IOU Architecture Documentation¶
Welcome to the comprehensive documentation for the IOU Architecture Framework and the RONL ecosystem.
What is this?¶
What is IOU Architecture?¶
The Information Architecture Framework for IOU integrates semantic web technologies, decision models, and Dutch government standards into a unified system for managing regulatory compliance and spatial planning.
Architecture Overview¶
graph TB
subgraph "IOU Architecture Ecosystem"
A[Municipality Portal<br/>React] -->|OIDC/JWT| B[Keycloak IAM]
B -->|Validated Token| C[Business API<br/>Node.js]
C -->|REST| D[Operaton BPMN<br/>Business Rules]
E[CPSV Editor<br/>React] -->|TTL| F[TriplyDB<br/>Knowledge Graph]
E -->|DMN Files| D
F -->|SPARQL| G[Orchestration Service<br/>Node.js]
G -->|Deploy BPMN+DMN| D
G -->|asset storage| K[PostgreSQL<br/>lde_assets]
H[Linked Data Explorer<br/>React] -->|API Calls| G
H -->|Direct SPARQL| F
I[CPRMV API<br/>Python/FastAPI] -->|XML download| J[BWB / CVDR / CELLAR]
I -->|cprmv-json / RDF| F
I -->|cprmv-json / RDF| H
end
Ecosystem Components¶
βοΈ RONL Business API¶
The core business API layer that provides secure authentication and process orchestration for Dutch government services.
Live App: mijn.open-regels.nl
ποΈ Norm Editor¶
Vue/Quasar application for creating FLINT interpretations of legal sources: load a normative text, annotate fragments, and build Fact, Act, and Claim-duty frames that export to RDF in TriplyDB. Backed by NLP, unwrap, and wrap-up services.
βοΈ CPSV Editor¶
React-based application for creating CPSV-AP 3.2.0 compliant RDF/Turtle files for Dutch government services.
Live App: cpsv-editor.open-regels.nl
π Linked Data Explorer¶
Web application for SPARQL queries and BPMN & DMN orchestration with TriplyDB integration.
Live App: linkeddata.open-regels.nl
π CPRMV API¶
Python/FastAPI service that fetches individual rules from Dutch and European legal publications on the fly, transforming them to CPRMV-structured RDF. Implements the Core Public Rule Management Vocabulary standard and hosts the CPRMV specification.
Live App: cprmv.open-regels.nl/docs
Technology Stack¶
The IOU Architecture ecosystem is - apart from TriplyDB and eDOCS - built entirely on open source technologies:
| Component | Technology | License |
|---|---|---|
| IAM | Keycloak | Apache 2.0 |
| BPMN Engine | Operaton | Apache 2.0 |
| Backend | Node.js + Express | MIT |
| Frontend | React | MIT |
| Database | PostgreSQL | PostgreSQL License |
| Cache | Redis | BSD 3-Clause |
| Reverse Proxy | Caddy | Apache 2.0 |
| Knowledge Graph | TriplyDB | - |
| Document Mngmnt | eDOCS | - |
| Rule API | Python / FastAPI | EUPL-1.2 |
Standards Compliance¶
- CPSV-AP 3.2.0 - EU Public Service Vocabulary
- CPRMV - Core Public Rule Management Vocabulary
- RONL - Dutch Rules Vocabulary
- BIO - Baseline Informatiebeveiliging Overheid
- NEN 7510 - Healthcare information security
- AVG/GDPR - Data protection
What is the state of it?¶
Documentation Status¶
Loading documentation statusβ¦
π What's New¶
-
βοΈ RONL Business API β v2026.09.12 Β· September 2026
The API describes itself, and one rule decides every tenant
The backend now publishes an OpenAPI 3.1 description at
/v1/openapi.jsonβ 113 of its 131 operations, each checked against a running service, with only the machine-to-machine group still to come β and a test fails whenever a served route is neither described nor listed as pending. Browse it on the new API Specification page. Tenant access now has a single source of truth: every process and task check reads the case's own organisation label, refuses when there is none, and answers one code,403 TENANT_MISMATCH. Staff can no longer start another organisation's process, a citizen's case goes to the organisation that runs it and stays readable to them, and a task completion can no longer relabel a case. On the supply chain, every release now carries an SBOM, dependencies are audited daily on both branches, and an unused Keycloak adapter that pulled 48 packages into production is gone. Local development is rewritten from the code, including how the Operaton engine starts and why a bash shell is required. -
ποΈ Norm Editor β v2026.09.1 Β· September 2026
A choice of NLP model, and a test suite to go with it
Role detection is no longer fixed to one model at deploy time:
nlp-apicarries a registry of selectable models and the Act frame form gained a dropdown to pick one, with the response echoing the model actually used so a caller can tell a fallback from a hit. Model files moved out of the service image onto mounted storage, so adding one no longer means rebuilding. July filled the other gap: automated tests across all five services and a GitLab CI pipeline that blocks the image build when they fail β this component had none before. -
βοΈ CPSV Editor β v2026.09.7 Β· September 2026
