| Party | A principal identified by party_id = H(PARTY, ak), admitted by an FI into the party registry, holding a signing key ak and an encryption key epk. |
| Record | A private state object: a salted commitment to a template, an instance, typed fields, a stakeholder set, and a secret rho. Canton's contract. |
| Template | A record schema plus its signatory and observer roles and its choices. |
| Program | A deployable set of templates and methods, registered as one leaf. |
| Instance | Immutable configuration for a program deployment; records are scoped to one. |
| Method | One choice of one template: consumes up to K_R records, creates up to M_R, moves value through notes and flows. Compiled to one application circuit. |
| Stakeholder | A signatory or observer of a record. Signatories authorize creation; observers only receive it. |
| Actor | A party that signs a fragment's manifest. Canton's controller when exercising. |
| Bound note | A native Weld note whose owner is a record rather than a party; it is the way a record holds value. |
| Fragment | One party's view of a transaction: one method invocation, its records, notes, flows, and envelopes, proven by the kernel. Canton's projection. |
| Flow | A salted commitment to (asset, amount, edge_id) that one fragment produces and exactly one other fragment consumes. |
Kernel K | The universal circuit that verifies a method proof and enforces authorization, consistency, conservation, admission, and delivery for one fragment. |
Join J | The universal circuit that verifies N fragments and pairs their flows under one manifest. |
| Manifest | The canonical description of a whole transaction that every actor signs and the pool reconstructs. |