# Cabuya place feed (v0.1)

The JSON Schemas the validator enforces. Every field with its type, constraints, an example value, and the check ids that fire on it — generated from the schema files themselves.

Canonical: https://cabuya.org/developers/schemas/0.1/place-feed
Language: en

Schema id: https://cabuya.org/schemas/0.1/place-feed.schema.json

## Fields

| Field | Type | Required | Profile | Example | Checks | Description |
|---|---|---|---|---|---|---|
| `last_updated` | `string` | Yes | Core | `"2026-08-16T04:05:00Z"` | ENV001, ENV002 | Mandatory feed-level generation timestamp (RFC 3339 UTC). MUST NOT be computed per-request (always-now anti-pattern). |
| `ttl` | `integer` | Yes | Core | `300` | ENV001, ENV006 | Seconds a consumer may cache before re-polling. The caching contract. |
| `version` | `string` | Yes | Core | `"0.1.0"` | ENV001, ENV008 |  |
| `publisher_id` | `string` | Yes | Core | `"acopios-demo"` | ENV001, ENV009 |  |
| `license` | `string` | Yes | Core | `"ODbL-1.0"` | ENV001, ENV003, ENV004 |  |
| `permitted_use` | `array` | No | Extended | `[…3]` | ENV005 |  |
| `data` | `object` | Yes | Core | `{…}` | — |  |
| `data.places` | `array` | Yes | Core | `[…3]` | ENV001 |  |
| `data.places[].id` | `string` | Yes | Core | `"shel-0007"` | REC002, REC003 | Publisher's stable local id (int/uuid/hex all acceptable, R3). Opaque; MUST NOT embed personal data (R6). |
| `data.places[].publisher_id` | `string` | Yes | Core | `"acopios-demo"` | REC003 |  |
| `data.places[].name` | `any` | Yes | Core | `[…2]` | REC010, REC012 | CR-2: MUST NOT encode operational state ('(cerrado ahora)' belongs in service_status, not the name). |
| `data.places[].place_kind` | `string` | Yes | Core | `"shelter"` | REC004 |  |
| `data.places[].place_kind_secondary` | `array` | No | Extended | `[…1]` | — |  |
| `data.places[].place_kind_ext` | `string` | No | Extended | — | REC005 |  |
| `data.places[].origin_category` | `string` | No | Extended | `"albergue_temporal"` | — | Publisher's own category value, verbatim, untranslated. Keeps every crosswalk auditable. |
| `data.places[].description` | `any` | No | Extended | — | PII003, PII004 | Publishers MUST strip personal data before publishing (free text is the third leak channel). |
| `data.places[].municipality_code` | `string | null` | Yes | Core | `"66001"` | REC006 | DIVIPOLA. null permitted ONLY with municipality_text present (validator warning, not error — Q3). |
| `data.places[].municipality_text` | `string` | No | Extended | — | — |  |
| `data.places[].address_text` | `string` | No | Extended | `"Av. Las Américas con Calle 37, Villa Olímpica"` | PII004 |  |
| `data.places[].neighborhood_text` | `string` | No | Extended | — | — |  |
| `data.places[].lat` | `number` | No | Extended | `4.815091` | REC007 |  |
| `data.places[].lon` | `number` | No | Extended | `-75.735` | REC007 |  |
| `data.places[].geo_precision` | `string` | No | Extended | `"exact"` | — |  |
| `data.places[].lifecycle_status` | `string` | Yes | Core | `"active"` | REC008 |  |
| `data.places[].service_status` | `string` | No | Extended | `"full"` | REC009, REC011 |  |
| `data.places[].closed_at` | `string` | No | Extended | — | — |  |
| `data.places[].expires_at` | `string` | No | Extended | — | — |  |
| `data.places[].last_confirmed_at` | `string | null` | Yes | Core | `"2026-08-16T02:30:00Z"` | REC001, REC014, BEH002 | Key MUST be present. null = never confirmed (honest). Omission = non-conforming. |
| `data.places[].confirmed_by` | `string` | No | Extended | `"volunteer"` | REC015, PII005 | Publisher-scoped ROLE/actor token (team, volunteer, official_source, partner:{publisher_id}). MUST NOT be a person's name. |
| `data.places[].confirmation_method` | `string` | No | Extended | `"in_person"` | — |  |
| `data.places[].confirmations_24h` | `integer` | No | Extended | `3` | — |  |
| `data.places[].contradictions_active` | `integer` | No | Extended | `0` | — | Negative confirmation is a first-class signal. |
| `data.places[].last_reported_absent_at` | `string` | No | Extended | — | — |  |
| `data.places[].updated_at` | `string` | No | Extended | `"2026-08-16T02:31:12Z"` | REC013 | CR-1: never a substitute for last_confirmed_at — an edit is not a confirmation. |
| `data.places[].published_at` | `string` | No | Extended | — | — |  |
| `data.places[].source` | `object` | Yes | Core | `{…}` | REC016 | Structured provenance, never prose (free-text 'fuente' observed leaking personal names). Aggregators MUST preserve the original chain. |
| `data.places[].source.source_id` | `string` | Yes | Core | `"acopios-demo"` | — |  |
| `data.places[].source.source_url` | `string` | No | Extended | — | — |  |
| `data.places[].source.retrieved_at` | `string` | No | Extended | — | — |  |
| `data.places[].source.source_kind` | `string` | No | Extended | `"first_party"` | — |  |
| `data.places[].source_authority` | `string` | No | Extended | `"community"` | — |  |
| `data.places[].attribution_required` | `boolean` | No | Extended | `true` | — |  |
| `data.places[].public_url` | `string` | Yes | Core | `"https://acopios-demo.invalid/p/shel-0007"` | REC017 | REQUIRED. Link-out is how contact/media/detail reach users WITHOUT travelling in the feed. |
| `data.places[].contact_available` | `boolean` | No | Extended | `true` | PII001, PII002 | Carries the fact, never the value. |
| `data.places[].same_as` | `array` | No | Extended | `[…2]` | — | Fully-qualified {publisher_id}:{id} claims. One-hop, non-transitive, never authority (Q5). |
| `data.places[].merged_into` | `string` | No | Extended | — | — | Same-publisher supersession pointer (precedent: alluda ciudades.fusionada_en). |
| `next_cursor` | `string | null` | No | Extended | — | — | Read-API responses only. Opaque server-side sequence cursor — never a record timestamp. |

