diff --git a/services/ontology/schemas/company.json b/services/ontology/schemas/company.json index 227d69ec7..120cea412 100644 --- a/services/ontology/schemas/company.json +++ b/services/ontology/schemas/company.json @@ -18,6 +18,16 @@ "type": "string", "description": "MetaEnvelope ID of the canonical GroupManifest" }, + "directors": { + "type": "array", + "minItems": 1, + "uniqueItems": true, + "items": { + "type": "string", + "pattern": "^@[^\\s]+$" + }, + "description": "eNames of the directors. Any one director may create roles and grant delegations; only an existing director may change this list. The creator is the first director." + }, "legalName": { "type": "string", "description": "Registered legal name" @@ -62,6 +72,36 @@ "updatedAt": { "type": "string", "format": "date-time" + }, + "authorization": { + "type": "object", + "description": "The wallet signature, over this record's canonical form (`w3ds-grant/v1`), of the director who set or last changed `directors`: the creator for the first version, then an existing director. The eVault verifies it before accepting the write.", + "properties": { + "signerEName": { + "type": "string", + "pattern": "^@[^\\s]+$" + }, + "signedPayload": { + "type": "string", + "description": "The exact canonical string that was signed", + "minLength": 1 + }, + "signature": { + "type": "string", + "minLength": 1 + }, + "signedAt": { + "type": "string", + "format": "date-time" + } + }, + "required": [ + "signerEName", + "signedPayload", + "signature", + "signedAt" + ], + "additionalProperties": false } }, "required": [ @@ -70,5 +110,10 @@ "createdAt", "updatedAt" ], - "additionalProperties": false + "additionalProperties": false, + "dependencies": { + "directors": [ + "authorization" + ] + } } diff --git a/services/ontology/schemas/delegatedSignature.json b/services/ontology/schemas/delegatedSignature.json new file mode 100644 index 000000000..4d286b117 --- /dev/null +++ b/services/ontology/schemas/delegatedSignature.json @@ -0,0 +1,74 @@ +{ + "$schema": "http://json-schema.org/draft-07/schema#", + "schemaId": "e2736a06-176e-4004-8fda-b40b9a132669", + "title": "DelegatedSignature", + "domain": "governance", + "description": "Audit record of a signature made for a company under a Delegation. Written to the company's eVault by the platform that verified it.", + "type": "object", + "properties": { + "companyEName": { + "type": "string", + "pattern": "^@[^\\s]+$" + }, + "signerEName": { + "type": "string", + "pattern": "^@[^\\s]+$" + }, + "delegationId": { + "type": "string", + "description": "MetaEnvelope id of the Delegation used", + "minLength": 1 + }, + "title": { + "type": "string", + "description": "The signer's title at signing time" + }, + "scope": { + "type": "string", + "pattern": "^(ontology:[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}|@[^\\s:]+:[a-z][a-z0-9-]*)$", + "description": "`ontology:` or a platform-declared keyword `@:`" + }, + "documentHash": { + "type": "string", + "description": "Hash of what was signed, as named in the payload" + }, + "session": { + "type": "string" + }, + "signedPayload": { + "type": "string", + "description": "The exact `w3ds-sign/v1` string the wallet signed", + "minLength": 1 + }, + "signature": { + "type": "string", + "minLength": 1 + }, + "platformEName": { + "type": "string", + "pattern": "^@[^\\s]+$", + "description": "Platform that requested, verified and recorded the signature" + }, + "signedAt": { + "type": "string", + "format": "date-time" + }, + "createdAt": { + "type": "string", + "format": "date-time" + } + }, + "required": [ + "companyEName", + "signerEName", + "delegationId", + "scope", + "documentHash", + "signedPayload", + "signature", + "platformEName", + "signedAt", + "createdAt" + ], + "additionalProperties": false +} diff --git a/services/ontology/schemas/delegation.json b/services/ontology/schemas/delegation.json new file mode 100644 index 000000000..7519d69cf --- /dev/null +++ b/services/ontology/schemas/delegation.json @@ -0,0 +1,226 @@ +{ + "$schema": "http://json-schema.org/draft-07/schema#", + "schemaId": "0b2f15d8-c3f9-4dba-b959-5cfa11272dae", + "title": "Delegation", + "domain": "governance", + "description": "Lets a person sign for a company within some scopes. Either assigns a Role (granted by a director) or narrows a parent Delegation (re-delegation, only when the parent allows it). Lives in the company's eVault and is public so verifiers can check it.", + "type": "object", + "properties": { + "companyEName": { + "type": "string", + "pattern": "^@[^\\s]+$", + "description": "eName of the company eVault" + }, + "delegateEName": { + "type": "string", + "pattern": "^@[^\\s]+$", + "description": "Who may sign for the company" + }, + "roleId": { + "type": "string", + "description": "MetaEnvelope