How it works
VTE answers one narrow question about a private position and records the answer on a Canton ledger, together with the evidence behind it.
The roles
1Relying party
Writes the request and its terms, and decides whether to rely on the answer.
2Subject
Sees exactly what is asked, enters its own figures, and accepts or declines.
3Source
Attests the figures with its own key. In this demo the only source is operated by our team.
4Canton ledger
Checks that the declarations agree.
5Bounded package
Back to the relying party. Decision, confidence level, freshness, validity and ledger references. Never the individual figures behind the answer.
Governance
The ledger parties that can read the data in some modes, shown in their own view.
The flow of a request
Pick a step to see who acts and what is signed.
Step 1 of 4
Request with terms
Required figures, freshness and validity.
- Who acts
- Relying party
- What is signed or recorded
- The request lives in the memory of the demo service. It is not a contract on the ledger.
Step 2 of 4
Consent by the subject
The subject sees exactly what is asked, enters its own figures, and accepts or declines.
- Who acts
- Subject
- What is signed or recorded
- The client’s wallet signs the login and the consent, outside the ledger.
Step 3 of 4
The service runs the mode on the ledger
The Daml templates check that the pieces agree.
- Who acts
- The service
- What is signed or recorded
- The ledger steps are signed by the service’s demonstration parties.
Step 4 of 4
Bounded package to the relying party
Decision, confidence level, freshness, validity and ledger references, never the individual figures behind the answer.
- Who acts
- Relying party
- What is signed or recorded
- The service delivers the package.
The four modes in detail
| Mode and question | The asking party sees | Governance sees the values |
|---|---|---|
| VTE RevealWhat do these holdings add up to? | Exact total and pass or fail | Partial sums, in this demo |
| VTE PolicyWhat is the total made of? | Total, category breakdown and pass or fail | Yes |
| VTE Trade CheckIs there enough behind this trade to proceed? | Pass or fail against the required minimum | Yes |
| VTE MatchDoes the position reach the minimum? | Whether the position clears the minimum | No |
For VTE Match the value never reaches the ledger and the band is attested by the source. For VTE Reveal the requesting party receives only the total; in this demo, governance parties can also read partial sums until a fix ships. The service's governance parties can see the values in VTE Policy and VTE Trade Check.
Composing the modes
The four modes can run on one case and be composed into a single cross-checked package. The cross-check is coherence between what was attested: same subject, scope, epoch, governance and book. It is not a verification of the data.
What the ledger adds
Each refusal is shown with the participant’s own error.
Disagreement
The ledger refuses a submission when the subject and the source disagree.
Source never onboarded
It refuses when the source was never onboarded.
Source revoked
It refuses when the source has been revoked.
Replay
It refuses when a command already committed is replayed (within the participant’s deduplication window).
After the answer
Revalidation receipt
A revalidation receipt, with a validity window applied by the service.
Reliance decision
A reliance decision signed only by the relying party, stating that relying on the evidence is its own responsibility.