Skip to content
LogoLogo

Workflows

A workflow is a set of typed private records (Canton's contracts) with signatories and observers, and programs whose methods (Canton's choices) consume and create them. A transaction is a set of fragments, one per party's view (Canton's projections), each proven by that party and its institution, and joined by one proof that checks the fragments' flows pair up.

Nobody re-executes anything, no counterparty has to be online to validate, and the chain learns a fixed-shape record per transaction and nothing about which program ran. Weld's hold becomes a library template. Weld's policy slot, wrapper, registry, context typing, and framework are reused unchanged in shape.

Loading diagram...

Goals

  1. A developer writes a multi-party workflow as templates and choices in Noir, in the shape of a Daml module, and the framework generates every circuit.
  2. Canton's ledger-model guarantees hold cryptographically: well-authorized creation and exercise, consistency, and need-to-know visibility at the level of a party's view.
  3. Atomic composition across programs and parties in one transaction without any party seeing another party's view.
  4. The chain learns neither program, method, template, amounts, nor parties.
  5. The FI policy slot applies to every fragment.

Non-goals in v1

Private calls between programs inside one fragment, contract keys, mutually secret computation, reads of live private state without consumption, and batch scheduling. Each is discussed under open questions.