id of the Role this assigns", + "minLength": 1 + }, + "parentDelegationId": { + "type": "string", + "description": "MetaEnvelope id of the Delegation this narrows", + "minLength": 1 + }, + "title": { + "type": "string", + "minLength": 1, + "maxLength": 80 + }, + "scopes": { + "type": "array", + "minItems": 1, + "uniqueItems": true, + "items": { + "type": "string", + "pattern": "^(ontology:[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}|@[^\\s:]+:[a-z][a-z0-9-]*)$", + "description": "`ontology:` or a platform-declared keyword `@:`" + }, + "description": "Must be a subset of the role's or parent's scopes" + }, + "appLimits": { + "type": "object", + "description": "May only tighten the parent's app limits" + }, + "mayRedelegate": { + "type": "boolean" + }, + "validFrom": { + "type": "string", + "format": "date-time" + }, + "validUntil": { + "type": [ + "string", + "null" + ], + "format": "date-time" + }, + "grantedBy": { + "type": "string", + "pattern": "^@[^\\s]+$", + "description": "The director, or the parent delegation's delegate" + }, + "status": { + "type": "string", + "enum": [ + "active", + "revoked" + ] + }, + "revokedAt": { + "type": [ + "string", + "null" + ], + "format": "date-time" + }, + "revokedBy": { + "type": [ + "string", + "null" + ] + }, + "revocationReason": { + "type": [ + "string", + "null" + ], + "enum": [ + "revoked", + "cascade", + null + ], + "description": "`cascade` when revoked because a role or parent was revoked or narrowed" + }, + "createdAt": { + "type": "string", + "format": "date-time" + }, + "updatedAt": { + "type": "string", + "format": "date-time" + }, + "authorization": { + "type": "object", + "description": "The wallet signature of the grantor over this record's canonical form (`w3ds-grant/v1`). The eVault verifies it before accepting the write.", + "properties": { + "signerEName": { + "type": "string", + "pattern": "^@[^\\s]+$" + }, + "signedPayload": { + "type": "string", + "description": "The exact canonical string that was signed", + "minLength": 1 + }, + "signature": { + "type": "string", + "minLength": 1 + }, + "signedAt": { + "type": "string", + "format": "date-time" + } + }, + "required": [ + "signerEName", + "signedPayload", + "signature", + "signedAt" + ], + "additionalProperties": false + } + }, + "required": [ + "companyEName", + "delegateEName", + "title", + "scopes", + "mayRedelegate", + "grantedBy", + "status", + "createdAt", + "updatedAt", + "authorization" + ], + "additionalProperties": false, + "allOf": [ + { + "oneOf": [ + { + "required": [ + "roleId" + ], + "not": { + "required": [ + "parentDelegationId" + ] + } + }, + { + "required": [ + "parentDelegationId" + ], + "not": { + "required": [ + "roleId" + ] + } + } + ] + }, + { + "if": { + "properties": { + "status": { + "const": "revoked" + } + }, + "required": [ + "status" + ] + }, + "then": { + "required": [ + "revokedAt", + "revokedBy", + "revocationReason" + ], + "properties": { + "revokedAt": { + "type": "string", + "format": "date-time" + }, + "revokedBy": { + "type": "string", + "pattern": "^@[^\\s]+$" + }, + "revocationReason": { + "enum": [ + "revoked", + "cascade" + ] + } + } + }, + "else": { + "properties": { + "revokedAt": { + "type": "null" + }, + "revokedBy": { + "type": "null" + }, + "revocationReason": { + "type": "null" + } + } + } + } + ] +} diff --git a/services/ontology/schemas/role.json b/services/ontology/schemas/role.json new file mode 100644 index 000000000..49b33e6f9 --- /dev/null +++ b/services/ontology/schemas/role.json @@ -0,0 +1,169 @@ +{ + "$schema": "http://json-schema.org/draft-07/schema#", + "schemaId": "65fd0e21-34b9-43ef-be76-c5b39727010e", + "title": "Role", + "domain": "governance", + "description": "A titled bundle of signing authority a company hands out, e.g. 'Head of Finance'. Lives in the company's eVault and is public so verifiers can check it. Created and changed only by a director.", + "type": "object", + "properties": { + "companyEName": { + "type": "string", + "pattern": "^@[^\\s]+$", + "description": "eName of the company eVault" + }, + "title": { + "type": "string", + "minLength": 1, + "maxLength": 80, + "description": "Easy to remember title shown when signing" + }, + "description": { + "type": "string" + }, + "scopes": { + "type": "array", + "minItems": 1, + "uniqueItems": true, + "items": { + "type": "string", + "pattern": "^(ontology:[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}|@[^\\s:]+:[a-z][a-z0-9-]*)$", + "description": "`ontology:` or a platform-declared keyword `@:`" + }, + "description": "What holders may sign for the company. Core scopes are never accepted." + }, + "appLimits": { + "type": "object", + "description": "Platform-specific limits (e.g. maxAmount), enforced by the platform that declared