ED03 - Diary Format: JSON Artefacts, Temporal Signature, V7GUID, Sidecars
Problem
An entrepreneur wants to keep their diary in Git - but what exactly does an entry look like technically? Today's practice knows no binding answer:
- Free-text notes in Markdown, Word or paper - not machine-readable, not schema-validated, not traceable
- Excel rows with date, activity, hours - not versioned, not cryptographically anchored, not auditable
- Payroll-software exports as PDF - not machine-evaluable (§ 147 Abs. 6 AO), not retrogradely/progressively traceable
- No unique identity - every entry has a file name, but the file name can change; the identity of the entry is not stable
- No temporal anchoring - the date is a string in the document, but who recorded what when? The recording time is not cryptographically linked to the identity
Core Statement
A GitCover diary entry is a JSON artefact with:
- JSON-Schema-First - the schema exists before the entry; the entry is validated against the schema (Pre-Commit hook)
- V7GUID (Class Identifier) - classifies the document/action based
on the
.gitcoverregistry (what/which type); serves storage organisation and DB query (e.g. EF Core in a Vertical App) - uuidV7 (Object ID) - is already alone the unique identity
(DocID) of the entry, RFC 9562 §5.7, generated from a
predefined timestamp (not
now()) via GitCover helper (UuidV7Gen), rest filled with randomness - Composite Key
V7GUID:uuidV7- the GCPN Sidecar Composite Key, serves storage organisation and query; the recording time is in theuuidV7(48-bit timestamp), no separatedatetime/datefield - Sidecar obligation - every document receives a
.v7g.mdsidecar with its ownuuidV7(classification act) and theuuidV7of the document - Retrograde/progressive traceability - resolvable from the
booking record → document → diary entry →
uuidV7and back
Compliance by Design: The format is not after the fact - it is structural. Schema, V7GUID (Class), uuidV7 (Object) and sidecar are mandatory fields, without which an entry is not admitted to the repo.
No redundant
datetime/date: The recording time is anchored in theuuidV7itself (48-bit timestamp, RFC 9562 §5.7). A separate string representation in JSON schemas or JSON data is redundant and is not kept in the facts. String representation for DTO/HTMX transfer is the harness's responsibility, not the facts layer.
The JSON Schema (Schema-First)
(vor Eintrag)"] S --> V["Schema-Validierung
(Pre-Commit-Hook)"] E["Tagebucheintrag
(JSON)"] E --> V V -->|gültig| C["Commit akzeptiert
+ uuidV7 generiert"] V -->|ungültig| R["Commit abgelehnt
Schema-Verstoß"] style S fill:#DBEAFE,stroke:#1D4ED8,color:#0F1B33 style V fill:#DBEAFE,stroke:#1D4ED8,color:#0F1B33 style E fill:#0F1B33,stroke:#0F1B33,color:#FBFAF7 style C fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33 style R fill:#FDBA74,stroke:#C2410C,color:#0F1B33
The schema exists before the entry - it is stored in
.gitcover/schemas/diary-entry-1.0.schema.json and is versioned. An
entry without a schema reference ($schema) is rejected by the
Pre-Commit hook.
