License Model¶
The license model is implemented in argus.core.licenses. It checks data source policy before a package leaves the core boundary.
License Fields¶
| Field | Meaning |
|---|---|
license_id |
Versioned policy identifier. |
source |
Source id such as regulatory_filing. |
status |
Authorized, restricted, prohibited, or unknown. |
allowed_uses |
Purposes that can consume the data. |
prohibited_uses |
Purposes that must be rejected. |
redistribution |
Whether downstream redistribution is allowed, restricted, prohibited, or unknown. |
authorized_institutions |
Institution ids allowed by the license. |
restricted_fields |
Fields that must be blocked or removed. |
Enforcement¶
When data_license.enforcement_enabled is true, license rejection is fail closed: unknown or prohibited license state does not leak restricted field values or source excerpts, and successful packages include the license policy fields so downstream agents can preserve usage limits.
License and redistribution checks default off in settings and service
constructors. The reversible enforcement_enabled server switch also controls
nested ingestion, official filing publication, ETF/option/market record filters,
PIT and bounded stream license checks. While disabled, checks record
license_enforcement_disabled instead of blocking responses. Missing or unknown
captured terms remain metadata and do not alone downgrade a data result. The
license table stays loaded when readable; disabled deployment checks do not
require a valid grant. This setting never changes unknown/prohibited terms to
authorized, removes source evidence checks or supplies missing provider data.
Authentication, tenant ownership, output projections and the independent
external-model processing approval remain active.
The current local demo policy allows factual_lookup and audit_reproduction for regulatory_filing, with restricted redistribution.
Current source policy inspection¶
Prepared migration 0063 preserves a source license snapshot on normalized external facts and controlled source-material metadata. New connector ingestion captures the exact assigned policy, intersects connector and policy uses, and keeps the stricter redistribution limit and all declared prohibitions. Status, institution scope and restricted fields remain those of the captured policy; the requested purpose or caller cannot expand them. Changed terms create a distinct normalized version with a capture-time visibility boundary.
Legacy rows have no snapshot. The migration leaves them unverified, and public
results retain their actual facts and evidence with status=unknown. An enabled
license switch adds a partial result and external_source_license_scope coverage
gap; the default disabled switch preserves business status. Current configuration
must not be applied retroactively to those rows. Generic enforcement keeps its
existing administrative setting; a successful read does not grant source rights.
source_license_snapshot_present reports captured metadata, while
source_license_use_scope_verified also checks the actual status, caller
institution and requested purpose. Neither flag proves full data coverage.
The prepared 1.1.8 data_license_check implementation reads the same loaded
policy repository as the shared business boundary. It accepts an exact configured
connector source id (for example openfigi_security_mapping), a policy source,
or a versioned license id. A connector's assigned policy id must resolve exactly;
a missing assignment or missing policy is reported as unknown. This reader has
not yet been deployed to the running 1.1.7 service.
license.status describes configured source terms. license.allowed and
license.reason describe the administrative decision for the authenticated
institution, purpose and requires_redistribution setting. With generic
enforcement disabled, that decision records license_enforcement_disabled;
it does not change an unknown or prohibited source to authorized.
license.policy_allowed, license.policy_reason and
license.policy_restrictions separately report what those configured terms
permit. Record-level distribution filters follow the server switch, while the
external-model processing approval stays independent. This check does not promise that a subsequent data query is
available.
The report includes configured allowed/prohibited uses, restricted fields, redistribution, policy version and terms fingerprint. Missing verification metadata stays unknown. Tuple-valued metadata is encoded as JSON strings. It reports the caller's institution eligibility without exposing other institutions' identifiers. The report's own license applies to Argus metadata; it grants no rights to the queried provider's data.
This operation inspects current configuration, not historical policy versions.
Its effective and known times are the actual inspection time; an as_of input
does not backdate that configuration. Use the returned evidence locator with
source_evidence_lookup to retrieve the immutable, owned public projection of
that inspection, and its data_package:<audit_id> with evidence_bundle_export
to verify the archived package checksum. Neither result proves a subscription,
provider connection or data coverage. A metadata inspection may complete with
license.status=unknown or license.allowed=false; business data acceptance
still requires the relevant tool's real records and evidence.