## Examples

Two that conform and three that do not. The invalid ones state, in their own file, what they are demonstrating — and the validator’s tests assert against those exact strings.

### valid-minimal-core.json — Conforms

> **What this example demonstrates:** VALID — minimal Core feed. The L2 floor: what an afternoon of work produces. Note last_confirmed_at: null on the second record — 'never confirmed' stated honestly (the silence test: a publisher with zero freshness data can still conform).

```json
{
  "$comment": "VALID — minimal Core feed. The L2 floor: what an afternoon of work produces. Note last_confirmed_at: null on the second record — 'never confirmed' stated honestly (the silence test: a publisher with zero freshness data can still conform).",
  "last_updated": "2026-08-16T04:00:00Z",
  "ttl": 300,
  "version": "0.1.0",
  "publisher_id": "example-app",
  "license": "CC-BY-4.0",
  "permitted_use": ["display", "aggregate", "ai_answer"],
  "data": {
    "places": [
      {
        "id": "184",
        "publisher_id": "example-app",
        "name": "Coliseo Mayor",
        "place_kind": "shelter",
        "municipality_code": "66001",
        "address_text": "Av. Las Américas con Calle 37, Villa Olímpica",
        "lifecycle_status": "active",
        "service_status": "full",
        "last_confirmed_at": "2026-08-15T21:00:00Z",
        "confirmation_method": "in_person",
        "source": { "source_id": "example-app", "source_kind": "first_party" },
        "public_url": "https://example-app.invalid/lugares/184"
      },
      {
        "id": "b3f2c9e1-7a44-4a1c-9d02-1f6e8a5c0d11",
        "publisher_id": "example-app",
        "name": "Punto de acopio Kennedy",
        "place_kind": "collection_center",
        "municipality_code": "66001",
        "address_text": "Parque principal de Kennedy",
        "lifecycle_status": "active",
        "last_confirmed_at": null,
        "source": { "source_id": "example-app", "source_kind": "user_report" },
        "public_url": "https://example-app.invalid/lugares/b3f2c9e1-7a44-4a1c-9d02-1f6e8a5c0d11"
      }
    ]
  }
}
```

