Access Model
Who may connect, what each role can do at the interface, and what never crosses the vault wall.
Maturity: Early Access. Enforcement details for Early Access keys are issued per partner — this page is the public actor contract.
Actors
| Actor | Role at the interface |
|---|---|
| Institution ops / Early Access operator | Creates onboard cases, attaches vault material, triggers decision/seal paths entitled to their key |
| Venue / clearing integrator | Calls gate check only (or eligibility read as issued). Never receives vault bytes |
| Examiner / reviewer | Opens assessor pack (decided / sealed / consumed). No vault via pack |
| Cleared service | Verifies clr_ keys, enforces scopes, maintains live-pass cache, fails closed on gate miss/timeout |
| BlockSkunk operator | Provisions environments and keys; does not publish judgment criteria in this docs set |
Capabilities
| Capability | Ops | Venue | Examiner |
|---|---|---|---|
| Onboard / attach docs | Yes (scoped) | No | No |
| Read eligibility / case status | Yes (scoped) | Read-only if scoped | Via pack only |
| Gate check (allow/deny) | Optional | Yes (primary) | No |
| Assessor pack export | Yes if entitled | No | Consume / verify |
| Vault download | Ops vault path only | Never | Never |
Unauthorized calls return public error categories — see Errors. Existence of out-of-scope subjects is not confirmed beyond those categories.
Vault wall
- Vault holds document preimages and screening inputs.
- Stratum / optional prove / pack payloads carry no PII (fitness denylist at CI for Early Access).
- Gate and pack APIs never return vault bytes.
- Public prove (when Live) proves digests / txids — not vault contents.
Keys and scopes
Partners receive clr_ API keys with scopes such as:
| Scope (illustrative) | Intent |
|---|---|
cleared.onboard | Create case, attach vault refs |
cleared.eligibility.read | Read case / eligibility status |
cleared.gate | Gate check before quote/settle |
cleared.pack.read | Assessor pack export / verify |
Exact scope strings are issued with the key. Treat undocumented scopes as non-contract. See Authentication.