{
  "$schema": "http://json-schema.org/draft-07/schema#",
  "$id": "https://cognitive-delivery.github.io/contract/1.x/config-core.schema.json",
  "title": "CDF config, shared core",
  "description": "The part of .cdf/config.yaml that every Cognitive Delivery implementation must understand identically. Product-specific sections are deliberately NOT here: a product carries its own alongside these, which is why additionalProperties is true at the root.",
  "type": "object",
  "properties": {
    "adoption_tier": {
      "type": "integer",
      "enum": [
        1,
        2,
        3,
        4
      ],
      "description": "How much governance this workspace has adopted. Read by the Index, so it must mean the same thing everywhere.",
      "maximum": 9007199254740991,
      "$comment": "stability: stable"
    },
    "governance": {
      "type": "object",
      "properties": {
        "source": {
          "type": "string",
          "$comment": "stability: stable"
        },
        "refresh_mode": {
          "type": "string",
          "enum": [
            "on-open",
            "manual",
            "scheduled"
          ],
          "$comment": "stability: stable"
        },
        "profile": {
          "type": "string",
          "$comment": "stability: stable"
        }
      },
      "additionalProperties": true,
      "$comment": "stability: stable"
    },
    "review_policy": {
      "type": "object",
      "description": "Who must review, and whether the author may. Security-relevant: an implementation that ignored reviewer_cannot_be_implementer would let work approve itself.",
      "properties": {
        "cross_model_review_required": {
          "type": "boolean",
          "$comment": "stability: stable"
        },
        "reviewer_cannot_be_implementer": {
          "type": "boolean",
          "$comment": "stability: stable"
        },
        "required_reviewers": {
          "type": "integer",
          "minimum": 0,
          "maximum": 9007199254740991,
          "$comment": "stability: stable"
        }
      },
      "additionalProperties": true,
      "$comment": "stability: stable"
    },
    "provenance": {
      "type": "object",
      "properties": {
        "required_fields": {
          "type": "array",
          "items": {
            "type": "string"
          },
          "$comment": "stability: stable"
        }
      },
      "additionalProperties": true,
      "$comment": "stability: stable"
    },
    "cdi": {
      "type": "object",
      "properties": {
        "enabled": {
          "type": "boolean",
          "$comment": "stability: stable"
        },
        "aggregation_endpoint": {
          "type": [
            "string",
            "null"
          ],
          "description": "Null means local only. Null is the default and is a value, not an omission.",
          "$comment": "stability: stable"
        }
      },
      "additionalProperties": true,
      "$comment": "stability: stable"
    },
    "break_glass": {
      "type": "object",
      "description": "The exceptional override. Security-relevant: an implementation that widened this beyond one spec and one non-final gate would break the policy the framework states.",
      "properties": {
        "mode": {
          "type": "string",
          "enum": [
            "self-service-logged",
            "two-person",
            "disabled"
          ],
          "$comment": "stability: stable"
        },
        "timeout_minutes": {
          "type": "integer",
          "minimum": 0,
          "maximum": 9007199254740991,
          "$comment": "stability: stable"
        }
      },
      "additionalProperties": true,
      "$comment": "stability: stable"
    },
    "sealed": {
      "type": "array",
      "items": {
        "type": "string",
        "pattern": "^[a-z][a-z0-9_]*(\\.[a-z][a-z0-9_]*)*$",
        "description": "A dotted path of lower-case segments (`review_policy.reviewer_cannot_be_implementer`). The runner also checks that a sealed path in a fixture resolves to a key the file carries."
      },
      "description": "Dotted paths of fields an upper layer has fixed. SEALING IS PART OF THE CONTRACT, and any implementation that ignores it fails conformance. A sealed field may not be relaxed by a downstream layer: a lower layer may match the sealed value or make it stricter, never looser. Ignoring this would let a workspace quietly undo a control its organisation set.",
      "$comment": "stability: stable"
    }
  },
  "additionalProperties": true
}
