Sigil documentation
ReferenceRust referencesigil-core

sigil-core · mandate

Source declarations, signatures and documentation for mandate.

Source: sigil/node/sigil-core/src/mandate.rs. SHA-256: 69429341049624e22dd6fb997f19bdd7ee712e2a0455760cf233fbb7f416b149.

This reference follows declared source modules, retains conditional attributes, and includes public declarations and implementation methods. Private-module re-exports and trait resolution require the compiler; this is a source reference, not a claim that every listed item is a root import. Function bodies and constant values are omitted.

mandate::MandateId

Stable identifier for an issued mandate.

Conceptually did:oas:sigil:mandate:<id> — kept as an opaque string for flexibility across encodings.

pub type MandateId = String;

Source line: 30.

mandate::JobCategory

Job category tag. Free-form lowercase string kept stable in indices.

pub type JobCategory = String;

Source line: 33.

mandate::TokenId

Token identifier (native SIGIL or a custom token DID).

pub type TokenId = String;

Source line: 36.

mandate::MandateStatus

Status of a mandate.

#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum MandateStatus {
    Active,
    Paused,
    Expired,
    Revoked,
}

Source line: 41.

mandate::AllowedCounterparties

Allowed counterparties for actions taken under a mandate.

#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
#[serde(tag = "kind", content = "data", rename_all = "snake_case")]
pub enum AllowedCounterparties {
    /// Any DID allowed.
    Any,
    /// Restricted to an explicit allowlist of DIDs.
    Allowlist { dids: Vec<String> },
    /// Restricted to specific entity classes.
    Classes { classes: Vec<CounterpartyClass> },
}

Source line: 51.

mandate::CounterpartyClass

Class of counterparty an actor is allowed to engage with.

#[derive(Debug, Clone, Copy, PartialEq, Eq, Hash, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum CounterpartyClass {
    Human,
    Agent,
    Dao,
    Committee,
    AriseProvider,
    Contract,
}

Source line: 63.

mandate::SpendLimits

Spend limits enforced at every spend.

#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct SpendLimits {
/// Maximum amount permitted in a single transaction.

pub per_transaction_max: u128,
/// Maximum aggregate spend per epoch (or `None` for no per-period cap).

pub per_epoch_max: Option<u128>
}

Source line: 74.

mandate::MandateBudget

Total budget available under a mandate, independent of period caps.

#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct MandateBudget {
/// Total amount granted.

pub total_amount: u128,
/// Amount already spent (recorded on-chain via `RecordMandateSpend`).

pub spent_amount: u128
}

Source line: 83.

mandate::MandateBudget::remaining

Remaining spendable amount.

pub fn remaining(&self) -> u128;

Source line: 92.

mandate::MandateScope

Scope of work a mandate authorizes.

#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct MandateScope {
/// Job categories the mandate may engage with (e.g., "audit",

/// "explorer-frontend", "infra-ops"). Empty means "any".

pub job_categories: Vec<JobCategory>,
/// Free-form tag commitments for explorer/UI.

pub tag_commitments: Vec<String>,
/// If `Some(true)` the mandate may *post* jobs; otherwise post-only flows

/// are denied. Used to distinguish hiring-only vs paying-only mandates.

pub may_post_jobs: bool,
/// If `Some(true)` the mandate may *accept* jobs as a worker.

pub may_accept_jobs: bool
}

Source line: 99.

mandate::MilestonePolicy

Milestone payment policy under a mandate.

#[derive(Debug, Clone, Copy, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum MilestonePolicy {
    /// Pay each milestone independently as it is attested.
    PerMilestone,
    /// Final lump-sum payment after all milestones are attested.
    LumpSumOnCompletion,
}

Source line: 115.

mandate::ApprovalPolicy

Approval policy for milestone attestations.

#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
#[serde(tag = "kind", content = "data", rename_all = "snake_case")]
pub enum ApprovalPolicy {
    /// Single signer (employer DID).
    Employer,
    /// Threshold of named DIDs.
    Committee {
        members: Vec<String>,
        threshold: u32,
    },
    /// Single trusted oracle DID.
    Oracle { oracle_did: String },
    /// Automated rule executed by a deterministic verifier (e.g., a CI hash
    /// match). The string is a verifier identifier.
    Automated { verifier_id: String },
}

Source line: 125.

mandate::DisputePolicy

Dispute policy associated with a mandate or contract.

#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
#[serde(tag = "kind", content = "data", rename_all = "snake_case")]
pub enum DisputePolicy {
    /// DAO governance resolves disputes.
    DaoGovernance,
    /// Threshold of a named arbitration committee.
    Committee {
        members: Vec<String>,
        threshold: u32,
    },
    /// Single oracle resolves disputes.
    Oracle { oracle_did: String },
    /// Random selection from staked jurors. Selection rule is consensus-defined.
    StakedJury { minimum_stake: u128 },
}

Source line: 143.

mandate::RevocationPolicy

Revocation policy for a mandate.

