Core + Extension

One event, with the right evidence attached.

A bird sighting, a phone photograph, a quartz sample, a plankton tow, and an SEM image need different fields. They still share a who, when, where, provenance, and licence. Clio’s planned architecture keeps that common spine intact.

Event core

Every submission starts here.

eventID
platform-minted UUID v4
eventDate
ISO 8601 date or date-time
decimalLatitude
WGS84 decimal degrees
coordinateUncertaintyInMeters
required, including deliberate fuzzing
recordedByID
ORCID iD, where available
license
CC0, CC BY, or CC BY-NC

Extensions

Domain-specific evidence joins the event.

biology
Darwin Core Occurrence
geology
ABCD-EFG, IGSN where retained
media
Audiovisual Core, EXIF
microscopy
REMBI, OME-TIFF, OME-Zarr
sampling
Humboldt Extension
packaging
EML, Darwin Core Archive

Verification is data

The latest identification is never the whole story.

The planned record retains the verbatim submission, normalized values, and every identification event. A status is a queryable state with evidence behind it.

Unverified

As submitted. The original contributor’s words and media remain visible.

Community-verified

At least two independent, agreeing identifiers from established contributors.

Expert-verified

Confirmed by a credentialed curator with an ORCID iD and affiliation on file.

Identity + evidence

Trust is architecture, with an explicit implementation boundary.

Current tested source is a Clio trust log with Ma’atara integration in progress: canonical did:maatara contributor identity, a personal Veritas chain per contributor, and a separate Clio receipt all exist and are tested against production WASM. None of it is deployed. A contributor can already generate and hold that key locally, at /contribute — nothing past that step is built or reachable yet.

Implemented: contributor-owned identity

A locally generated ML-DSA-65 owner key derives did:maatara, locked against shared vectors. OIDC links account access through an owner-signed statement it never derives or replaces. Browser-side key generation now runs at /contribute; there is still no account to link it to.

Implemented: personal chain, separate receipt

Each contributor’s canonical Veritas chain, and Clio’s separately signed institutional receipt, are built and tested against real Ma’atara WASM. A service did:web still publishes issuer keys; it is not interchangeable with the owner DID. Neither is reachable without a browser identity.

Current evidence status

ML-DSA-65 is the only signing suite in the trust source — the P-256 fallback has been removed, not relabelled. A signed migration record links the frozen legacy SHA-256 log to the new profile; both verifiers still work. External anchoring and DOI registration remain disabled, and nothing here is deployed.

Maatara is the same team’s post-quantum identity and evidence infrastructure; it also underpins Parable (parable.city), a sibling project. Choosing it here is a disclosed, deliberate decision, not a hidden dependency — Clio still owns its keys, its resolver, and its evidence log, and keeps operating if any hosted Maatara service is down.

Integration in progress: Maatara — post-quantum identity

The academic handshake

Projection, not translation.

The intended export path is a projection from standard-shaped internal fields into a Darwin Core Archive: meta.xml, eml.xml, and occurrence, event, and media tables. That makes future repository review simpler, but it is not a claim that an export pipeline is live today.

Record layerPlanned outputPurpose
Eventevent.txtWho, when, where, and sampling context
Occurrenceoccurrence.txtOrganism identity and verification history
Mediamultimedia.txtImages, access URIs, and file metadata
Dataseteml.xmlScope, methods, attribution, and licence