Skip to content

Glossary

The DUST platform vocabulary, in alphabetical order. Docs prose uses these terms consistently; API endpoint paths and field names sometimes keep older implementation names (noted per term).

Making a Label’s DUST markings identifiable, so an Identify scan can find the Label or, once bound, its Thread. Labels enrolled by an enrollment station arrive Verify-only and stay that way until activated. Any Team member can activate a Label or a whole Reel — it is not an administrator action. See Labels and Reels.

Taking a change an upstream source has disclosed into your own copy of a Thread. Adoption is a decision, not a sync: disclosed data stays visible without being adopted, and a copy you have already adopted stays with you even if the source later redacts it. See Disclosures.

Whether two scans of an Identifier could be registered against each other well enough to compare. It is a precondition for a Tamper Analysis, never a result — poor alignment means the comparison is not usable, not that anything is wrong with the item.

The credential issued to a Service Account, exchanged for a short-lived bearer token before calling the API. Personal API keys do not exist. Keys and tokens carry the Service Account’s full access and belong on a server, never in a browser. See Authentication.

Hiding an Identifier from the default view on a Thread without detaching it. The opposite display rule from Void, which keeps the Identifier visible and marked. The two are independent: an Identifier can be archived, voided, or both. See Identifiers and Scanning.

A Thread that aggregates other Threads as its attached parts, while remaining a fully first-class Thread itself — with its own name, Fields, Identifiers, and Certificate. An Assembly can be nested inside another Assembly. Every Thread reachable inside an Assembly belongs to the same owning Team.

The act of associating an Identifier with a Thread, performed through the Identifier endpoints. Once bound, scanning the Identifier resolves back to that Thread.

One operation that binds a Reel Range to an ordered selection of Threads — the first Label in the range to the first Thread, the second to the second, and so on. It is all-or-nothing and never skips a position, because a skip would silently shift every pairing after it. Preview the pairing in the Pick List before binding. See Labels and Reels.

The DUST Camera Controls desktop application, which lets a website drive a connected Dragon — focus and capture settings a browser cannot reach on its own. Optional: the Dragon also works as an ordinary camera without it. See Supported Devices.

A cross-cutting grouping that classifies Threads. Unlike a Folder, a Thread can belong to many Categories at once. Categories can nest under a parent Category (subcategories); membership is direct, not rolled up.

An immutable, point-in-time PDF generated from a Thread’s data and issued by the platform. It is stored as a Resource attached to the Thread, with a record carrying its trust status (issued or voided) and provenance. The Resource checksum is the certificate hash.

A reusable, Team-owned design that defines how a Certificate is laid out and which Thread data fills it. A Certificate Form locates values by field name (with optional aliases), not by Template, so it can generate Certificates for owned, shared, and transferred Threads alike.

The standing relationship between two Teams in different Organizations — the channel for all cross-team exchange. Sharing and Shipments are only initiated over a Connection, and its lifecycle (pending, connected, paused, deleted) and direction (send, receive, or both) govern what may flow between the pair. Teams within one Organization collaborate without a Connection.

Moving a contiguous span of Labels from one Reel onto another — the ledger form of cutting the spool, and how a customer order leaves your inventory. The span is bounded by scanning the first and last Label, or by typed positions. Positions inside the span that cannot move (archived, shipped, or never enrolled) stay behind as gaps, and the resulting count is previewed — and enforced, if you state an order quantity. See Labels and Reels.

A provenance entry a person or a business system asserts, rather than one the platform witnessed — a goods receipt, an inspection sign-off, a sale. Each entry is attributed and permanent: it travels with the item’s history and can be retracted but never deleted. The platform records the claim; it does not verify it. See Recording past events and ERP provenance.

An immutable, numbered version of a Public Page Design — v1, v2, v3 — frozen when the design is published, and the only thing “version” names in the Public Pages module (a page’s own publications are identified by date, never numbered). Publishing a version does not change any live page; pages move onto it only through a rollout, which is forward-only: a Design Version is never restored, and a bad one is corrected by publishing a newer one.

The explicit act by which a Thread owner makes selected data — Fields, Resources, Identifiers, or Certificates — visible downstream through Fabric. Transferred copies are snapshots: source edits propagate only when the owner explicitly discloses them, and a made disclosure is visible to every downstream consumer on the chain.

The USB DUST scanner. It reads a DUST marking through its own optics, so it takes the capture rather than assisting a phone camera the way a Loupe does. At a desk it connects to a computer, where the Camera Controls app adds focus control; on Android it connects to the phone, where DUST Go drives it directly. See Supported Devices.

The physical DUST mark applied to an object, scanned as an image capture and resolved server-side by identifying or verifying it against enrolled Identifiers. A DUST Identifier represents a physical identity and is never copied between Threads. See Identifiers and Scanning.

The mobile entry point for DUST-enabled web experiences: a host app that runs a web page and gives it access to the device’s scanning hardware — the phone camera with a Loupe on iPhone, or a Dragon over USB on Android. Web apps talk to it through the dust-go-connect bridge. See DUST Go.

