Composable work and bounded permission
Compose rights, modules, equipment, and stake state.
Attribution, IP policy, graph/library/plugin trust, equipment, and stake objects compose reusable work while keeping each source, permission, runtime capability, and custody transition explicit.
Data and state model
Five independent models meet at composition time.
Attribution
Object/viewer, creator, subject, role label, attestation state, active/deactivated state, and timestamp record contribution without granting another authority.
Rights
Policy/version, controller, rights object, license, access mode, action scope, token gate, recipient, nonce, deadline, and evidence bind what may be done.
Graph and module trust
Graph/version, manifest and resource digests, module/plugin/library identity, exact bytes, ABI/adapter, permissions, target/code hash, review status, reason, and replacement define reusable code.
Equipment
Definition, slot, source object/revision, descriptor commitment, backed token custody, loadout, reservation, capacity, consumed state, and visual digest define an equipped part.
Stake object
Host token, staked token, manager policy, runtime code/revision, seed, arguments, variables, lockup, counters, and active custody define a temporary runtime attachment.
Reads, writes, and authority
Each plane has its own controller and its own failure mode.
Attribution writes
Creators attest labels; contributors may self-claim visibly unverified labels; records deactivate rather than disappear. Neither path grants edit, ownership, runtime, or license authority.
Rights writes
Controllers publish policies and grants; users execute only an exact active action; wrapped custody and token gates are checked at execution time.
policy + version
recipient + action scope
token gate + nonce + deadline
current authorization check
exact executor call or rejectionModule/plugin writes
Publishers submit exact graph versions; reviewers sanction/deprecate/revoke; hosts re-derive current graph, permissions, code, target, ABI, adapter, and status before an operation.
Equipment/stake writes
Token owners approve custody and mutate loadouts or stake state. Collection controllers curate compatibility. Verified managers enforce reservation, lock, runtime, and return policy.
Failure and security boundaries
Composition must never create authority by implication.
Ownership is not a license
Holding or wrapping a token does not automatically authorize download, remix, remint, commercial use, or delegation.
Attribution is not edit authority
A credited artist, engineer, partner, or contributor cannot revise the object unless the separate edit policy allows it.
Review status is not enough
A sanctioned plugin or module is usable only when every exact graph binding, code identity, permission, target, and expiry still matches.
Custody remains backed
Equipment and stake managers recheck owners across external calls, reserve actual supply, clear state before transfer, and fail atomically on mismatch or exhaustion.
Ethereum and Tezos realizations
The conceptual planes match; standards and current deployment evidence differ.
Ethereum
Creator identity, graph, equipment, and IP-control modules have recorded Sepolia deployment data. Stake-object source/tests exist without a module deployment record.
Tezos
Creator profiles/attribution, graph/library/plugin review, IP policies/licenses/gates/wrapped FA2/actions, equipment/reservations, and stake objects have local SmartPy sources and scenarios.
Source · Implemented locally
vault-tezos/contracts/keel_creator_profile.py; keel_graph.py; keel_ip_*.py; keel_equipment.py; stake_object.pySDK and Studio surfaces
Portable declarations travel through the builder; live authority is rechecked at use time.
SDK
@keel/protocol defines attribution, IP control, project-stack composition, capability policy, module indexes, and stake objects. @keel/sdk builds module review and wallet request envelopes.
Studio
Creator profiles, module/library catalogs, access-policy records, IP download actions, project composition, equipment/stake preparation, and viewer overlays expose these planes to users.
Exact evidence
Contract and SDK lanes are separately testable.
EVM
Identity, graph, equipment, stake, and IP-control focused Foundry tests exercise the native state transitions.
Tezos
Creator, graph, equipment, stake, IP-control, and IP-action SmartPy scenarios exercise native counterparts.
Source
vault-tezos/tests/test_keel_creator_profile.py; test_keel_graph.py; test_keel_equipment.py; test_stake_object.py; test_keel_ip_control.py; test_keel_ip_action_executor.pyStudio
Creator-profile, library/catalog, module-catalog, and identity tests cover product projections rather than contract authority.

