# SPDX-License-Identifier: Apache-2.0
# Copyright (C) 2026 Bartek Kus
# Relicensed Apache-2.0 from OAP's AGPL-3.0 source by the sole copyright
# holder (see NOTICE). OAP source spec: 121-claim-provenance-enforcement
# FR-015 input (a); the tenant-tail owner is spec 002-provenance-verify-core.
#
# Built-in core allowlist for the spec 121 provenance validator.
#
# Tokens here are CONSIDERED IN-SCOPE FOR EVERY PROJECT and will not be
# flagged as external entities by the plausibility heuristic. The list is
# intentionally generous (the operator's directive: "false positives are
# cheap; missed external entities are catastrophic"). Add common English
# stopwords, jurisdiction nouns for Government of Alberta projects (the
# initial deployment context), and widely-used infrastructure / vendor
# names that any GoA project legitimately interacts with.
#
# Format: one lowercase token per line. Lines starting with `#` and blank
# lines are ignored. The file is embedded at compile time via include_str!
# so an edit triggers crate recompilation.

# --- English articles & common stopwords (carry no entity signal) ---
a
an
the
and
or
but
not
of
in
on
at
to
from
by
for
with
without
within
about
against
into
onto
under
over
between
through
across
around
above
below
upon
per
via
as
is
are
was
were
be
been
being
have
has
had
do
does
did
will
would
shall
should
may
might
must
can
could
this
that
these
those
their
there
here
where
when
which
what
who
whom
whose
why
how
its
it
they
them
he
she
his
her
him
i
we
us
our
you
your
my
me
mine
yours
ours
theirs
hers

# --- common verbs in requirement text ---
add
allow
ask
apply
approve
assess
build
call
change
check
choose
close
come
configure
confirm
contain
continue
create
define
delete
deliver
deploy
describe
design
display
do
edit
emit
enable
ensure
enter
execute
expand
extend
extract
fail
fetch
find
follow
gain
get
give
go
handle
help
hold
identify
include
inform
initiate
invoke
issue
keep
know
learn
leave
let
list
log
make
manage
match
move
need
note
notify
observe
open
operate
output
pass
perform
permit
post
prepare
present
print
process
produce
provide
publish
pull
push
put
query
raise
read
receive
record
register
reject
release
remove
render
report
request
require
reset
resolve
respond
return
review
run
save
search
see
select
send
serve
set
show
sign
specify
start
stop
store
submit
support
surface
take
test
track
transmit
try
turn
update
upload
use
verify
wait
want
work
write

# --- common nouns / cross-project domain words ---
account
action
activity
admin
administrator
alert
analysis
api
app
application
approval
artifact
attachment
audit
auth
authentication
authorization
backend
banner
bind
binding
boundary
budget
build
bundle
button
case
category
change
charter
check
checkbox
checkpoint
client
code
column
command
comment
component
config
configuration
connection
constraint
content
context
contract
count
counter
coverage
criteria
data
database
date
day
dashboard
default
definition
delivery
description
detail
diff
directory
document
domain
download
draft
edit
element
email
entity
entry
environment
error
event
example
exception
execution
exit
feature
field
file
filter
flag
flow
folder
form
format
frame
frontend
gate
graph
group
guide
header
help
history
home
host
icon
id
identifier
identity
import
index
info
information
input
inspection
instance
integration
interface
issue
item
job
key
keyword
label
layer
layout
level
library
line
link
list
location
log
login
logout
machine
manifest
map
member
membership
menu
message
metadata
method
mode
model
module
month
name
namespace
network
node
note
notification
number
object
office
operation
option
order
output
overview
owner
package
page
panel
parameter
password
path
pattern
permission
phase
plan
platform
plugin
point
policy
portal
position
post
preference
process
product
profile
project
prompt
property
protocol
provider
query
queue
range
rate
record
reference
region
registry
release
report
request
requirement
resource
response
result
review
role
route
row
rule
runtime
schema
schedule
scope
screen
script
search
section
selection
service
session
setting
share
sidebar
signal
site
size
slot
source
spec
specification
stage
state
status
step
storage
stream
string
structure
subject
subsection
summary
support
surface
system
table
tag
target
task
team
template
test
text
ticket
time
timestamp
title
toggle
token
tool
topic
tour
trace
transition
type
unit
update
upload
url
user
username
value
variable
vendor
version
view
visitor
warning
week
window
work
workflow
workspace
year

# --- Government of Alberta jurisdiction nouns (initial deployment) ---
alberta
canada
canadian
federal
provincial
goa
gov
government
ministry
ministries
minister
ministerial
municipality
municipal
public
crown
treasury
board
council
legislative
legislature
lieutenant
governor
premier
mla
constituency
caucus
program
project
service
services
department
agency
agencies

# --- common public-sector + grant program tokens ---
application
applicant
applying
applications
applied
applicants
funding
fund
funded
funder
grant
grants
recipient
recipients
beneficiary
client
constituent
participant
participants
shelter
shelters
society
societies
nonprofit
charity
charitable
registered
registry
registration
register
registrar
status
member
members
membership
ngo
governance
governed
governing
compliance
compliant
regulatory
regulator
regulation
regulations
regulated
emergency
emergent
crisis
violence
victim
domestic
family
intervention
support
counsel
counselling
counsellor
counsellors
case
caseworker
caseload

# --- ubiquitous web / cloud infrastructure (every project legitimately uses) ---
microsoft
azure
github
gitlab
google
aws
amazon
linux
windows
macos
chrome
firefox
safari
edge
docker
kubernetes
helm
terraform
postgres
postgresql
mysql
sqlite
redis
oauth
oidc
saml
jwt
ssl
tls
https
http
rest
graphql
json
yaml
markdown
csv
xml
html
css
javascript
typescript
python
rust
go
node
npm
pnpm
bun
cargo
git
gitignore
licence
license
readme
makefile
package
lock
workspace
build
dist
target
src
test
tests
spec
specs
docs
doc
data
config
configuration
settings
schema
schemas
api
apis
sdk
sdks
cli
ui
ux
gui

# --- common day/month/cardinal tokens (sentence-start capitalisation) ---
january
february
march
april
may
june
july
august
september
october
november
december
monday
tuesday
wednesday
thursday
friday
saturday
sunday
one
two
three
four
five
six
seven
eight
nine
ten
first
second
third
fourth
fifth

# --- generic vocab carrying no entity signal even when capitalised ---
yes
no
true
false
ok
okay
all
some
any
none
other
others
more
less
most
least
new
old
existing
current
previous
next
final
draft
approved
pending
complete
incomplete
required
optional
mandatory
recommended
suggested
allowed
prohibited
disabled
enabled
active
inactive
default
custom
public
private
internal
external
local
remote
upstream
downstream
read
write
readonly
writeonly
synchronous
asynchronous
parallel
sequential
ordered
unordered
sorted
unsorted
filtered
unfiltered
deterministic
nondeterministic