Schema diary-entry-1.0.schema.json (simplified)
{
"$schema": "https://json-schema.org/draft/2020-12/schema",
"$id": "https://gitcover.org/schemas/diary-entry-1.0.schema.json",
"title": "GitCover Diary Entry v1.0",
"type": "object",
"required": [
"$schema", "V7GUID", "uuidV7",
"author", "role", "tenant", "sphere", "source"
],
"properties": {
"$schema": {
"type": "string",
"format": "uri",
"const": "https://gitcover.org/schemas/diary-entry-1.0.schema.json"
},
"V7GUID": {
"type": "string",
"description": "Class Identifier - klassifiziert das Dokument/die Action aus .gitcover Registry (was/welcher Typ)"
},
"uuidV7": {
"type": "string",
"pattern": "^[0-9a-f]{8}-[0-9a-f]{4}-7[0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$",
"description": "Object ID - RFC 9562 §5.7 UUIDv7, generiert aus vorgegebener Zeitmarke (nicht now()), 48-Bit-Zeitstempel in der GUID verankert"
},
"author": { "type": "string", "description": "Akteur-Platzhalter, z. B. E1" },
"role": {
"type": "string",
"enum": ["GF", "Buchhalter", "Lohnverantwortlicher", "F&E-Leiter", "Administrator"]
},
"tenant": { "type": "string", "description": "Tenant-Platzhalter, z. B. ORG-1" },
"sphere": {
"type": "string",
"enum": ["ideell", "vermögensverwaltend", "zweckbetrieblich", "wirtschaftlich", "n/a"]
},
"source": {
"type": "string",
"enum": ["E1", "StB", "Notar", "Bank", "DRV", "FA", "BA", "VBG", "KK", "auto"]
},
"source_sha256": {
"type": "string",
"pattern": "^[0-9a-f]{64}$",
"description": "SHA-256 des referenzierten Belegs (eindeutige Beleg-ID)"
},
"tags": { "type": "array", "items": { "type": "string" } }
}
}
Important - no
datetime/datefield: The recording time is in theuuidV7(48-bit timestamp, RFC 9562 §5.7). A separate string representation is redundant and is not kept in the facts. TheuuidV7alone is the unique DocID; the Composite KeyV7GUID:uuidV7serves storage organisation and DB query.
V7GUID - Structure and 48-bit Timestamp
Bits 0–47
48 Bit Unix-ms"] V["version
Bits 48–51
0111 (UUIDv7)"] R["rand_a
Bits 52–63
12 Bit"] VA["variant
Bits 64–65
10"] RB["rand_b
Bits 66–127
62 Bit"] end T --> DT["48-Bit-Zeitstempel
in uuidV7 verankert
(kein separates datetime-Feld)"] V7 --> ID["uuidV7-Feld
Object ID
(vorgegebene Zeitmarke)"] style T fill:#DBEAFE,stroke:#1D4ED8,color:#0F1B33 style V fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33 style R fill:#E5E7EB,stroke:#6B7280,color:#0F1B33 style VA fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33 style RB fill:#E5E7EB,stroke:#6B7280,color:#0F1B33 style DT fill:#0F1B33,stroke:#0F1B33,color:#FBFAF7 style ID fill:#0F1B33,stroke:#0F1B33,color:#FBFAF7
| Bit Range | Width | Content | RFC-fixed |
|---|---|---|---|
| 0-47 | 48 bit | Unix milliseconds since Epoch (1970-01-01T00:00:00Z) | Yes (RFC 9562 §5.7) |
| 48-51 | 4 bit | Version = 0111 (UUIDv7) |
Yes |
| 52-63 | 12 bit | rand_a (random) | No |
| 64-65 | 2 bit | Variant = 10 |
Yes |
| 66-127 | 62 bit | rand_b (random) | No |
Core principle: The 48-bit timestamp component (bits 0-47) is authoritative for the recording time. It is anchored in the
uuidV7itself and cannot be changed afterwards without invalidating the GUID. A separatedatetimefield does not exist - the time is in theuuidV7. String representation for DTO/HTMX is the harness's responsibility.
GitCover Extension: Hierarchy and Process IDs in Bits 66-127
The GitCover V7GUID specification
(work/OSS/TOP/.gitcover/specs/v7guid/) extends the 62-bit random
component (bits 66-127) with a 6-level hierarchy and process
IDs - this is the patent-protected extension (DPMA Az. 10 2025 003
091.6):
| Bit Range | Width | Content |
|---|---|---|
| 66-89 | 6×4 bit | 6-level hierarchy (L1-L6, 4 bit each) |
| 90-97 | 8 bit | ProcessTypeId (process type) |
| 98-105 | 8 bit | GatewayId (control point) |
| 106-113 | 8 bit | Status (lifecycle bitmask) |
| 114-121 | 8 bit | Kind (type of activity) |
| 122-127 | 6 bit | VariantId (variant class) |
Note: This extension is not mandatory for the diary series - it becomes relevant in ED02 (Tenant/Sphere/Role) and later articles (Harness). Here the RFC 9562 basis with 48-bit timestamp suffices.
