Developers
The developer surface — what software does with a Tacit Tessera number.
This page is a specification: it says how the register is built to work. It is written for the people who put a number into software — a platform team, an agent builder, a control-system engineer at a machine maker, an integrator wiring a fleet's back office — and it says what a program asks the register, what the register answers, and what it refuses to answer however the question is put.
This page answers the path I am building with knowledge — Resolve the number. Read the Card. Check the licence. Report the use.
Everything below is stated in the present tense because it is a design, and the present tense is the honest one for a thing that is specified. The words on this page are the register's own: the Card, the edition, the seal, the Manifest, the rights expression, the twelve actions, cover, the usage receipt.
This page is a specification: it says how the register is built to work.
It carries no label saying so a second time. The word this estate uses for a thing written down before it is built is specification, and a specification is written the way this one is written — in the designed tense, with every field named, every answer given and every refusal stated, so that the thing which is built is built to it rather than described after the fact. There is no version number on this page and no date, because a specification that moves with a number is a changelog, and the register's changes are recorded against editions, not against pages.
What you may rely on here. Every answer, field and refusal below is ruled by the register's own standard. Where a question is open it is named as open on this page, in the same sentence as the thing it is open about, and it is pointed at counsel rather than resolved in copy. Two are open and both are named: what governs where the words of a licence and its machine-readable expression differ, and what a signed row must carry and be retained for to be useful in a dispute.
What is not here, and will not appear here later in a smaller font. There is no kit to download, no test service to sign into, no second address to point a program at, and no schema on offer. A surface that is not designed is not described on this page in any form — not as an intention, not as a direction, not as a thing under consideration.
Who reads this page, and what each one is reading for. For the person in the seat it is the reason a count can be read back to their own number years later, because the row a program writes is the row they are paid from. For an OEM's procurement officer it is what a supplier is being asked to build, in enough detail to be written into a specification or a tender. For counsel it is where the open questions sit and who answers them.
A developer resolves the number, reads the public Card, checks the seal, reads the Manifest, asks whether the licence covers this number and this edition, and reports the use.
Six steps, and they are the whole of the working relationship between a program and this register. They run in that order because each one depends on the one before it: there is nothing to read until the number resolves, nothing to check until the Card is read, nothing to ask about until the edition is fixed, and nothing to report until the use has happened.
- Resolve the numberTen characters, the sector first, the last character computed and never typed. The register answers whether the number is well formed and whether it knows it.
CH1001CV17 - Read the public CardWhat the entry is, in the register's own words: number, name, status, tile and scope statement.
- Check the sealAn edition is sealed, and its seal can be checked. Nothing is stored as a verdict; every check is recomputed from the sealed Card, every time.
- Read the Tacit Tessera ManifestThe Card's machine-readable form, one record per edition, emitted by the register.
- Ask whether the licence covers this number and this editionThe register answers from the licence it recorded. It answers about the licence, never about the work.
- Report the useOne signed row, handed to the licensee and read from both ends.
Step one, resolve the number. A number is ten characters and it is the address of one skill set. A program hands the register the machine form and the register answers whether the last character is the one the other nine compute to, and whether the register knows the number at all. Those are two different answers and they are given separately: a number that is typed wrong is a typing fault, and a number that is well formed but unknown is a different fact about the world. A nine-character number with no sector letter in front is an old-form number, and the register says so rather than calling it a typo. How the numbering works takes the grammar apart character by character.
Step two, read the public Card. The public side of a Card shows five things — number, name, status, tile and scope statement — and a program reads those and nothing else from the public side. The scope statement is the sentence that says what the entry covers and where it stops, and it is the field a program should show a human before anything runs. Cards takes the Card apart group by group.
Step three, check the seal. An edition is frozen, and what makes it checkable is its seal. A program checks a seal in order to know that the Card it is holding is the Card the register holds, and that the edition it pinned is the edition it is still running. The check is recomputed from the sealed Card on every lookup, so a stored answer is never authority and a printed card is never authority; the address is.
Step four, read the Manifest. A program cannot act on a page. The Manifest is the same Card in a form software reads, and it is where the rights group sits — the consents, the licence kinds offered, the actions named one by one, the conditions and the rights state. Section 04 says what it is and what is not offered with it.
Step five, ask whether the licence covers this number and this edition. This is one question and no more, and it is answered from the licence the register recorded. It is not a decision about whether the work should go ahead. Section 07 says what is asked, what comes back and what never comes back.
Step six, report the use. A use produces one signed row. That row is the count, and the count is the economic record; it is read from both ends, by the licensee and by the register, so that what is owed can be worked out from a record both sides hold. Section 08 names the row's fields.
Nothing in the six steps asks a program to hold the material a skill set was made from, and nothing in them hands a program a copy of it. What travels is an address, a description, a seal, a permission and a receipt.
