Skip to content
DRAFT⚠OIML SMART pilot programme · internal use only · all documents and specifications are drafts and may change without notice

The standards licenses

A certification procedure sometimes applies a standard the platform does not publish itself, because another publisher holds its text. The platform answers with a due process, not an upgrade screen: the organization's declaration opens nothing by itself, the scheme operator's confirmation opens the licensed procedure's interactive tier in the test run, and a per-key history keeps every row of the arc. This walkthrough performs the whole process on the live demo, from the citation tier to the unlocked stepper and back.

Try this flow now

Assume the Test Laboratory persona through the identity service and open the surge run below to see the citation tier; the OIML-CS Administrator persona holds the scheme operator's confirmation queue. The instance resets nightly and the license posture resets with it.

→

The flow at a glance

The actors are two roles. The laboratory's operator (the Test Laboratory seat of the Blefuscu Central Laboratory, BCL, a fictional laboratory) works the test runs; the scheme operator (the OIML-CS Administrator seat of the OIML-CS console) works the confirmation queue. The demo seeds the Blefuscu Central Laboratory with two confirmed licenses and one declaration awaiting confirmation, so a single laboratory sign-in shows both tiers side by side: the confirmed standards walk the interactive stepper, the declared one renders the citation tier.

The doctrine the flow demonstrates is that a declaration alone opens nothing. An attestation that opens nothing is the point: the organization's administrator declares the license it holds, with the evidence reference written on the record, and the tier opens only when the scheme operator confirms that declaration. Only the operator's revoke closes the tier again, and a revoke carries a mandatory reason. The whole arc stays readable afterwards in the per-key history.

FIG. THE LICENSE DUE PROCESSFIG. THE LICENSE DUE PROCESS4 ACTORSSTEP 01The run, unlicensedthe citation tieropens nothingthe declaration aloneSTEP 02The declarationthe attestation + evidenceopens the tierdeclared to activeSTEP 03The confirmationthe scheme operator's actcloses the tierthe revoke, note mandatorySTEP 04The run, licensedthe interactive stepper

The walkthrough

S1

The citation tier: the run that applies an unlicensed standard

The laboratory's operator opens the surge test on the worked example's load cell, the test whose procedure applies IEC 61000-4-5. The Example Laboratory holds no confirmed license for that standard, so the run renders the citation tier: the Recommendation's own declared form exactly as it renders without the licensed tier, plus the behavior's citation naming the applied standard and a license hint naming the two acts that open the interactive tier, the organization's declaration and the scheme operator's confirmation. The page makes no licensed request at all; nothing of the other publisher's text arrives, and nothing is teased, blurred, or gated mid-form.

Try it:sign in as Test Laboratory, then work in/app/lab/run/…on the demo instance.

The surge run at the laboratory rendering the citation tier: the behavior's citation, the license hint naming the two acts that open the interactive tier, and the plain procedure form beneath.
The surge run at the laboratory rendering the citation tier: the behavior's citation, the license hint naming the two acts that open the interactive tier, and the plain procedure form beneath. Live surface · captured 2026-09-22 by the scripted apparatus.
S2

The queue: the declaration awaiting its answer

The declaration half of the process has already happened on the demo: the Example Laboratory's declaration for the surge standard stands in the queue at status declared, recorded through the same kernel verbs a live declaration uses. The evidence reference rides the row (the IEC Webstore order number), and the declaring actor is named. On a production deployment the declaration is the organization administrator's act, made in the organization settings' Standards licenses tab, and nothing about it is pre-provisioned; the demo provisions it through the seed because the demonstration cast carries no organization administrator to walk that tab live.

Try it:sign in as OIML-CS Administrator, then work in/app/cs/standards-licenseson the demo instance.

