Source Authority Reference
- Owner: Origo Engineering
- Last updated: 2026-04-14
- Slice/version reference: S44
Purpose and scope
- Runtime and operator reference for how Origo decides which source is allowed to write canonical truth for each canonical family.
- Scope covers the machine-readable authority registry, selector-aware authority claims, writer-time enforcement, and operator-visible authority conflict evidence.
- This is a runtime reference. The authoritative machine contract is
contracts/canonical-source-authority-v1.json.
Authoritative surfaces
- Machine-readable registry:
contracts/canonical-source-authority-v1.json
- Runtime enforcement:
origo/events/source_authority.py
origo/events/writer.py
- Operator-visible conflict evidence:
- ClickHouse table
canonical_authority_conflicts
- runtime-audit event type
canonical_authority_conflict
Core rules
- Source authority is zero-default multi-source.
- Canonical source-event identity does not change; authority enforcement is separate from exactly-once identity.
- Pre-write authority enforcement happens before canonical append.
- Non-authoritative claims are rejected before canonical write.
- Rights, FRED registry, and precision contracts are subordinate supporting surfaces; they do not override authority decisions.
Authority families
- Single-source families:
binance / binance_spot_trades
okx / okx_spot_trades
bybit / bybit_spot_trades
bitcoin_core / bitcoin_block_headers
bitcoin_core / bitcoin_block_transactions
bitcoin_core / bitcoin_mempool_state
bitcoin_core / bitcoin_block_fee_totals
bitcoin_core / bitcoin_block_subsidy_schedule
bitcoin_core / bitcoin_network_hashrate_estimate
bitcoin_core / bitcoin_circulating_supply
- Selector-aware families:
etf / etf_daily_metrics using selector record_source_id
fred / fred_series_metrics using selector record_source_id
- Bitcoin keeps blockchain-derived streams and mempool separated through
stream_id.
Writer-time behavior
- Single-source families may use the writer's default authority claim.
- Selector-aware families must pass an explicit structured authority claim.
- The writer validates:
- canonical family
(source_id, stream_id)
- allowed
authority_source_id
- exact selector-key set
- selector/value agreement for
record_source_id
Conflict evidence
- Conflict rows record:
- canonical stream key
- attempted authority source id
- selector JSON
- source offset or equivalent
- event id
- payload hash
- producer id
- reason code and reason
- Runtime-audit emits the same rejection as
canonical_authority_conflict so operators can pivot from conflict row to runtime activity.