them" + }, + "mayRedelegate": { + "type": "boolean", + "description": "Whether holders may pass on a narrower part of this role" + }, + "validFrom": { + "type": "string", + "format": "date-time" + }, + "validUntil": { + "type": [ + "string", + "null" + ], + "format": "date-time" + }, + "status": { + "type": "string", + "enum": [ + "active", + "revoked" + ] + }, + "revokedAt": { + "type": [ + "string", + "null" + ], + "format": "date-time" + }, + "revokedBy": { + "type": [ + "string", + "null" + ] + }, + "createdBy": { + "type": "string", + "pattern": "^@[^\\s]+$", + "description": "The director who created the role" + }, + "createdAt": { + "type": "string", + "format": "date-time" + }, + "updatedAt": { + "type": "string", + "format": "date-time" + }, + "authorization": { + "type": "object", + "description": "The wallet signature of the director making this change over this record's canonical form (`w3ds-grant/v1`). The eVault verifies it before accepting the write.", + "properties": { + "signerEName": { + "type": "string", + "pattern": "^@[^\\s]+$" + }, + "signedPayload": { + "type": "string", + "description": "The exact canonical string that was signed", + "minLength": 1 + }, + "signature": { + "type": "string", + "minLength": 1 + }, + "signedAt": { + "type": "string", + "format": "date-time" + } + }, + "required": [ + "signerEName", + "signedPayload", + "signature", + "signedAt" + ], + "additionalProperties": false + } + }, + "required": [ + "companyEName", + "title", + "scopes", + "mayRedelegate", + "status", + "createdBy", + "createdAt", + "updatedAt", + "authorization" + ], + "additionalProperties": false, + "allOf": [ + { + "if": { + "properties": { + "status": { + "const": "revoked" + } + }, + "required": [ + "status" + ] + }, + "then": { + "required": [ + "revokedAt", + "revokedBy" + ], + "properties": { + "revokedAt": { + "type": "string", + "format": "date-time" + }, + "revokedBy": { + "type": "string", + "pattern": "^@[^\\s]+$" + } + } + }, + "else": { + "properties": { + "revokedAt": { + "type": "null" + }, + "revokedBy": { + "type": "null" + } + } + } + } + ] +} diff --git a/services/ontology/schemas/shareholding.json b/services/ontology/schemas/shareholding.json new file mode 100644 index 000000000..4a0d20d32 --- /dev/null +++ b/services/ontology/schemas/shareholding.json @@ -0,0 +1,143 @@ +{ + "$schema": "http://json-schema.org/draft-07/schema#", + "schemaId": "6382a144-5c28-450e-bf47-e37c747791c2", + "title": "Shareholding", + "domain": "governance", + "description": "A holding of a company's shares. Recorded by a director; carries no signing authority.", + "type": "object", + "properties": { + "companyEName": { + "type": "string", + "pattern": "^@[^\\s]+$" + }, + "holderEName": { + "type": "string", + "pattern": "^@[^\\s]+$", + "description": "The holder, when they have an eName" + }, + "holderName": { + "type": "string", + "description": "Display or legal name of the holder", + "minLength": 1 + }, + "shareClass": { + "type": "string", + "minLength": 1, + "description": "e.g. ordinary, preference" + }, + "shares": { + "type": "integer", + "minimum": 0 + }, + "acquiredAt": { + "type": "string", + "format": "date-time" + }, + "status": { + "type": "string", + "enum": [ + "active", + "disposed" + ] + }, + "disposedAt": { + "type": [ + "string", + "null" + ], + "format": "date-time" + }, + "createdAt": { + "type": "string", + "format": "date-time" + }, + "updatedAt": { + "type": "string", + "format": "date-time" + }, + "authorization": { + "type": "object", + "description": "The wallet signature of the director recording it over this record's canonical form (`w3ds-grant/v1`). The eVault verifies it before accepting the write.", + "properties": { + "signerEName": { + "type": "string", + "pattern": "^@[^\\s]+$" + }, + "signedPayload": { + "type": "string", + "description": "The exact canonical string that was signed", + "minLength": 1 + }, + "signature": { + "type": "string", + "minLength": 1 + }, + "signedAt": { + "type": "string", + "format": "date-time" + } + }, + "required": [ + "signerEName", + "signedPayload", + "signature", + "signedAt" + ], + "additionalProperties": false + } + }, + "required": [ + "companyEName", + "shareClass", + "shares", + "status", + "createdAt", + "updatedAt", + "authorization" + ], + "anyOf": [ + { + "required": [ + "holderEName" + ] + }, + { + "required": [ + "holderName" + ] + } + ], + "additionalProperties": false, + "allOf": [ + { + "if": { + "properties": { + "status": { + "const": "disposed" + } + }, + "required": [ + "status" + ] + }, + "then": { + "required": [ + "disposedAt" + ], + "properties": { + "disposedAt": { + "type": "string", + "format": "date-time" + } + } + }, + "else": { + "properties": { + "disposedAt": { + "type": "null" + } + } + } + } + ] +}