A station that enrolls Labels onto a Reel through the API, usually alongside the machine that prints or applies them. Stations running unattended enroll Verify-only by default, so the Labels must be activated before an Identify scan can find them.

How many Identifiers of each type a Label on a given Reel carries, entered as a number per type. It guides enrollment — one capture slot per expected Identifier — but never limits what a Label may actually carry. See Labels and Reels.

The cross-team provenance graph of the platform. When a Thread is transferred or sliced, Fabric records the resulting links between source and derived Threads, and carries Disclosures along them — independent of live sharing or Connection state.

A named, typed value on a Thread — text, numbers, dates, images, and other attributes that describe the item the Thread represents. Templates define reusable sets of Fields.

A nestable container that organizes Threads and other Folders. A Thread lives in at most one Folder (single-home — contrast with Category). Sharing a Folder cascades access to its contents.

A DUST Identifier that has been indexed, so an Identify scan can find it. The opposite of Verify-only. DUST markings enrolled in DICE are identifiable by default; ones from an enrollment station become identifiable when activated.

A scannable physical or digital code associated with a Thread: DUST, QR, barcode, Data Matrix, or NFC. The user-facing term for what the API calls a tag — endpoint paths and field names keep the legacy naming (/api/v1/tags, tagType). See Identifiers and Identifiers and Scanning.

The act of finding a Thread by scanning or entering an Identifier. The Teams searched are set per request (the API’s searchTeamIds), defaulting to the Team the request acts in. See Identifiers.

One physical label carrying one or more Identifiers — a printed text code, a DUST marking, a QR code, an NFC chip, a barcode, or a Data Matrix symbol, in any combination. Labels are manufactured on a Reel and keep their physical position on it. Until a Label is bound to a Thread it is inventory; binding it attaches all of its Identifiers at once. See Labels and Reels.

A folder that groups Reels. It is an organizing tool only and is never shipped — contrast a Folder, which organizes Threads. A Reel outside any Collection is unfiled.

An optical accessory that mounts over a phone’s rear camera to magnify a DUST marking for the phone’s own camera to photograph. It is not a camera itself, and it is model-specific: each Loupe fits a particular phone in a compatible MagSafe case. See Supported Devices.

The draft contents of a Shipment or other Fabric operation: the selected Threads, their selected assets, and any Assembly, Folder, or Category structure to carry along. The manifest freezes when the Shipment is sent.

One of the DUST particles a Tamper Analysis counts when comparing a fresh scan against the reference captured at Bind. Distinct from an Identifier: markers are what an individual DUST marking is made of. See Tamper Analysis.

The top-level account boundary, containing Teams and their members. API requests carry the active Organization in the Dust-Ctx-Org-Id header. See Conventions.

A Part is a Thread attached to an Assembly — each Thread is a part of at most one Assembly, and by default inherits the Assembly’s access. A Position is a named Thread-valued Field on an Assembly assigned to one of its attached Threads (for example “front wheel”). Distinct from a Label’s position on its Reel, which is an ordering key on physical inventory rather than a slot on an Assembly.

The position-to-Thread pairing table a Bulk Bind shows before binding and keeps afterwards, downloadable as CSV — so the person at the bench applies the right Label to the right item. Derived from the Reel Range and the selection, never stored as its own record.

The public, unauthenticated web view of a Thread — the digital product passport a consumer reaches by scanning an Identifier or following a printed link. Its URL is permanent and can be reserved (and its QR code printed) before anything is published; until then it serves a “registered” notice. A Public Page carries no content configuration of its own: it shows exactly what its Public Page Design pulls, pinning one Design Version and one publication of its data. See Public Pages.

A reusable, Team-owned design that determines the content and appearance of every Public Page published through it — an ordered stack of blocks that pull Thread data by field name, in the same way a Certificate Form does. One design serves a whole product line; editing it changes nothing public until a Design Version is published and rolled out.

A scoped background run that publishes or republishes every Public Page in a Folder, Category, Template, or explicit selection through one Design Version, with per-Thread success and failure accounting. A wave can be retried for its failures, or cancelled — which stops the remaining pages without moving already-published ones back.

A grant on a Team membership meaning “may make this Team’s data public”. It gates every change in the Public Pages module — authoring and publishing Public Page Designs, publishing and unpublishing pages, rollouts, and Publish Waves. Team admins always hold it; members without it have read-only access to the module. Service Accounts can hold it, for pipeline publishing.

An alternative New Thread flow that opens an optional photo capture step followed by a short create step, with an Add details / full form escape to the complete form. It is enabled per organization, so many Teams see the full form directly instead. See Getting started.

Withdrawing an asset from a Disclosure you previously made. Downstream Teams stop seeing further detail, but anything they already adopted stays with them — a disclosure cannot be un-seen, only stopped. See Disclosures.