### valid-rich-extended.json — Conforms

> **What this example demonstrates:** VALID — Extended feed exercising the worked duplicate cases. Record 1 = the Coliseo Mayor cluster (Manizales test: municipality_code disambiguates; same_as claims the two peers' records, one-hop, no authority). Record 2 = the Colegio María Auxiliadora case: this publisher says 'paused' while a peer says active — the record carries its OWN status with its OWN age plus a same_as claim; discrepancies are preserved, not resolved. Record 3 shows negative confirmation and merged_into.

```json
{
  "$comment": "VALID — Extended feed exercising the worked duplicate cases. Record 1 = the Coliseo Mayor cluster (Manizales test: municipality_code disambiguates; same_as claims the two peers' records, one-hop, no authority). Record 2 = the Colegio María Auxiliadora case: this publisher says 'paused' while a peer says active — the record carries its OWN status with its OWN age plus a same_as claim; discrepancies are preserved, not resolved. Record 3 shows negative confirmation and merged_into.",
  "last_updated": "2026-08-16T04:05:00Z",
  "ttl": 300,
  "version": "0.1.0",
  "publisher_id": "acopios-demo",
  "license": "ODbL-1.0",
  "permitted_use": ["display", "aggregate", "redistribute"],
  "data": {
    "places": [
      {
        "id": "shel-0007",
        "publisher_id": "acopios-demo",
        "name": [{ "text": "Coliseo Mayor", "language": "es" }, { "text": "Main Coliseum shelter", "language": "en" }],
        "place_kind": "shelter",
        "place_kind_secondary": ["collection_center"],
        "origin_category": "albergue_temporal",
        "municipality_code": "66001",
        "address_text": "Av. Las Américas con Calle 37, Villa Olímpica",
        "lat": 4.815091,
        "lon": -75.735,
        "geo_precision": "exact",
        "lifecycle_status": "active",
        "service_status": "full",
        "last_confirmed_at": "2026-08-16T02:30:00Z",
        "confirmed_by": "volunteer",
        "confirmation_method": "in_person",
        "confirmations_24h": 3,
        "contradictions_active": 0,
        "updated_at": "2026-08-16T02:31:12Z",
        "source": { "source_id": "acopios-demo", "source_kind": "first_party" },
        "source_authority": "community",
        "attribution_required": true,
        "public_url": "https://acopios-demo.invalid/p/shel-0007",
        "contact_available": true,
        "same_as": ["pereira-ayuda:coliseo-mayor", "unidos-demo:c32653bdd8"]
      },
      {
        "id": "acop-0119",
        "publisher_id": "acopios-demo",
        "name": "IE María Auxiliadora",
        "place_kind": "collection_center",
        "origin_category": "acopio",
        "municipality_code": "66170",
        "address_text": "Cl. 43 #13-74, Dosquebradas",
        "lifecycle_status": "active",
        "service_status": "paused",
        "last_confirmed_at": "2026-08-15T18:00:00Z",
        "confirmation_method": "phone",
        "source": { "source_id": "acopios-demo", "source_kind": "first_party" },
        "public_url": "https://acopios-demo.invalid/p/acop-0119",
        "same_as": ["unidos-demo:76f30c68a4"]
      },
      {
        "id": "acop-0042",
        "publisher_id": "acopios-demo",
        "name": "Acopio UTP — Parque del Estudiante",
        "place_kind": "collection_center",
        "municipality_code": "66001",
        "address_text": "Carrera 27 #10-02, Álamos (frente al edificio Favi)",
        "lat": 4.79105,
        "lon": -75.690601,
        "geo_precision": "approximate",
        "lifecycle_status": "active",
        "last_confirmed_at": "2026-08-14T09:00:00Z",
        "contradictions_active": 2,
        "last_reported_absent_at": "2026-08-15T20:15:00Z",
        "merged_into": "acop-0040",
        "source": { "source_id": "partner-feed-demo", "source_url": "https://partner.invalid/feed.json", "retrieved_at": "2026-08-16T03:00:00Z", "source_kind": "partner_feed" },
        "public_url": "https://acopios-demo.invalid/p/acop-0042"
      }
    ]
  }
}
```

