1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
//! [`InstrumentRef`] — one act recorded on a passport as applicable to it.
use ;
/// Where a recorded instrument came from.
///
/// Not a confidence ranking — both values are equally authoritative on a
/// passport. What they distinguish is *who asserted it*, which matters when a
/// record is audited years later.
/// One legal instrument recorded on a passport as applicable to it.
///
/// # Recorded, never recomputed
///
/// The applicable set is fixed when the product is placed on the market —
/// `placedOnMarketDate` on the passport is the same moment — and is never
/// re-derived afterwards. Two reasons, and the second is the load-bearing one:
///
/// 1. **The law that governs a product is the law at placing on the market.**
/// Recomputing later would silently re-govern a published record by acts
/// adopted after it was issued.
/// 2. **There is no function to recompute it with.** Applicable instruments are
/// not derivable from the product group — see [`RecordedBasis::Operator`] —
/// so any "refresh" would quietly *narrow* the set to whatever the catalog
/// happens to know, dropping exactly the entries a human had to supply.
///
/// It is therefore a protected field: not patchable, not in the
/// retention-mutable set, and corrected only by superseding the passport with a
/// new version. A mis-recorded legal basis is a fact about a published record,
/// and the way to fix a published record is to publish a corrected one.
///
/// # Why there is no timestamp here
///
/// An earlier shape carried a per-entry `recordedAt`. It was **redundant** —
/// the whole set is written at issuance, so every entry's timestamp equalled the
/// passport's own `createdAt` — and a redundant copy of a date is a date that
/// can disagree with the one it duplicates.
///
/// Removing it also sidesteps a live hazard worth knowing about: the access
/// filter classifies nested keys **by name, not by path**, using a policy built
/// from the *product group's* schema. The battery schema declares its own
/// `recordedAt` as individual-tier data (Annex XIII point 4), so this field's
/// timestamp inherited that class and was redacted out of every public battery
/// projection — leaving a document that no longer deserialised. Any envelope
/// field whose nested key name collides with a product-group field name will hit
/// the same thing.