The scheme operator's Standards licenses queue with the laboratory's declared surge row awaiting confirmation, its evidence reference and declaring actor named.
The scheme operator's Standards licenses queue with the laboratory's declared surge row awaiting confirmation, its evidence reference and declaring actor named. Live surface · captured 2026-09-22 by the scripted apparatus.
S3

The confirm act: the scheme operator answers the declaration

The scheme operator opens the queue, reads the attestation's evidence reference, adds a verification note recording what was checked, and confirms. The row moves from declared to active, the record stamps the confirming seat's name beside the note, and the row leaves the pending list. The act is deliberately a scheme seat's and no one else's: the organization cannot confirm its own declaration, and the queue is seated by role, so the confirmation is the scheme's answer, not a self-service switch. The demo names its built shape honestly: this build scopes the CS administrator's session to its own organization, so the demonstration's confirmation rides the platform administrator's organization-unbound seat, the same account the platform's own end-to-end suite drives for this arc.

Try it:sign in as OIML-CS Administrator, then work in/app/cs/standards-licenseson the demo instance.

The confirm act on the scheme operator's console: the verification note typed against the declared surge row, the confirmation button ready.
The confirm act on the scheme operator's console: the verification note typed against the declared surge row, the confirmation button ready. Live surface · captured 2026-09-22 by the scripted apparatus.
S4

The tier unlocks: the same run, now interactive

The laboratory's operator re-opens the same surge run. The run re-resolves the organization's active entitlement set on every document load, and the citation tier gives way to the interactive tier: the licensed procedure's phases walk as a stepper in the order the model declares, each phase carrying its clause anchor and its declared record fields, and the phase readings evaluate against the declared tolerances as the operator works. The entitlement state is cached at the edge for a short window, so the first reload after a confirmation can still show the citation banner; the next one carries the stepper, which is the honest cost of the cache and nothing more.

Try it:sign in as Test Laboratory, then work in/app/lab/run/…on the demo instance.

The same surge run after the confirmation: the licensed procedure's phases walking as the stepper in the model's order, the citation banner gone.
The same surge run after the confirmation: the licensed procedure's phases walking as the stepper in the model's order, the citation banner gone. Live surface · captured 2026-09-22 by the scripted apparatus.
S5

The history: the arc, readable after the fact

Every status change appends to the per-key history, so the row's whole life reads in one place: who attested and on what evidence, who confirmed and why, and any revoke with its mandatory reason. Nothing is ever removed. The capture reads the demonstration's own row end to end: the seed's declaration, the capture drive's confirmation, and the drive's revoke restoring the demonstration posture; the nightly reset returns the row to its documented starting posture, and the history keeps every row it passed through.

Try it:sign in as OIML-CS Administrator, then work in/app/cs/standards-licenseson the demo instance.

The per-key history reading the surge row's whole life: the declaration with its attesting actor and evidence reference, the confirmation with its verification note, and the revoke with its mandatory note.
The per-key history reading the surge row's whole life: the declaration with its attesting actor and evidence reference, the confirmation with its verification note, and the revoke with its mandatory note. Live surface · captured 2026-09-22 by the scripted apparatus.

The presenter scripts

Two lengths, keyed to the steps above (S1 to S5). Print this page for a clean copy of the scripts.

The 5-minute presenter script · the committee slot

  1. 0:00The gate question: when a procedure applies a standard another publisher holds, what does the software do? The answer is not an upgrade screen; it is a due process. Simulated cast, nightly reset.
  2. 0:30S1The citation tier: the surge run renders the plain declared form, the citation naming the applied standard, and the hint naming the two acts that open the tier. The page makes no licensed request; the wire carries nothing of the other publisher's text.
  3. 1:30S2The queue: the scheme operator's console lists every declared row across the registered organizations with its evidence reference. The surge row stands at declared; a declaration alone opens nothing.
  4. 2:30S3The confirm act: the operator reads the evidence, adds the verification note, and confirms. Declared becomes active, the record stamps the operator's name, and the queue row leaves the pending list.
  5. 3:30S4-S5The same run re-opened walks the licensed procedure as a stepper, phases in the model's order with clause anchors. The per-key history reads the arc: who attested, on what evidence, who confirmed and why. Only the operator's revoke closes the tier, and the revoke carries a mandatory reason.
  6. 4:30Try it: the Test Laboratory account for the runs, the OIML-CS Administrator account for the queue, on demo.oimlsmart.org.