Helper Routines: Creating V7GUID from Foreign Keys
(Zeitmarke in Daten
oder Dateiname)"] F --> H["Helper-Routine
UuidV7Gen"] H --> TS["48-Bit-Zeitstempel
extrahiert/konvertiert"] TS --> G["uuidV7 generiert
(Guid.CreateVersion7)"] G --> A["JSON-Artefakt
V7GUID + uuidV7"] A --> D["GoBD-Dokumentation
zeitnahe Erfassung
nachvollziehbar"] style F fill:#FDBA74,stroke:#C2410C,color:#0F1B33 style H fill:#DBEAFE,stroke:#1D4ED8,color:#0F1B33 style TS fill:#DBEAFE,stroke:#1D4ED8,color:#0F1B33 style G fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33 style A fill:#0F1B33,stroke:#0F1B33,color:#FBFAF7 style D fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33
The GitCover OSS tool UuidV7Gen
(work/OSS/TOP/tools/UuidV7Gen/) provides two central operations:
gen - generate uuidV7 (guid)
# Erzeugt eine neue uuidV7 mit vorgegebener Zeitmarke (nicht now())
# Zeitmarke z. B. aus Dateiname "260815_0900" → ISO 2026-08-15T09:00:00Z
uuidv7gen gen "2026-08-15T09:00:00Z" "Tagebucheintrag-260815"
# Ausgabe: Label;UUID;ISO-Zeitstempel
# Tagebucheintrag-260815;019f2c6f-0900-7000-8000-000000000000;2026-08-15T09:00:00.000Z
decode - extract timestamp from uuidV7
# Extrahiert den 48-Bit-Zeitstempel aus einer uuidV7
uuidv7gen decode 019f2c6f-0900-7000-8000-000000000000
# Ausgabe: ISO-8601-Zeitstempel
# 2026-08-15T09:00:00.000Z
Foreign Key → uuidV7
The helper routines allow creating a valid uuidV7 key from a
foreign key (e.g. a timestamp in the file name like
260815_0900_Lohnabrechnung.pdf) - with a predefined timestamp,
not now():
- Parse foreign key -
260815_0900→2026-08-15T09:00:00Z - Compute 48-bit timestamp - Unix milliseconds since Epoch
- Generate
uuidV7-Guid.CreateVersion7()with explicit timestamp, rest with randomness - Composite Key -
V7GUID(Class from registry) :uuidV7(Object with timestamp) - GoBD documentation - timely recording traceably anchored (no separate datetime field)
GoBD reference: The timely recording (GoBD Rz. 146) is cryptographically documented by the 48-bit timestamp in the
uuidV7- not merely claimed. The timestamp is part of the identity, not modifiable afterwards.
Sidecar Structure (.v7g.md)
Every document receives a sidecar with two uuidV7 references:
(PDF, XML, EML)"] D --> S["Sidecar .v7g.md"] S --> U1["uuidV7 (eigen)
Identität des Sidecars
+ 48-Bit-Erfassungszeit"] S --> U2["uuidV7 (fremd)
Identität des Dokuments
in v7g_taxonomy"] S --> SH["sha256
Eindeutige Beleg-ID"] S --> T["v7g_taxonomy
Klassifizierung
(Tenant, Sphäre, Kategorie)"] S --> O["obsolescence
status: active/superseded/obsolete"] style D fill:#0F1B33,stroke:#0F1B33,color:#FBFAF7 style S fill:#DBEAFE,stroke:#1D4ED8,color:#0F1B33 style U1 fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33 style U2 fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33 style SH fill:#FDBA74,stroke:#C2410C,color:#0F1B33 style T fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33 style O fill:#E5E7EB,stroke:#6B7280,color:#0F1B33
Sidecar Example
{
"$schema": "https://gitcover.org/schemas/v7g-sidecar-1.0.schema.json",
"V7GUID": "<V7GUID-Class-aus-Registry>",
"uuidV7": "019f2c6f-0900-7001-8000-000000000001",