The physical roll Labels are manufactured on, and the unit DICE tracks them in. A Reel has a name (usually the number printed on the spool), an optional description, and an expected composition. Every Label keeps its position on its Reel — an ordering key, printed nowhere on the Label itself, where gaps are normal. Reels sit at the top level of a Team’s inventory or inside a Label Collection. See Labels and Reels.

A contiguous, inclusive span of positions on one Reel, read in reel order — the selection a Bulk Bind consumes. Not a Cut: the Labels stay where they are.

A directional link type used to connect two Threads owned by the same Team (for example “supplied by”). Relationship links are free-form annotations; unlike Part attachment they do not grant access and do not nest.

A file attached to a Thread — documents, images, and other uploads. Resources can be selected into Manifests, Slices, and Disclosures.

The only correction available for a recorded entry such as a Declared Transaction — errata, not erasure. The original entry and its retraction both remain in the transaction log, because the record is shared with future owners.

The set of Teams an Identify searches. Every scanner surface uses this name; the API expresses it as searchTeamIds, defaulting to the Team the request acts in. See Identifiers and Scanning.

A machine identity owned by an Organization. API integrations act as a Service Account, never as a person, and it is the holder of an API key. A Service Account is a member of the Teams it can act in, exactly like a person. See Authentication.

Granting another Team live access to a Thread or Folder while your Team stays the owner. The other Team sees it in their Shared view with the role you granted, and access is revocable — contrast a Transfer, which hands ownership over for good. See Sharing and access.

The user-facing name in DICE for a Transfer: an outbound or inbound package of Threads exchanged between connected Teams, moving through draft, sent, accepted, and processing states, with the recipient able to accept, reject, or request changes.

Deriving new Threads from a source Thread by copying or linking selected Fields, files, and Identifiers, with Fabric recording the lineage. DUST Identifiers represent a physical identity and are never copied into a slice.

A comparison of a fresh scan of a DUST Identifier against the reference captured when it was bound, producing marker coverage measurements and visual evidence layers — and no conclusion. The platform reports what it measured and shows the evidence; it never states whether the Identifier was tampered with, and offers no summary number, rating, or threshold. See Tamper Analysis.

A person’s own conclusion drawn from one Tamper Analysis — the only conclusion the platform stores. Its result is one of Consistent, Expected (normal wear and tear for the identifier’s use case and substrate), Inconsistent, or Unknown, chosen actively with no default. Observations are attributed, immutable, and never replaced: an Analysis retains the whole series. The subject is the Identifier surface, not the Thread or the goods it represents.

The access and collaboration scope within an Organization. Teams own Threads and Folders, and are the unit of sharing, Connections, and request context. The request header is Dust-Ctx-Team-Id; Dust-Ctx-Grp-Id is the legacy spelling, still accepted as a header alias (Dust-Ctx-Team-Id wins when both are sent). That alias is the only surviving “group” name on the wire — request body fields use the current spelling, such as searchTeamIds on identify. A few error codes (GROUP_ID_REQUIRED) also predate the rename. See Conventions.

A reusable definition of the Fields a Thread carries, used when creating Threads individually or importing them in bulk (for example from CSV).

The printed, human-readable Identifier on a Label, typed on a keyboard rather than scanned. It is the input of last resort when a camera cannot read a code — and the one that works on a Verify-only Label.

The core record of the platform: a digital identity for a physical thing or item. A Thread holds Fields, Resources, Identifiers, and Certificates, lives in a Folder, and can be classified, shared, shipped, sliced, and disclosed.

A Thread as it stood at one point on its Fabric chain: its Live state — the current data, when you have live access — plus a fixed version for each time it was transferred, sliced, or had a Disclosure pushed down its chain. See Fabric.

The permanent, attributed record of everything that has happened to a Thread — platform-witnessed events alongside Declared Transactions. It travels with the item to future owners and entries are never deleted, only retracted. See Activity.

Moving Threads from one Team to another over a Connection: the recipient receives new Threads it owns outright, the source Threads are closed out, and Fabric links the two sides. Surfaced in DICE as Shipments; acceptance is the point of no return.

Confirming that a scanned Identifier matches an expected Identifier bound to a specific Thread — a yes/no check against a claimed identity, as opposed to Identify’s open-ended search. See Identifiers.

A DUST Identifier that Verification can confirm against a claimed Thread, but that Identify cannot find, because it has not been indexed. The opposite of identifiable. Deliberate for inventory that should stay out of search until it is activated.

A permanent public URL that redirects to a destination you control — printed on an item as a QR code, and repointed later without reprinting anything. See Vlinks.

Marking an Identifier as no longer the live marking for an item — the DUST was destroyed, re-applied, or the marked material was cut away. Void is a label: the Identifier stays bound to its Thread with its full history, stays visible in the Identifier list (in red, marked Voided), and can still be identified, verified, and unbound. It is reversible, and it does not change the underlying DUST record. Distinct from archiving, which hides an Identifier from the default view, and from a Certificate void, which is permanent. See Identifiers and Scanning.