Governance Envelope Schema
Core schema for envelopes: action, action trace, context metadata.
The SAFR whitepaper defines what should hold for every agent action: it is declared, its agent is verified, it is assessed against controls, it receives one of four outcomes, and it is recorded. It deliberately leaves the form of implementation to each institution.
That flexibility has a cost. If every institution designs its own envelope and log format, the fragmentation problem the whitepaper describes simply moves one layer down. OpenSAFR's first priority is a shared, language-agnostic schema for the Governance Envelope and the Audit Log record, with a conformance suite to check implementations against it. The disposition engine is where institutions differentiate. The record format is where they should agree.
Core schema for envelopes: action, action trace, context metadata.
Record format for every disposition, including hash-chain and controls-version fields.
Test vectors and runner for schema validity and disposition behaviour.
Emit envelopes, validate records, verify chains.
TypeScript equivalent for agent platforms and gateways.
Disposition engine with tiered policy pack, from the SingHacks build.
Working systems built on SAFR concepts: Implementations →
[TODO: state the licences once decided (e.g. CC BY 4.0 for the spec, Apache 2.0 for code).]
Reviewing the draft schema is the most valuable contribution right now. Open issues, comment on RFCs, or tell us where the envelope or record format doesn't fit your use case. See Get involved.
[TODO: link GitHub discussions and issues once the spec repository is public.]
OpenSAFR is an independent, unofficial open reference implementation. It is not affiliated with or endorsed by the Monetary Authority of Singapore, BuildFin.ai, or any organisation that contributed to the SAFR whitepaper. SAFR is an industry reference approach, not regulatory guidance. Nothing on this site is legal, regulatory, or financial advice.