"sha256": "ab94670c0dd8499c27ef2feddd1d9c5925977d55a52150a6fca0f6567d2e5e79",
"title": "260815_Lohnabrechnung.pdf",
"original_filename": "260815_Lohnabrechnung.pdf",
"locations": [
{
"unc_path": "./ORG-1/sources/lohn/260815_Lohnabrechnung.pdf",
"from": "260815",
"to": null,
"note": "Primärspeicherort"
}
],
"v7g_taxonomy": [
{
"v7guid": "019f2c6f-0900-7000-8000-000000000000",
"taxonomy": "ORG-1/Lohn",
"valid_from": "260815",
"valid_to": null,
"note": "Tenant: ORG-1, Category: Lohn, Sphäre: ideell"
}
],
"gcpn": {
"prima_nota_ref": null,
"journal_entry_ref": null
},
"obsolescence": {
"status": "active",
"superseded_by": null,
"superseded_at": null
}
}
Composite Key
V7GUID:uuidV7:
V7GUID(field 1) - Class Identifier of the sidecar (classification from.gitcoverregistry: what/which type)uuidV7(field 2) - Object ID of the sidecar itself, generated with a predefined timestamp (when was it classified?), 48-bit timestamp anchored in the GUIDv7g_taxonomy[].v7guid- Object ID of the classified document (which document is being classified?)This makes not only the document uniquely identified, but also the classification act itself - including the point in time (in
uuidV7), who classified and in which role. No separatedatetimefield - the time is in theuuidV7values.
Retrograde and Progressive Traceability
(SKR04)"] B --> BE["Beleg
(SHA-256)"] BE --> DE["Tagebucheintrag
(uuidV7)"] DE --> V7["uuidV7
(48-Bit-Zeitstempel)"] end subgraph PRO["Progressiv (vom Beleg vorwärts)"] direction LR BE2["Beleg
(SHA-256)"] BE2 --> BS["Buchungssatz
(SKR04)"] BS --> GB["Grundbuch
(JSON)"] GB --> EB["Eröffnungsbilanz"] end style B fill:#DBEAFE,stroke:#1D4ED8,color:#0F1B33 style BE fill:#FDBA74,stroke:#C2410C,color:#0F1B33 style DE fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33 style V7 fill:#0F1B33,stroke:#0F1B33,color:#FBFAF7 style BE2 fill:#FDBA74,stroke:#C2410C,color:#0F1B33 style BS fill:#DBEAFE,stroke:#1D4ED8,color:#0F1B33 style GB fill:#DBEAFE,stroke:#1D4ED8,color:#0F1B33 style EB fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33
| Direction | Start | Resolution via | Target |
|---|---|---|---|
| Retrograde | Booking record (SKR04) | source_sha256 → document → uuidV7 |
Diary entry with 48-bit timestamp |
| Progressive | Document (SHA-256) | uuidV7 → diary entry → source_sha256 |
Booking record → ledger → opening balance |
GoBD reference: Retrograde traceability corresponds to GoBD Rz. 146 (traceability). Progressive traceability corresponds to GoBD Rz. 147 (auditability). Both are guaranteed by Design through
uuidV7+ SHA-256 - not through manual cross-references.
Time Recording in the Diary
Every diary entry contains a time-recording table:
| Start | End | Hours | Activity | Tenant | Sphere | Source |
|---|---|---|---|---|---|---|
| 0900 | 1200 | 3.0 | Payroll master data | ORG-1 | ideell | E1 |
| 1200 | 1400 | 2.0 | R&D: V7GUID specification | ORG-1 | ideell | E1 |
FZul reference: Time recording is the basis for FZul hour records (ED18). The R&D vs. administration separation is done via the
rolefield (F&E-Leitervs.GF) and thetags(["fzul", "forschung"]vs.["verwaltung"]).
