Package governed rights and evidence without replacing them
ENTITY passports are portable signed envelopes around existing governed state. A passport binds rights, evidence, profiles, custody references, provenance, economic state and optional BTDU information—but profile composition itself does not create authority.
1. Issue a rights passport
rights_registry = RightsPassportRegistry(STATE, identity, fabric)
passport = rights_registry.issue(
controller=owner_id,
object_id=object_id,
rights=[{
"effect":"ALLOW",
"actions":["READ", "TRAIN"],
"conditions":{"purpose":"research"},
"obligations":["ATTRIBUTE_SOURCE"],
"right_refs":[right_id],
}],
authority_refs=[authority_id],
privacy_profile="SELECTIVE_DISCLOSURE",
provenance_refs=[provenance_edge_id],
economic_terms={"underlying_information_remains_nonrival":True},
)The passport rules can be ALLOW, REQUIRE or PROHIBIT. The controller signs an immutable version.
2. Keep custody as a locator, not authority
custody=[{
"provider":"example-provider",
"locator":"bucket/object-ref",
"content_sha256":CONTENT_SHA256,
"provider_is_authority":False,
"credentials_included":False,
}]The implementation rejects a custody locator that claims the provider is authority or embeds provider credentials inside the passport.
3. Verify the passport
result = rights_registry.verify(passport) assert result["valid"] is True
Verification checks the body hash, controller signature, core primitives and the custody/transfer/legal boundaries.
4. Supersede instead of rewriting history
If rights change, issue a new immutable version and record supersession. Do not mutate the old passport to pretend the earlier rights state never existed.
5. Build a global passport
A global passport composes an already-valid rights passport with profiles, evidence/provenance references, jurisdiction profiles, standards mappings, economic state, industry context, protocol-origin binding and optional BTDU binding.
global_registry = GlobalPassportRegistry(
STATE, identity, fabric,
rights_registry, profile_registry,
)
global_passport = global_registry.issue(
owner_id,
object_id,
passport["passport_id"],
profile_refs=["profile:research-data"],
evidence_refs=[attestation_id],
provenance_refs=[provenance_edge_id],
economic_state={"state":"POTENTIAL", "amount_units":0, "currency":"CAD"},
)The global passport explicitly preserves boundaries including profile_composition_does_not_create_authority, evidence_does_not_establish_objective_truth and standards_mapping_is_not_normative_equivalence.