Rights are explicit, machine-readable state
Authority answers who may act. Rights answer what a grantee may do with a governed object. ENTITY deliberately separates those concepts.
Rights actions
INSPECT · READ · COPY · DERIVE · TRAIN · INFER · EXECUTE · MODIFY · REDISTRIBUTE · COMMERCIALIZE · CONTROL · TRANSFER
1. Grant only the needed actions
right = fabric.grant_right(
object_id,
grantor_entity_id=owner_id,
grantee_ref=researcher_id,
actions=["READ", "TRAIN", "DERIVE"],
constraints={
"purposes":["climate-research"],
"jurisdictions":["CA"],
},
economic_terms={
"price_units":25000,
"currency":"CAD-CENTS",
},
expires_at_ms=EXPIRY_MS,
)The record explicitly states access_is_not_ownership=true. Giving TRAIN does not silently give COMMERCIALIZE. Giving READ does not give REDISTRIBUTE.
2. Evaluate a right at use time
allowed = fabric.active_right(
object_id,
researcher_id,
"TRAIN",
purpose="climate-research",
jurisdiction="CA",
)
assert allowed is not None3. Negative tests matter
assert fabric.active_right(
object_id,
researcher_id,
"COMMERCIALIZE",
purpose="climate-research",
jurisdiction="CA",
) is None
assert fabric.active_right(
object_id,
researcher_id,
"TRAIN",
purpose="advertising",
jurisdiction="CA",
) is NoneA real integration should make these failures visible. Do not “helpfully” broaden a right because the caller is authenticated or has physical access to the bytes.
4. Revoke it
fabric.revoke_right(owner_id, right["right_id"])
assert fabric.active_right(
object_id, researcher_id, "TRAIN",
purpose="climate-research", jurisdiction="CA"
) is None5. Separate byte possession from legal/economic permission
A recipient may possess a copy while the governed right expires or is revoked. ENTITY records the rights state around the information; it does not pretend non-rival information bytes become physically scarce.