### invalid-1-missing-confirmation-key.json — Does not conform

> **What this example demonstrates:** INVALID — WHY: the first record OMITS the last_confirmed_at key entirely. Omission is non-conforming; the honest form is last_confirmed_at: null ('never confirmed'). The distinction is the trust core's whole point: a consumer must always be able to render an age or 'sin confirmar' — silence is not an answer. VALIDATOR ERROR: data.places[0]: required property 'last_confirmed_at' is missing (did you mean to publish last_confirmed_at: null?).

```json
{
  "$comment": "INVALID — WHY: the first record OMITS the last_confirmed_at key entirely. Omission is non-conforming; the honest form is last_confirmed_at: null ('never confirmed'). The distinction is the trust core's whole point: a consumer must always be able to render an age or 'sin confirmar' — silence is not an answer. VALIDATOR ERROR: data.places[0]: required property 'last_confirmed_at' is missing (did you mean to publish last_confirmed_at: null?).",
  "last_updated": "2026-08-16T04:00:00Z",
  "ttl": 300,
  "version": "0.1.0",
  "publisher_id": "example-app",
  "license": "CC-BY-4.0",
  "data": {
    "places": [
      {
        "id": "300",
        "publisher_id": "example-app",
        "name": "Punto de acopio El Remanso",
        "place_kind": "collection_center",
        "municipality_code": "66001",
        "address_text": "Av. principal El Remanso, junto al centro de salud",
        "lifecycle_status": "active",
        "source": { "source_id": "example-app" },
        "public_url": "https://example-app.invalid/lugares/300"
      }
    ]
  }
}
```

### invalid-2-contact-and-personal-data.json — Does not conform

> **What this example demonstrates:** INVALID — WHY (three violations of §7): (1) a phone number travels in the feed ('x_example_phone' — namespaced extensions do NOT exempt contact data; contact is public_url + link-out, fetch-on-demand from origin); (2) confirmed_by carries a person's NAME instead of a role token; (3) description embeds a personal name and phone (free text is the third leak channel — publishers MUST strip before publishing). Schema alone passes some of these; the validator's deny-pattern pass catches them all. VALIDATOR ERRORS: data.places[0].x_example_phone: contact values MUST NOT travel in feeds (use contact_available + public_url) · data.places[0].confirmed_by: must be a role token (team|volunteer|official_source|partner:{id}), never a personal name · data.places[0].description: possible personal data detected (name+phone pattern) — strip before publishing.

```json
{
  "$comment": "INVALID — WHY (three violations of §7): (1) a phone number travels in the feed ('x_example_phone' — namespaced extensions do NOT exempt contact data; contact is public_url + link-out, fetch-on-demand from origin); (2) confirmed_by carries a person's NAME instead of a role token; (3) description embeds a personal name and phone (free text is the third leak channel — publishers MUST strip before publishing). Schema alone passes some of these; the validator's deny-pattern pass catches them all. VALIDATOR ERRORS: data.places[0].x_example_phone: contact values MUST NOT travel in feeds (use contact_available + public_url) · data.places[0].confirmed_by: must be a role token (team|volunteer|official_source|partner:{id}), never a personal name · data.places[0].description: possible personal data detected (name+phone pattern) — strip before publishing.",
  "last_updated": "2026-08-16T04:00:00Z",
  "ttl": 300,
  "version": "0.1.0",
  "publisher_id": "example-app",
  "license": "CC-BY-4.0",
  "data": {
    "places": [
      {
        "id": "77",
        "publisher_id": "example-app",
        "name": "Acopio Consota",
        "place_kind": "collection_center",
        "municipality_code": "66001",
        "address_text": "Mz 7 y 8, Villa Consota, Cuba",
        "lifecycle_status": "active",
        "last_confirmed_at": "2026-08-15T10:00:00Z",
        "confirmed_by": "María Ejemplo Pérez",
        "description": "Recibe alimentos. Preguntar por María Ejemplo Pérez, cel 3000000000.",
        "x_example_phone": "+57 300 000 0000",
        "source": { "source_id": "example-app" },
        "public_url": "https://example-app.invalid/lugares/77"
      }
    ]
  }
}
```

