Skip to content
โ—‡ AirawatOS Developer
๐Ÿšง Under development โ€” this portal is being built track by track. Content will keep growing, and some sections are still placeholders.

Deep Dives

Worked example: money across tenants

How a water-supply grant moves from a national ministry, through a state, to a city โ€” and why the money follows the information.

A single-organization workflow stays inside one tenant. This one crosses sovereign tenants โ€” a ministry, a state department, a city โ€” none of which can see into another's database. It shows the platform's sharpest civic idea: the flow of information across agencies determines the flow of money. Make the information flow governed, shared, and tamper-evident, and the money flow follows it โ€” with no PDFs, no portal reconciliation, and one true picture everyone can trust.

This is the pattern behind India's centrally-sponsored schemes (PMAY-U, AMRUT, Jal Jeevan Mission) โ€” the classic 60:40 Centre:State co-funding, released in instalments gated on reported progress. It composes primitives you've already met โ€” the cross-tenant data-request/grant lane, signed decisions, double-entry finance, and verifiable credentials โ€” arranged along the jurisdiction ladder (nation โ†’ state โ†’ city).

The players โ€” three tenants

Each is sovereign over its own data. Nobody has a login to anyone else's system. Everything below moves through the governed cross-tenant lane: a tenant requests to see another's record, that tenant's admin consents, and a signed grant lets the kernel serve exactly that data โ€” and only that data โ€” leaving a receipt.

The loop โ€” information gates money

1. The city assesses need (its own data). KMC's diagnosis โ€” coverage gaps in piped water, drawn from its governed layers โ€” becomes a governance.recommendation and then a funding proposal: "extend supply to these wards; โ‚นX." It's a signed record in KMC's tenant. Nothing has left the city yet.

2. The funders see the proposal โ€” under consent. KMC submits the proposal to the scheme. MoHUA and HUDD don't get a copy of KMC's database โ€” they file a data-request for that proposal; KMC's admin approves; the kernel issues a signed grant and serves just the proposal, with a data-read receipt KMC keeps as proof of what it shared, with whom, when. The funders now see the same proposal the city sees โ€” one true picture, no re-keying.

3. The ministry sanctions โ€” a decided change-request. MoHUA reviews and admits it. That's a signed decision (governance.decision) โ€” never an automatic transfer; a named official decided, and it's tamper-evident. The sanction is co-funded 60:40, so it references the state's share too. MoHUA issues KMC a verifiable credential โ€” an award the city holds in its wallet as portable proof it was funded, verifiable by anyone without calling MoHUA.

4. Money posts โ€” double-entry, in each tenant's books. The disbursement of tranche 1 is a finance.transaction โ€” double-entry, posted in the funder's ledger and received in the city's. Because it's a decided change-request, there's a decision behind every rupee. The state's 40% posts the same way from HUDD. The money moved because a signed sanction moved.

5. The city executes and reports โ€” the same lane, in reverse. KMC does the work and records progress against the project's results-contract โ€” per-step receipts and a milestone credential ("phase 1 complete, verified"). This isn't a report typed into three different portals; it's governed data.

6. Verified progress releases the next tranche. MoHUA and HUDD read that verified progress through the same governed lane (request โ†’ consent โ†’ grant โ†’ receipt). Because the completion is a signed, verifiable fact โ€” not a claim in an email โ€” it satisfies the release condition automatically, and tranche 2 is sanctioned. A verified progress report reached the funder, so the money followed.

Why this is different

Every hop shares the property that makes it work:

That's fiscal federalism as a data problem, solved once: sovereign tenants, governed sharing under consent, signed decisions, and money that follows verified information down the jurisdiction ladder.

This composes the cross-tenant lanes and finance/decision primitives the platform already provides; the full multi-tier program orchestration is a separate design for federated program funding. Related: Participants & the Network (tenants + federation), Governance & Decisions (signed decisions), and Data Ownership & Consent (why a link is not access).