{
  "schema": "micyte.gadget.declaration.v1",
  "what_this_is": "This file ENABLES tools; it never adds code. Every tool named here is already in the MiCyte package your instance runs \u2014 installing from this declaration shows those tools and creates the blank documents they need. It cannot introduce a tool your build does not have, and it grants nothing: showing a tool is not permitting it, and what a tool may write is decided by your instance's own grants, which deny by default.",
  "how_to_verify": "`digest` is sha256 over this declaration canonically serialized, excluding version, label, summary, icon and publishable \u2014 the same value micyte.tools._packages_manifest.declaration_digest computes, which is what an instance compares when it pulls the same declaration over GET /__mss/public/packages. A declaration whose digest does not match the one your instance computes is not the declaration this build published.",
  "publisher": "micyte.com",
  "micyte_version": "0.4.1",
  "generated_at": "2026-10-04T21:48:06Z",
  "digest": "sha256:d9e4228ec0b2afbde6415507cf35c97c5c78998f8b2d0d1ea5ce66d8122984d4",
  "package": {
    "package_id": "pim",
    "version": "0.1.0",
    "label": "PIM",
    "summary": "The client's own record of their provider-service relationship, held as datum documents in an isolated sandbox and fed through the ports their own service key permits. Home says what the sandbox keeps and what the client pays; Authoring and Design are their site and the writing published to it; Analytics, Email, Resources, Storage, Payment and Domain each light when the seam that feeds them is bound and say why when it is not.",
    "source": "local",
    "tools": [
      "pim_overview",
      "pim_design"
    ],
    "requires": {
      "sources": [],
      "documents": [],
      "documents_any": [],
      "fields": [],
      "archetypes": []
    },
    "writes": [],
    "icon": "folder",
    "hub_tool": "pim_overview",
    "app_sandbox": {
      "namespace": "",
      "why": "a PIM sandbox's anchor is copied verbatim from the instance's own core anchor, so its namespace is INHERITED and resolved at install \u2014 never stated as a token that could disagree with the copy",
      "documents": [
        {
          "name": "contacts",
          "archetype": "natural_entity_profile",
          "why": "people who signed up on the client's website \u2014 the client's own record of them, in their own sandbox. NOT quiar's CRM contacts: same archetype, different record",
          "archetype_hash": ""
        }
      ]
    },
    "port_declarations": [
      {
        "port_id": "email_provider",
        "why": "the FND module seam: an instance's own mail, and AWS's view of its users and their verification stages, fetched with the service key the channel minted and kept as records. DECLARED, not bound \u2014 binding is the operator's act on Ports and the grant a separate one after it, so this ships able to do nothing",
        "writes": [],
        "calls": [],
        "operations": [
          "mailbox.list",
          "message.fetch",
          "alias.list",
          "forwarding.set",
          "identity.verify_request",
          "identity.remind"
        ]
      },
      {
        "port_id": "site_hosting",
        "why": "the client's own site: which pages it has, and the writing they publish to it. DECLARED, not bound \u2014 the operator selects an extension on Ports and writes the grant afterwards, so this ships able to do nothing",
        "writes": [],
        "calls": [],
        "operations": [
          "page.list",
          "article.publish",
          "article.retire",
          "analytics.read",
          "content.replace",
          "asset.upload"
        ]
      }
    ],
    "scoped_features": [],
    "port_fills": [],
    "publishable": true,
    "digest": "sha256:d9e4228ec0b2afbde6415507cf35c97c5c78998f8b2d0d1ea5ce66d8122984d4"
  }
}
