hip-1193

HIP-1193: Standing — Entity Upkeep and Annual Filings. Status Final. Hanzo architectural specification.

HIP-1193: Standing — Entity Upkeep and Annual Filings

Abstract

/v1/standing is the canonical capability for standing within the Hanzo Cloud platform. Package standing prices and tracks what it costs to KEEP a company, as distinct from what it cost to form one. The implementation is hanzoai/cloud apps/standing and plugin/standing (HIP-0106, HIP-0139). All operations are native, composable, and authenticated against Hanzo IAM (HIP-0026).

Motivation

Before this specification, standing operations lacked a unified canonical surface or were scattered across disparate endpoints. Under HIP-0139 (§1), every cloud capability maps 1:1 with exactly one plugin binary, one address prefix, one client class, and one authoritative specification. This eliminates duplicate implementations and ensures strict physical isolation, predictable billing, and orthogonal composability across the estate.

Specification

The key words MUST, MUST NOT, and SHOULD are to be interpreted as in RFC 2119.

§1 Addresses and Operations

The standing capability answers exclusively under its assigned route prefixes:

| Method | Path | Summary | |---|---|---| | POST | /v1/standing/upkeep | Reports what keeping this entity costs every year, itemised. |

§2 Storage and Physical Isolation

Data is isolated physically per organization using cloud.OrgDB: {DataDir}/orgs/{org}/standing.db. Isolation is strictly enforced at the filesystem and OS level; no cross-tenant queries are permitted. Where temporal or timeseries data is captured, postings are signed and immutably appended.

§3 Authentication and Principal

Every request reaching /v1/standing MUST present a valid Hanzo IAM bearer token (HIP-0026, HIP-0111). Anonymous requests are rejected at the edge gateway before invoking the plugin. The executing principal is extracted from the token and bound to the request context.

Security Considerations

  1. Physical Separation: Each tenant retains an isolated SQLite database file.
  2. Replay & Channel Binding: Direct dials and internal RPCs enforce channel binding over ZAP native transport.
  3. Audit Trails: All state-modifying actions emit immutable audit events to the centralized event plane (HIP-1190).

References