The check answers four things and nothing else.
Any reader, authenticated or not, is answered these four and no more:
- The check character Whether the check character is valid — whether the number was typed correctly. A nine-character number with no sector letter in front is an old-form number, and the page says so rather than calling it a typo.
- Whether it is known Whether the register knows the number.
- Its status Its status.
- The edition Whether this edition is the current one.
It does not say who holds a licence, what a skill set is worth, how it was tested, or anything about the person behind it. That refusal is the shape of the whole surface and it does not soften for an authenticated caller: a licensee is told more about its own licence and nothing more about anybody else's.
To an authenticated licensee, about its own licence only, the Verify API also answers whether the licence covers this number and edition, the licence kind, the meter class, the context envelope, and whether the number is frozen under a challenge. It refuses who owns it, who the person is beyond the licence name, whether other copies exist, whether the skill is any good, any figure and any evaluation result. There is no list, browse, bulk or export endpoint.
Nothing is stored as a verdict. Every check is recomputed from the sealed Card, every time. There is no cached answer to go stale and no ticket to hold up as authority after the fact; a program that needs to know the answer now asks now.
Every entry the check can find reads Specified. That is the one public status word on this register, and a program should treat it as a word rather than as a rung — there is no ladder beneath it and no ladder above it. Verify is the same check, run by a person in a browser, and it owns the explanation of what a check shows.
A resolved number, marked EXAMPLE, reads like this. The specimen is a real catalogue entry; the person behind it is an EXAMPLE.
Request
GET /verify/CH1001CV17
Response · EXAMPLE
{
"example": true,
"number_human": "C H 1 001 CV · 1",
"number_machine": "CH1001CV17",
"check_character": "valid",
"known": true,
"status": "Specified",
"edition": 1,
"edition_is_current": true,
"seal": {
"state": "sealed",
"checkable_at": "/verify/CH1001CV17"
}
}Four answers, and the seal. No licensee, no figure, no identity, and no word that reads as a verdict.
A program that wants more than those four things about an entry it does not license is asking the register to be something it is not. The four are not a starting set that grows with a better tier of access; they are the answer, and section 09 says why.
The Tacit Tessera Manifest is the Card's machine-readable form: a serialisation of a Card that already exists and is already sealed, not a second object.
It is one record per edition, emitted by the register. It is not a file a licensee keeps and edits, not a passport a machine carries around, and not a parallel record that could drift from the Card; if the Card changes, it is because a new edition was sealed, and the Manifest of the old edition still reads exactly as it did.
What it carries, in five groups: Identity — the number, the edition, the seal and the status. Who — the source, the house that collected it, who owns what is made of the skill, and who licenses it. What — the sector, track, family and trade, the kind of knowledge it is, the scope statement, what it refuses, and the context envelope. Rights — the consents, the licence kinds offered with their actions, the conditions and the rights state. Provenance — what it was built from, any set membership, and the event history. Cards owns the Card and takes each group apart in full.
What is never in it. No share, weight or proportion; no price, rate or royalty schedule; no identity beyond the licence name; no count of jobs, hours or regions; no outcome measured on a person; no ranking, grade, score, star or badge; no real client, job number or rate; no claim of ownership and no claim that no other copy exists; and nothing about insurance, underwriting, assessment or indemnity. Where a field's value would be a figure, the field carries its class and not its value.
The seal field is named seal. The register's public words are sealed and its seal can be checked, and the Manifest uses the same word for the same reason: what a reader needs is the fact that an edition is fixed and checkable, and the way it is computed is the standard's business rather than a page's.
The schema is not offered here. On what terms it may be published is a question for counsel, and it is open. Until it is answered this page describes the Manifest and hands out nothing: no schema address, no file, no export. The Manifest is what the register holds about an entry; it is not a copy of the skill set, and no arrangement on this page turns it into one.
A licence carries a machine-readable expression of the permissions it grants.
What it is. A licence is an agreement between two parties, written in words and signed. The rights expression is that agreement's permissions restated in a structure a program can read: the entry it is about, the actions allowed and the actions not granted, the term, the field of use, the territory, the meter class the count is taken in, the conditions, and how attribution is to be carried. It is emitted with the Manifest and it moves with the licence, not with the skill set.
Why it exists in this register. A machine cannot read a contract, and a person cannot re-read one at every use. Without a machine-readable form, a permission survives only as far as the first integration that forgets it: the edition drifts, the field of use is nobody's job, the condition a contributor put on their own skill is a sentence in a document nobody opened, and the count runs against nothing. This register exists so that a skill set arrives at a machine with its permissions attached and legible, and the rights expression is the form that attachment takes.
