ENTITY Documentation Portal
Core tutorial 10

Operate across core, edge, satellite and offline nodes without giving infrastructure authority

ENTITY's global topology is designed for disconnected and federated operation. Nodes can host, transport and checkpoint state, but topology membership itself never grants sovereign authority.

1. Register topology nodes

topology = TopologyRegistry(STATE, identity)
core = topology.register_node(
    operator=core_operator_id,
    node_id="core-ca-01",
    topology_class="CORE",
    jurisdiction="CA",
    trust_domain="btg-core",
    capabilities=["RESOLUTION", "SETTLEMENT"],
)
edge = topology.register_node(
    operator=edge_operator_id,
    node_id="edge-field-01",
    topology_class="EDGE",
    jurisdiction="CA",
    trust_domain="field-team",
    capabilities=["OFFLINE_CAPTURE"],
)

Supported topology classes are CORE, REGIONAL, EDGE, SATELLITE and OFFLINE. Node registration is signed by the operator and explicitly states that infrastructure membership is not sovereign authority.

2. Publish causal checkpoints

sync = PartitionSync(STATE, identity)
cp1 = sync.publish(
    node_id="edge-field-01",
    operator=edge_operator_id,
    partition_id="incident-123",
    sequence=1,
    epoch=1,
    state_root_sha256=STATE_ROOT,
    vector_clock={"edge-field-01":1},
)

Subsequent checkpoints must increase sequence by one and link the previous checkpoint hash.

3. Create an offline envelope

envelope = OfflineEnvelope.create(
    identity,
    actor=operator_id,
    node_id="edge-field-01",
    partition_id="incident-123",
    sequence=2,
    payload=payload,
    expires_at_ms=EXPIRY_MS,
)
result = OfflineEnvelope.verify(identity, envelope)
assert result["valid"] is True

The envelope is signed, content-bound and expiry-bounded. Valid offline evidence is still not automatic merge authority.

4. Merge partitions causally

merge = sync.merge("incident-123")

If all current checkpoints share a state root, ENTITY can report converged state. If one checkpoint causally dominates the others, it can be selected. If two states are concurrent and divergent, merge returns a conflict and explicitly prohibits automatic last-writer-wins.

5. Treat conflicts as governance/evidence events

A concurrent divergent state needs resolution under the relevant authority/policy. The node with the newest wall-clock timestamp is not automatically correct.

This is sovereignty as an engineering property: the network can partition and reconnect without silently transferring decision authority to the fastest server, latest timestamp or largest provider.