Skip to main content

Module governance

Module governance 

Source
Expand description

Guarded Asset classification and operator-owned preserving conversion. Both direct and libpq Sessions use the same transaction/function boundary.

Structs§

DisclosureIntent
DisclosureSnapshot
Evidence of a metadata decision, never by itself permission to return bytes.
GovernanceAppointment
Explicit appointment. Never inferred from the first Study creator.
GovernanceLedgerBinding
GovernanceMaintenance
Narrow governance maintenance over administrator authority already resolved for the Session. No configuration documents or Secret stores are reopened.
GovernanceUpgrade
GovernanceUpgradePlan
LegacyDatafileOrigin
LegacyDatasetOrigin
UnfinishedDisclosure

Functions§

abandon_disclosure
The application must prove executor exclusion before calling this operator function. It terminalizes evidence without recreating user authority.
admit_disclosure
admit_disclosure_with_datafile
admit_disclosure_with_inputs
Keep the metadata policy/version locks until the Lake adapter has captured immutable input capabilities. A failed capture rolls the decision back.
admit_disclosure_with_semantic_inputs
bind_datafile
bind_dataset_location
Only the resolved operator capability may attest an actual Lake table.
capture_derivation_inputs
Computation may consume high inputs, but has no content-delivery capability. The final output admission independently revalidates its forced-high policy.
classification
finish_disclosure
ledger_binding
Operator-only binding; the application uses this to open the system ledger through the Lake adapter. It contains no physical location or credential.
pending_evidence
Bounded operator recovery inventory. Pending older disclosure completions are independent of the evidence required by a new admission.
project_evidence
Serialize one event’s projection across workers and both durable stores. The callback must append and read back the identical event in the ledger. A lost acknowledgement leaves an independently retryable outbox event.
reclassify
The database rechecks current owning-Study custodianship and revision while holding the same locks used for admission. This is an all-version decision.
required_evidence
scoped_evidence_ids
Current owning-Study custodians and the appointed governance custodian may discover only acknowledged event identities through the ordinary Session.
start_disclosure
unfinished_disclosures