What it records. The number and the edition, so that a permission is never about a skill set in general. The twelve actions, each one granted or not granted on its own — section 06. The term, the field of use and the territory, which are the three limits every licence kind carries. The meter class, which names what the licence is counted on. The conditions a contributor put on what is made of their skill, which travel on the Card and in the licence. And the rights state as it stood when the licence was taken.
What it never decides. It is not a lock, it is not a policy engine and it is not an opinion about whether a use is wise. The agreement governs; the expression states it to software. Where the two differ, the words of the agreement are what a court reads, and the expression is evidence of what the parties told each other's systems. It has no name of its own, no version of its own and no authority of its own.
What is open, and where it goes. Where the prose of a licence and the machine-readable expression of the same permissions differ, which governs — and whether the structured form binds the operator of a machine who never read the prose — is a question for counsel, not for this page. It is with counsel, and the legal position is where the register's open questions are written out in the same three-step shape: the question, that it is open, and what is built so that the answer does not change what the person in the seat gets.
The three readers. For the person in the seat the expression is the reason a condition they set — a field of use, a territory, no use for surveillance, no unattended operation, a house kept away from their skill — reaches the machine instead of stopping at a filing cabinet. For an OEM's procurement officer it is the thing that makes a licence auditable without a lawyer in the loop for every run. For counsel it is an evidentiary record of what was permitted and when, and the open question above is theirs.
What is licensed is not a licence but a list of things that may be done.
Three licence kinds are offered — execution, learning and derivative — and inside each of them the actions are named one by one, so that what is licensed is not a licence but a list of things that may be done. The three kinds are the shape of the paper and they do not change; the twelve actions are the grain inside them, and they are what a program reads.
| Action | What it permits | Sits under |
|---|---|---|
| VIEW | A person may inspect the material. | execution |
| QUERY | A system may search and retrieve against it. | execution |
| INFER | A system may use it while answering. | execution |
| TRAIN | It may be used to build a model. | learning |
| FINE-TUNE | It may be used to adjust a model already built. | learning |
| EMBED | It may be turned into another machine representation. | learning |
| EXECUTE | A machine may run the way of working. | execution |
| SIMULATE | It may be run against a model of the work rather than against the work. | execution |
| EVALUATE | It may be used to test a machine. The machine is tested, never the person. | an Evaluation set's own licence |
| DERIVE | A new artefact may be made from it, and its ancestry is declared. | derivative |
| REDISTRIBUTE | A licensed representation may be passed onward. Not granted by this register. | named, not granted |
| SUBLICENSE | A licensee may grant rights downstream. Not granted by this register. | named, not granted |
The register does not grant REDISTRIBUTE or SUBLICENSE. They are named so that a licence can say they are not granted. A program reading a rights expression will find them in the list with the answer against them, which is the point: a permission that is absent from a vocabulary is ambiguous, and a permission that is present and denied is not.
EXECUTE is the one to read carefully. It permits that a machine may run the way of working. It is not a statement that a machine runs without a person, and the condition a contributor may set against running without one is written no unattended operation. The decision to run belongs to the operator and the machine, and it is never something a rights record hands over.
An action is not a status. It never appears as a badge, a chip, a tick or a value on a public status line. It appears in a licence and in the Card's rights group, and nowhere else.
Where DERIVE is granted, the register records the ancestry the licensee declares, and certifies nothing about it; a declared descendant is a recorded declaration, not a finding. What the register can show about a derived model is what was licensed for it, and nothing about what the model now contains. The rule for ending a learning or derivative licence is a date, not a switch: Material used to build a model comes out at the model's next revision, and that date is stated to the person before they sign. The register never claims a model has forgotten anyone.
Rights owns the mapping of the twelve to the three kinds and the four consents beneath them; License owns the licence kinds themselves, with the term, the field of use and the territory each one carries.
The register answers from the licence, not about the work.
Before a use, a licensee may ask whether its licence covers this number and this edition. The register answers from the licence, not about the work. The register's word for that answer is cover, and the word is chosen carefully: it describes the register reading back a licence it already recorded, which is a different act from deciding anything.
The register records; it does not decide.
What is asked. The number, the edition, the action out of the twelve, and the licence the caller holds. What is answered. Whether the licence covers this number and this edition; the licence kind; the meter class; the context envelope; and whether the number is frozen under a challenge. The answer is in words, and it is about the licence.
What is never answered. Whether the work should go ahead. Whether the task is a good idea, whether the jurisdiction allows it, whether the machine is fit, whether the operator is ready, whether the conditions on the day are right. None of those is a question about a licence, and the register has no facts with which to answer any of them.
A licence permits a use; it never requires one. The machine's own safety logic refuses whenever it refuses. A program that treats a coverage answer as a release to run has built a safety case out of a rights record, and this register will not be part of one. Rights policy never asserts safety.
