Lifecycle
Shared vocabulary for where a case is and what the venue may assume. Names states and signals — not admission rules.
Maturity: Contract-preview (v0.1). Exact enum strings may be pinned in your issued OpenAPI.
Unit of record
The eligibility record (sealed fact under policy_version) is what the gate reads. A case is the ops container that produces that fact. See Eligibility record.
Case states
| State | Meaning at the interface |
|---|---|
received | Case created; vault attach may be in progress |
screening | Silent screens running (no public criteria) |
decided | Pass / fail / refer recorded with policy_version |
sealed | Stratum ack present (stratum_record_id); live-pass eligible if pass |
pack_ready | Assessor pack can be exported |
closed | Terminal for this case lineage (new material change → new event) |
Eligibility states (venue-facing)
| Signal | Gate implication |
|---|---|
| Live pass | allowed: true for actions in allows[] until expires_at |
| No live pass | Deny (no_live_pass or equivalent) |
| Expired | Deny |
| Failed / referred decision | Deny for quote (and other actions not in allows[]) |
| Timeout / error reading cache | Deny (fail closed) |
Transitions
Happy path (ops → venue → examiner):
received → screening → decided(pass) → sealed → pack_ready
↓
venue gate allows quote
↓
pack consumed (examiner)
Fail / refer: decided(fail|refer) — no seal that allows quote. Material change / sanctions path: new append-only event — never overwrite the prior seal.
Append-only
Material changes create a new eligibility event. Prior seals remain for audit. Gate always reads the current live-pass cache under the policy your environment publishes — not a mutable overwrite of history.