What ships is what was tested, and each release keeps its bill of materials
The production bundle is now built on the runner, from the tree
npm ciinstalled and on the Node the tests ran on, and uploaded withskip_app_buildβ until now Oryx rebuilt it inside a floating container, so the code that passed the tests and the code that shipped were different builds. Node is one exact version, 24.20.0 from.nvmrc, and production moved up from 22.22.0 (Deployment). Every release now commits a CycloneDX SBOM of its production dependencies, a daily audit reads the lockfiles of bothaccandmain, and npm itself observes the 14-day cooldown Renovate already kept. Renovate never offers a major's X.0.0, ubuntu 26.04 is deferred on record, a lockfile out of step withpackage.jsonfails under its own name, and the build check is now required onacc. The editor itself is unchanged; the suite still stands at 763 tests, all passing. -
π Linked Data Explorer β v2026.09.8 Β· September 2026
A promotion deploys in order, and every release carries its own SBOM
A push to
mainused to start three production deploys at once, and on the v2026.09.6 promotion the ROPA site finished before the backend had even begun building. One promotion workflow now decides what changed, deploys the backend first and releases the two sites only once it has succeeded; its path rules live in a tested script, and a promotion pull request still previews the real production site, by decision. Every deploy check now runs instead of the first failure hiding the rest, andbuild-info.jsonis read at start-up, closing a false pass in the very gate that proves a new build is serving. Each release now commits a CycloneDX SBOM, dependencies are audited daily on bothaccandmain, a lockfile that disagrees withpackage.jsonfails under its own name, and Renovate never offers a major's X.0.0. In the Modeler, both Thuisbatterij processes gain swimlanes and Dutch names, and "Aanvullende gegevens opvragen" finally has a form that can be deployed. The suites stand at 3083 tests, all passing. -
π CPRMV API β v0.4.1 Β· June 2026
CPRMV 0.4.1 conformance & reference resolution
RuleSets are now FRBR Works (
frbroo:F1_Work);/refauto-detects Juriconnect, ELI (to EU CELLAR), and CPRMV-API references; new/cellar-by-celexand/cellar-by-eliredirects;unformatworks across all output formats; and the API now exposes a basic MCP server at/mcp.
ποΈ Slide decks¶
Four topics also exist as slide decks. Each has a page showing every slide with its text, next to the prose it summarises, and the PDF to download.
| Deck | Where | Slides | What it covers | As of | |
|---|---|---|---|---|---|
| IOU Architecture | Site-wide | 25 | The whole ecosystem, from quoted legal text to the decision the citizen sees β the four boards and the public knowledge base, then how it is built and safeguarded. Slides in Dutch | 30 Aug 2026 | 1.0 MB |
| DMN to Linked Data Workflow | CPSV Editor Β· User Guide | 9 | From a legal body's DMN export to a tested decision service published as linked data β Amsterdam, SZW and Den Haag β and three questions for a standardisation body | 18 Sep 2026 | 261 KB |
| DSO Viewer APIs | Linked Data Explorer Β· Features | 13 | How the DSO Viewer talks to the Digitaal Stelsel Omgevingswet β the proxy, the six upstream APIs, what each tab calls, and how an activity's dossier is assembled | 24 Sep 2026 | 184 KB |
| CI Posture Across Repos | Contributing | 5 | The four CI controls on the CPSV Editor and the Linked Data Explorer, and the delivery decision they lead to | 11 Sep 2026 | 127 KB |
A deck is a snapshot of its date, and each page states what it was checked against.
How do I work on it?¶
Development Workflow¶
- Design β for features where the UX is substantial, work starts in Claude Design; small changes skip straight to implementation.
- Handoff β a finished design leaves as a briefing package for the next stage, not as code.
- Implementation β happens in Claude Code, following red/green TDD: a failing test first, then the minimum code needed to pass it.
- Release β each of the application repositories cuts its own release with a versioning command tailored to its changelog.
- Documentation β once a component ships, these docs are brought back into sync with it.
Not part of the core team? Start from the Contributing Guide instead.
Contributing¶
We welcome contributions! See the Contributing Guide for details.
Quick Links¶
| Resource | Link |
|---|---|
| CPSV Editor | cpsv-editor.open-regels.nl |
| Linked Data Explorer | linkeddata.open-regels.nl |
| Backend API | backend.linkeddata.open-regels.nl |
| Keycloak IAM | keycloak.open-regels.nl |
| Custom Business API | api.open-regels.nl |
| Operaton | operaton.open-regels.nl |
| CPRMV API | cprmv.open-regels.nl/docs |
Documentation Version: 1.0
Last Updated: February 2026
License: EUPL v1.2