ENTITY Documentation Portal
Core tutorial 8

Package governed rights and evidence without replacing them

ENTITY passports are portable signed envelopes around existing governed state. A passport binds rights, evidence, profiles, custody references, provenance, economic state and optional BTDU information—but profile composition itself does not create authority.

1. Issue a rights passport

rights_registry = RightsPassportRegistry(STATE, identity, fabric)
passport = rights_registry.issue(
    controller=owner_id,
    object_id=object_id,
    rights=[{
        "effect":"ALLOW",
        "actions":["READ", "TRAIN"],
        "conditions":{"purpose":"research"},
        "obligations":["ATTRIBUTE_SOURCE"],
        "right_refs":[right_id],
    }],
    authority_refs=[authority_id],
    privacy_profile="SELECTIVE_DISCLOSURE",
    provenance_refs=[provenance_edge_id],
    economic_terms={"underlying_information_remains_nonrival":True},
)

The passport rules can be ALLOW, REQUIRE or PROHIBIT. The controller signs an immutable version.

2. Keep custody as a locator, not authority

custody=[{
    "provider":"example-provider",
    "locator":"bucket/object-ref",
    "content_sha256":CONTENT_SHA256,
    "provider_is_authority":False,
    "credentials_included":False,
}]

The implementation rejects a custody locator that claims the provider is authority or embeds provider credentials inside the passport.

3. Verify the passport

result = rights_registry.verify(passport)
assert result["valid"] is True

Verification checks the body hash, controller signature, core primitives and the custody/transfer/legal boundaries.

4. Supersede instead of rewriting history

If rights change, issue a new immutable version and record supersession. Do not mutate the old passport to pretend the earlier rights state never existed.

5. Build a global passport

A global passport composes an already-valid rights passport with profiles, evidence/provenance references, jurisdiction profiles, standards mappings, economic state, industry context, protocol-origin binding and optional BTDU binding.

global_registry = GlobalPassportRegistry(
    STATE, identity, fabric,
    rights_registry, profile_registry,
)
global_passport = global_registry.issue(
    owner_id,
    object_id,
    passport["passport_id"],
    profile_refs=["profile:research-data"],
    evidence_refs=[attestation_id],
    provenance_refs=[provenance_edge_id],
    economic_state={"state":"POTENTIAL", "amount_units":0, "currency":"CAD"},
)

The global passport explicitly preserves boundaries including profile_composition_does_not_create_authority, evidence_does_not_establish_objective_truth and standards_mapping_is_not_normative_equivalence.

Think of a passport as a signed portable dossier around governed state—not a magic certificate that creates rights or legal status by being printed.