The 20-minute presenter script · the working visit

  1. 0:00Frame: certification workflows cite standards the platform does not publish. The platform's answer is an entitlement lifecycle with a due process on it, and the demo seeds one laboratory mid-process so both tiers show under one sign-in. Simulated cast, nightly reset.
  2. 1:00S1The citation tier in depth: open the surge run and read the banner aloud. The plain form is the same surface the Recommendation always rendered; nothing is hidden, nothing blurred, no licensed chunk crosses the wire. The honest refusal is the server-side gate answering any unlicensed request.
  3. 3:00S1The contrast: the same laboratory's humidity and burst runs, whose licenses stand confirmed, render the interactive stepper today. One login, both tiers; the tier never branches on a standard id, it derives from the model's reference, the license catalog, and the organization's entitlement set.
  4. 5:00S2The declaration: on a production deployment the organization administrator declares in the settings' Standards licenses tab, ticking the attestation and entering the evidence reference; the tab is seated by the registry's organization type, so an applicant organization never sees it. The demo pre-provisions the row with the same kernel verb, the same history row, and the same queue entry the tab would produce, because the demo cast carries no organization administrator.
  5. 8:00S3The confirmation as governance: the queue is the scheme's answer to declarations, seated by role. Read what the record keeps: the operator's name beside the note recording what was verified. The organization cannot confirm itself in.
  6. 10:00S4The unlock, live: re-open the surge run. The first reload may still show the citation banner because the entitlement echo is cached for a short window at the edge; say so before the room sees it, then reload again and the stepper stands. The phases walk in the model's declared order with their clause anchors; the phase records land on the run's evidence as model-keyed fields.
  7. 13:00S4The records question: the evaluation project and the test report derive from the stepper's evidence exactly as they do from manual entries, so a licensed procedure changes what the operator walks, never what the scheme receives.
  8. 15:00S5The history and the revoke: every row appends. Perform the revoke on any active row and show the mandatory-note refusal first, then the revoke with its reason, and the tier closing on the run's next document load. The history never forgets a row, which is what makes the operator's power accountable.
  9. 18:00The catalog question: the license keys exist in the generated catalog and nowhere else; a declaration validates against it, so a newly licensed standard gates with zero code change. Close on the try-it path: Test Laboratory for the runs, OIML-CS Administrator for the queue.

The honest questions

Is this a paywall inside a conformance scheme?

No: what the license gates is the text of a standard another publisher holds, not the certification workflow. The unlicensed run renders the Recommendation's own declared form and proceeds; the evidence, the report, and the evaluation all work unchanged. What the confirmation adds is the licensed procedure walked interactively, the phases, the clause anchors, and the tolerance-bearing records, in place of the plain form.

Who can declare, and who can confirm?

The declaration belongs to the organization's own administrator, in the organization settings' Standards licenses tab, with the attestation ticked and the evidence reference entered; the tab is seated by the registry's organization type, so an applicant organization never sees it. The confirmation belongs to the scheme operator alone, in the OIML-CS console's queue, and so does the revoke, whose note is mandatory. No seat can perform another seat's act.

What does the unlicensed surface hide?

Nothing that was there before it. The citation tier is the same plain declared form the run rendered before the licensed tier existed, with the citation and the license hint added; there is no teased content, no blurred text, and no request for licensed material leaves the browser. The server-side gate holds independently, answering an unlicensed request for licensed content with a named refusal.

What happens when a license is revoked or expires?

The tier closes on the run's next document load, and the citation tier stands in its place again; the entitlement cache bounds the switch by its short lifetime, never by a redeploy. The revoke's reason lands on the per-key history beside the declaration and the confirmation, and the history is append-only, so the row's whole life stays readable to the scheme operator and the organization alike.

Verified 2026-09-22: every step above was performed headlessly against the live demo by scripts/capture-walkthroughs.ts (the citation tier and the queue in both themes; the confirm act, the unlocked stepper, and the history under the drive flag, which restored the documented license posture with a revoked-and-noted row after capturing) and each capture carries its assertion record in public/img/walkthroughs/manifest.json. The step names and machine states match the engineering record (DEMO_FLOWS/07) in the smart repository.