#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
#[serde(tag = "kind", content = "data", rename_all = "snake_case")]
pub enum RevocationPolicy {
    /// Issuer may revoke at any time.
    IssuerAtWill,
    /// Issuer may revoke only after a notice period in blocks.
    IssuerWithNotice { notice_blocks: u64 },
    /// Revocation requires DAO governance.
    DaoGovernance,
}

Source line: 160.

mandate::ReputationImpactPolicy

Reputation impact rules that downstream contracts inherit.

#[derive(Debug, Clone, Copy, PartialEq, Eq, Serialize, Deserialize)]
#[serde(rename_all = "snake_case")]
pub enum ReputationImpactPolicy {
    /// Successful completion grants reputation; failure deducts.
    Standard,
    /// Successful completion grants reputation; failure has no impact.
    UpsideOnly,
    /// No reputation effect.
    None,
}

Source line: 172.

mandate::DelegationPolicy

Sub-delegation policy.

#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct DelegationPolicy {
/// May the authorized actor issue sub-mandates?

pub allow_subdelegation: bool,
/// Max remaining-budget percentage that may be sub-delegated, in basis

/// points (0..=10_000).

pub max_subdelegated_basis_points: u16
}

Source line: 183.

mandate::Mandate

On-chain mandate record.

#[derive(Debug, Clone, PartialEq, Eq, Serialize, Deserialize)]
pub struct Mandate {
pub mandate_id: MandateId,
pub issuer_did: String,
pub authorized_actor_did: String,
pub scope: MandateScope,
pub budget: MandateBudget,
pub token_id: TokenId,
pub spend_limits: SpendLimits,
pub allowed_counterparties: AllowedCounterparties,
pub milestone_policy: MilestonePolicy,
pub approval_policy: ApprovalPolicy,
pub dispute_policy: DisputePolicy,
pub revocation_policy: RevocationPolicy,
pub reputation_impact: ReputationImpactPolicy,
pub revenue_share: Option<DistributionPolicy>,
pub delegation_policy: DelegationPolicy,
/// Optional inclusive expiration epoch. None means "no expiration"

/// (still subject to revocation).

pub expires_at_epoch: Option<u64>,
/// Per-mandate spend nonce, monotonically increasing.

pub nonce: u64,
pub status: MandateStatus
}

Source line: 193.

mandate::SpendRequest

Detail describing a proposed spend, validated against a mandate.

#[derive(Debug, Clone, PartialEq, Eq)]
pub struct SpendRequest<'a> {
/// DID of the actor attempting the spend.

pub actor_did: &'a str,
/// DID of the counterparty receiving funds.

pub counterparty_did: &'a str,
/// Counterparty class (used when allowed_counterparties is `Classes`).

pub counterparty_class: CounterpartyClass,
/// Token requested.

pub token_id: &'a str,
/// Amount requested.

pub amount: u128,
/// Job category for this spend.

pub job_category: &'a str,
/// Current chain epoch.

pub current_epoch: u64
}

Source line: 219.

mandate::MandateClearance

Successful authorization output.

#[derive(Debug, Clone, PartialEq, Eq)]
pub struct MandateClearance {
pub mandate_id: MandateId,
pub authorized_amount: u128,
pub remaining_after: u128
}

Source line: 238.

mandate::MandateError

Errors returned by mandate authorization.

#[derive(Debug, Clone, PartialEq, Eq, Error)]
pub enum MandateError {
    #[error("mandate is not active")]
    NotActive,
    #[error("mandate has expired")]
    Expired,
    #[error("actor does not match authorized actor")]
    UnauthorizedActor,
    #[error("token does not match mandate token")]
    TokenMismatch,
    #[error("amount exceeds per-transaction limit")]
    PerTxLimitExceeded,
    #[error("amount exceeds remaining budget")]
    BudgetExhausted,
    #[error("counterparty not allowed by mandate")]
    CounterpartyNotAllowed,
    #[error("job category not in mandate scope")]
    CategoryOutOfScope,
    #[error("mandate scope forbids this action")]
    ActionOutOfScope,
    #[error("subdelegation not permitted")]
    SubdelegationNotPermitted,
    #[error("subdelegation exceeds permitted fraction")]
    SubdelegationExceedsCap,
    #[error("revenue shares must total 10000 basis points")]
    RevenueShareInvalid,
}

Source line: 246.

mandate::Mandate::authorize_spend

Validate a proposed spend against this mandate. Does not mutate the mandate; on success the caller must record the spend with RecordMandateSpend.

pub fn authorize_spend(
        &self,
        req: &SpendRequest<'_>,
    ) -> Result<MandateClearance, MandateError>;

Source line: 277.

mandate::Mandate::authorize_subdelegation

Validate a proposed sub-mandate against this parent mandate.

Sub-mandates must (a) be permitted by delegation_policy, (b) not exceed the parent's remaining budget, scope, expiration, or token, and (c) not exceed the configured fraction cap.

pub fn authorize_subdelegation(&self, child: &Mandate) -> Result<(), MandateError>;

Source line: 335.

On this page