Dataset catalog
Dataset records group one GIS collection or product layer with visibility and policy controls.
terminode.xyz
TermiNode turns governed datasets, versioned features, bounded queries, oracle proof workflows, and export evidence into a live DApp.
Core workflow
Create datasets, ingest spatial features, inspect current geometry, compare versions, verify high-value coordinates, and archive evidence packages.
Dataset records group one GIS collection or product layer with visibility and policy controls.
Each feature carries current geometry and version context for audit review.
Snapshots and proof receipts can be copied or exported for review.
Organization access
The local release candidate adds bounded organization-sponsored writes beside personal prepaid credits. A sponsor funds one workspace while importers remain identifiable through RBAC and per-member usage.
Total spend, per-member spend, optional expiry, active state, and remaining balance are enforced by the spatial canister.
An authorized importer can write a linked dataset without receiving TRMG or managing a ledger approval.
Revoked, expired, archived, over-limit, or unauthorized delegated writes stop before feature state changes.
Repeatable delivery
The local release candidate binds a stable source-system key to one TermiNode feature. Expected revisions stop stale jobs, while exact retries return a no-op instead of another feature version or write charge.
Source system, layer, and feature ID identify one upstream GIS record inside a governed dataset.
A changed payload must name the currently accepted revision before it can create a new spatial version.
Bounded batch reports expose created, updated, no-op, archived, conflicted, and failed entries with a deterministic checksum.
Controlled decisions
The local release candidate separates importer, reviewer, and approver responsibilities. Each decision binds an exact geometry version to actors, timestamps, safe evidence references, and a checksum-backed report.
A decision names one feature and version, so a later geometry update cannot silently inherit an older approval.
Review and approval are distinct canister-enforced transitions with owner and controller recovery paths.
A newer accepted version becomes current while the former accepted record remains readable as Superseded.
Operations
Launch evidence, controller drift checks, metrics snapshots, hardened asset headers, and domain smoke tests reduce operational guesswork.
The canonical DApp is served from the `frontend_assets` canister.
Production env checks prevent incomplete frontend configuration from shipping silently.
Internal market, fiat, custody, and exchange-like surfaces remain outside the default launch.