A licence is kept against the Card's seal and the date the coverage was answered, so a licensee can say which rights state it relied on, and when — Cards owns that snapshot and what it is made of.
A coverage question and its answer, marked EXAMPLE, read like this. A licensee asks about its own licence and nothing else.
Request · EXAMPLE
{
"number": "CH1001CV17",
"edition": 1,
"action": "EXECUTE"
}Answer · EXAMPLE
{
"example": true,
"answer": "the licence covers this number and this edition",
"licence_kind": "execution",
"actions": ["VIEW", "QUERY", "INFER", "EXECUTE", "SIMULATE"],
"meter_class": "hour",
"context_envelope": "as recorded on the Card",
"frozen_under_challenge": false,
"rights_state": "recorded",
"answered_against": {
"seal": "sealed",
"date": "the date the coverage was answered"
}
}An answer in words, about a licence. No verdict word, no figure, and nothing about the work.
Where a licence does not reach — a different edition, an action the licence does not name, a territory outside it, a number frozen under a challenge — the answer says which of those is the case, in the same words, and stops. It does not propose an alternative, offer an upgrade or name a licence that would cover it.
One signed row is handed to the licensee and read from both ends.
A use produces a usage receipt: the number, the edition, the licence, the licence kind, the action, the meter class, when, what was counted, and the seal. Those are the fields. No value for any of them appears on a page, here or anywhere else on this site, because a value is a figure and the register publishes none.
It is the same row that serves as clearance, invoice and pay, and it is read from both ends because paid is not paid correctly — Meter owns the count, the classes it is taken in and why one row does the work of three.
A use is not an event on the number. The event history records what happened to the entry — Rights lists the events it can carry — and a use is not one of them; it is a row in a ledger that two parties hold. Publishing every use against the number would turn a public index into a usage log, and a usage log about a person's way of working is the thing this register exists to avoid building.
What travels forward with the work. Every served passage and every work product names the number and edition it came from. That naming is the provenance receipt, and it is what lets a count be traced back to the skill set that earned it — For AI owns it and what it does not establish about the work itself.
What is open, and where it goes. What a signed row must carry, and be retained for, to be useful in a dispute — and what may never be claimed of it — is with counsel. It is named here because a program that writes the row is the thing that will have to carry the answer.
What a system is asked to show. A Knowledge Bill of Materials lists the numbers and editions a system is licensed to use, and it is the document a procurement officer asks a supplier for. A bill of materials lists what was licensed, not what a model contains. A program that keeps the number and pins the edition can produce one from its own records; a program that does neither cannot produce one at all. Enterprise owns it and says what it lists, why it is asked for and what it refuses.
A program that integrates the register and never writes a row has implemented the half that costs nothing. The row is the half the person in the seat is paid from, and it is the half this register is for.
It is not a corpus API.
There is no list, browse, bulk or export endpoint.
The refusal is narrow and it is deliberate. There is a scoped surface: a number resolves, a public Card reads, a seal checks, a licensee asks about its own licence, a use is reported. What there is not is any way to ask the register for everything — no call that returns a page of entries, no call that walks the register, no dump and no download. A search over the public side of the Book and an enumeration of the register are two different things, and only the first exists.
Why it is refused, rather than merely absent. What is licensed is the right to run, or to build, under a named and numbered edition — never the pile. An enumeration is the shape that turns a register into a pile: the moment the whole of it can be pulled down in one motion, every entry in it is a row in somebody else's corpus, the edition stops mattering, the licence stops travelling and the source comes off. The register can be asked about a number somebody already has a reason to hold. It cannot be asked to hand over the set of all numbers, and no commercial arrangement changes that answer.
The search that does exist reads what a Card makes public — number, name, status, tile and scope statement — and nothing else. It never reads the skill set itself. The Exchange owns that search and what it may be filtered on.
Refused
What no arrangement on this surface produces.
- No enumeration. No list, browse, bulk or export endpoint, in any tier of access.
- No material. No call returns the material a skill set was made from, and the Manifest is not a copy of it.
- No verdict. No answer about whether a use should go ahead, and no answer that could be read as a safety release.
- No identity. Nothing about the person behind an entry beyond the licence name.
- No figure. No value in any field of a receipt on a page, no rate, no worth, no count of anything.
- No assessment. No answer about whether a skill set is any good, and no evaluation result.
- No schema, today. The Manifest is described here and not offered, and the terms of publishing it are with counsel.
Each line above is a thing a program can be built to expect and will not get. Building against the surface that exists is the shorter road.
The honest statement of the whole page is that this register is small on purpose. It answers about identity, provenance and permission, it records a use, and it refuses everything that would make it a source of supply. A developer who wants the material wants a different kind of company, and this is not one.
