BLOCKED"
try: access.authorize_use(grant["grant_id"],reader["entity_id"],"RESEARCH","READ",use_hash)
except PermissionError: second="BLOCKED"
assert second=="BLOCKED"
print(f"VAULT_OBJECT={item['vault_object_id']}"); print("OWNER_READ=PASS"); print("PURPOSE_BOUND_READ=PASS"); print("SECOND_USE=BLOCKED"); print("CLAIM_BOUNDARY=encrypted custody and bounded access do not establish ownership")
Recorded successful run
ENTITY source commit: 5be325437a63c2efaee0dc3caaae9ab0cd0773d9 Recorded on: 2026-09-30 (America/Vancouver) Command: $env:ENTITY_ROOT='E:\ENTITY_ACTIVE\ENTITY_TUTORIAL_TEST' E:\ENTITY_ACTIVE\PYTHON311_EMBED\python.exe vault_purpose_access.py Output: VAULT_OBJECT=vobj1-74a05f86789fa0ed8412e41748b36e24c5fa375d OWNER_READ=PASS PURPOSE_BOUND_READ=PASS SECOND_USE=BLOCKED CLAIM_BOUNDARY=encrypted custody and bounded access do not establish ownership Note: generated identifiers and hashes may differ on each run while the documented invariants must remain the same.
What this demonstrates
- Encrypted bytes can be recovered by the owner.
- The bounded purpose/action grant authorizes exactly one use.
- A second use is rejected after the use cap is exhausted.
Claim boundary: Encrypted custody and a purpose-bound access grant do not establish ownership of the subject.