OpenChainGraph Suite · ART-503 · Human Accountability · Dual Control

Dual Control Certification Evidence

A certification that two named officers signed is worth exactly as much as the claim that they were two people. This page decides one thing: whether the required number of distinct named identities each filed a signed approval over one sealed subject in one role. It counts by identity, never by signature and never by key, and it names every record it could not count.

The surface is deliberately regime agnostic. regime_label is free text that nothing here interprets, so the same node evidences a chief executive plus chief financial officer certification at a threshold of two, a chief executive or chief operating officer certification at a threshold of one, and an audit sign-off. There is no enum of statutes on this page and no arithmetic about whatever was certified.

Distinct identities, never keys §27.8 parity enforced in the verdict No clock anywhere
Threshold construction pinned in every artifact this page exports: the OpenChainGraph §27.3 in-toto integer threshold, satisfied when at least N distinct identities have each filed a signed approval record naming the required role and the same subject. · No statute is interpreted on this surface and no citation is emitted.
What this is, and what it is not (§27.7)

This evidences that named humans took responsibility for the subject named here. It carries no claim that a regulator has accepted anything, it does not serve as a filing, and it makes no assertion that the certified numbers are correct. A satisfied threshold means the stated number of distinct identities each signed. It means nothing beyond that.

This surface counts approvals. It computes nothing about what was certified: no reserve composition, no eligible-asset determination, no outstanding-balance reconciliation and no ratio. Whether the certified figures are right is decided by the people who signed and by whoever examines their work.

A threshold over fewer than N distinct approvers is unsatisfied and never auto-passes. An absent subject, an unstated threshold, an unrecognised role, a read-only examiner role and an empty record set each resolve to a stated reason rather than falling through to a default.

An unsigned approval record is not conformant §27 evidence. The signed flag is the caller's declaration, not the evidence; where it disagrees with the proof the record actually carries, the record is rejected and the disagreement is reported.

🔒 All inputs are processed locally in your browser. No data is transmitted. Do not enter real personal data – use synthetic or anonymised inputs only.
⚠ No clock is read anywhere on this page. The as-of date is a value you supply, and it is the only instant this page knows. A §27.5 override never satisfies a threshold here: an override changes which policy applies, it does not produce a distinct human approver.
Certification
Who prepared the subject (optional, §27.8)
Signatory records

The default set is the failure a signature count cannot see. Three signatures, but the first two are one officer who rotated keys, and the third carries no proof at all. Two signatures are one person, and the third is a declaration rather than evidence, so the dual control threshold is not met.

Verdict
Counted identities
Duplicate identities collapsed
Records not counted
Agent parity (§27.8)
Subject
Execution Hash (SHA-256)
Related

Certifies a subject sealed elsewhere: a node output, or an attested artifact bound by the attested artifact subject binder. The safeguarding engagement that consumes the same accountability vocabulary is the CASS 15 safeguarding audit evidence pack. The threshold construction is described at §27.3 of the OpenChainGraph specification, and the agent parity rule at §27.8.