### invalid-3-status-in-name-and-always-now.json — Does not conform

> **What this example demonstrates:** INVALID — WHY (two production-observed anti-patterns): (1) CR-2 violation: the name encodes operational state ('(cerrado ahora)') — observed verbatim in the wild; state belongs in lifecycle_status/service_status so it can change without breaking name-based reconciliation, and so two publishers' opposite statuses are COMPARABLE fields, not prose. (2) The always-now anti-pattern: this feed's last_updated is regenerated per request (validator detects it by probing twice and seeing the value advance with the clock while content is unchanged) — worse than no signal, consumers can never detect change. Also note the record contradicts itself: name says closed, lifecycle_status says active. VALIDATOR ERRORS: data.places[0].name: operational state token detected in name ('cerrado') — move to service_status/lifecycle_status (CR-2) · envelope.last_updated: value advanced with the probe clock on identical content — generate at build/publish time, not per request.

```json
{
  "$comment": "INVALID — WHY (two production-observed anti-patterns): (1) CR-2 violation: the name encodes operational state ('(cerrado ahora)') — observed verbatim in the wild; state belongs in lifecycle_status/service_status so it can change without breaking name-based reconciliation, and so two publishers' opposite statuses are COMPARABLE fields, not prose. (2) The always-now anti-pattern: this feed's last_updated is regenerated per request (validator detects it by probing twice and seeing the value advance with the clock while content is unchanged) — worse than no signal, consumers can never detect change. Also note the record contradicts itself: name says closed, lifecycle_status says active. VALIDATOR ERRORS: data.places[0].name: operational state token detected in name ('cerrado') — move to service_status/lifecycle_status (CR-2) · envelope.last_updated: value advanced with the probe clock on identical content — generate at build/publish time, not per request.",
  "last_updated": "2026-08-16T04:59:59Z",
  "ttl": 300,
  "version": "0.1.0",
  "publisher_id": "example-app",
  "license": "CC-BY-4.0",
  "data": {
    "places": [
      {
        "id": "912",
        "publisher_id": "example-app",
        "name": "Centro de acopio IE María Auxiliadora (cerrado ahora)",
        "place_kind": "collection_center",
        "municipality_code": "66170",
        "address_text": "Cl. 43 #13-74, Dosquebradas",
        "lifecycle_status": "active",
        "last_confirmed_at": "2026-08-15T18:00:00Z",
        "source": { "source_id": "example-app" },
        "public_url": "https://example-app.invalid/lugares/912"
      }
    ]
  }
}
```

## Site Navigation

- [Home](https://cabuya.org/)
- [Specification](https://cabuya.org/developers/spec)
- [Schemas](https://cabuya.org/developers/schemas)
- [RFCs](https://cabuya.org/rfcs)
- [Changelog](https://cabuya.org/changelog)
- [Developers](https://cabuya.org/developers)
- [Registry](https://cabuya.org/registry)
- [Governance](https://cabuya.org/governance)
- [Join](https://cabuya.org/join)
- [GitHub](https://github.com/Cabuya)
- [Agent skill repository](https://github.com/Cabuya/cabuya-skill)
- [Founding record](https://github.com/Cabuya/cabuya.org/tree/main/docs/context)