What Lands in the Git Repo - and What Does Not
(Tagebucheinträge, Grundbuch)"] IN --> S["Sidecars .v7g.md"] IN --> B["Belege
(PDF, XML, EML)"] IN --> SC["Schemata"] IN --> D["Dictionaries"] OUT["Nicht im Git-Repo"] OUT --> P["Private Dokumente
(sofern nicht ausdrücklich eingeführt)"] OUT --> T["Temporäre Dateien"] OUT --> C["Credentials/Secrets"] style IN fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33 style J fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33 style S fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33 style B fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33 style SC fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33 style D fill:#D1FAE5,stroke:#0A7F5C,color:#0F1B33 style OUT fill:#FDBA74,stroke:#C2410C,color:#0F1B33 style P fill:#FDBA74,stroke:#C2410C,color:#0F1B33 style T fill:#FDBA74,stroke:#C2410C,color:#0F1B33 style C fill:#FDBA74,stroke:#C2410C,color:#0F1B33
Important: Only structured artefacts (JSON, sidecars, documents, schemas, dictionaries) are admitted to the Git repo. Private documents are never admitted to the repo unless they have been explicitly introduced and classified as artefacts. This is a data protection and compliance requirement (GDPR, GoBD).
Risk Leverage
| Today (cheap) | Tomorrow (auditable) | Risk mitigated |
|---|---|---|
JSON artefact with V7GUID (Class) + uuidV7 (Object) |
Recording time cryptographically anchored in uuidV7 | Dispute of recording time |
| Schema validation (Pre-Commit) | Only valid entries into the repo | Schema violation, incomplete mandatory fields |
Sidecar with Composite Key V7GUID:uuidV7 |
Classification act traceable | Dispute of classification |
source_sha256 per entry |
Retrograde traceability | Dispute of document assignment |
Helper UuidV7Gen for foreign keys |
Timely recording documented (timestamp in uuidV7) | GoBD violation "not timely" |
Harness Requirements (Preview)
Derivable from ED03:
| ID | Requirement | Priority |
|---|---|---|
| FA-1.1 | Diary entries as JSON artefacts (Schema-First) | MUST |
| FA-1.2 | Composite Key V7GUID (Class) : uuidV7 (Object) - no separate datetime/date field; time in uuidV7 (RFC 9562 §5.7) |
MUST |
| FA-1.3 | uuidV7 generated from predefined timestamp (not now()) via helper |
MUST |
| FA-2.1 | SHA-256 as document ID | MUST |
| FA-2.2 | .v7g.md sidecar obligation |
MUST |
| FA-2.3 | Sidecar with Composite Key V7GUID:uuidV7 (Class + Object) |
MUST |
| FA-2.12 | Retrograde traceability (booking → document → uuidV7) |
MUST |
| FA-2.13 | Progressive traceability (document → booking → ledger) | MUST |
| TA-1.5 | Helper routines for V7GUID creation from foreign keys (UuidV7Gen) |
MUST |
| TA-1.6 | Temporal requirements GoBD documented (48-bit timestamp in uuidV7) |
MUST |
| TA-2.1 | Pre-Commit: JSON schema validation | MUST |
The full requirements list in Harness-Anforderungen.md.
Sources
- RFC 9562 §5.7 (UUIDv7) - 48-bit Unix-ms timestamp
- V7GUID specification -
work/OSS/TOP/.gitcover/specs/v7guid/(normative) - DPMA Az. 10 2025 003 091.6 - V7GUID patent (main claim 2, claims 5-8)
- GitCover OSS tool
UuidV7Gen-work/OSS/TOP/tools/UuidV7Gen/(helpergen/decode) - GoBD (BMF letter, Rz. 146 - traceability, Rz. 147 - auditability)
- AO (§ 147 Abs. 2 - "machine-evaluable", § 147 Abs. 6 - data access)
AFJD/agents/(anonymised) - SSoT concept with JSON artefacts, sidecars
Source Topology and CDN Reference Links
| Role | Location | Purpose |
|---|---|---|
| Primary / SSoT | git.gitcover.org/GCC | Canonical storage (GPG-signed, versioned) |
| Public OSS Mirror / CDN | codeberg.org/gitcover-commons | Read-only mirror; FLOSS discovery |
| Community Hub | github.com/gitcover-commons | Issues & Discussions; source-code reference on Codeberg |
Note: This assignment of sources, mirror and community hub reflects the current state and may change. Please check the respective canonical source on gitcover.org for the current state.