{
  "tool_id": "art-497-validator-change-control-receipt",
  "tool_version": "1.0.0",
  "display_name": "Validator Change-Control Receipt",
  "mcp_name": "build_validator_change_control_receipt",
  "mandate_type": "compliance_control",
  "wave": 78,
  "gpu": false,
  "url": "https://ainumbers.co/chaingraph/art-497-validator-change-control-receipt.html",
  "description": "Turns one permissioned-validator event on an Avalanche Evergreen L1 -- a validator add, remove, or weight change -- into change-control evidence in the shape the SOX/ICFR control family already uses: the authorization chain of named identities, the weight delta and its share-of-total effect against a caller-supplied total network stake, and a quorum verdict comparing the caller's declared approval-quorum policy against what the caller states was achieved, plus a structural exceptions list (nonzero prior weight on an add, nonzero posterior weight on a remove, no delta on a weight change, an unauthorized change, an achieved-quorum count exceeding the number of named authorizers). No baked-in quorum threshold: quorum_required is the caller's own policy for that Evergreen L1, exactly as art-445/art-494 refuse to bake in their own thresholds. No chain observation, no P-Chain query, no RPC: the event is transcribed by the caller. Not X: use art-503 for a §27 dual-control certification that counts distinct approvers against a statutory-or-policy threshold across a subject; this node evidences one validator-set change event, not an approval-count certification. compliance_control. Zero PII: validator_ref and every authorizing identity are opaque references.",
  "input_schema_ref": "chaingraph/art-497-validator-change-control-receipt.html#manifest",
  "consumes": [],
  "feeds": [],
  "status": "live",
  "conformance_fixtures": true,
  "compute_capability": "server",
  "compute_images": [
    {
      "system": "sha256-source",
      "image_id": "sha256:54af35dcf6e35f959764ddf334f63dafbdf57047a8f810e47e3f980586a861b3",
      "valid_from": "2026-07-10"
    },
    {
      "system": "risc0",
      "image_id": "sha256:a1a0bc89b5b1febaeda3519f6dbade0fa5ac16beeb143c4e1b01689573567bc6",
      "valid_from": "2026-07-31"
    }
  ],
  "compute_proof_ready": "ready",
  "export_capability": [
    "json"
  ],
  "compute_proof": {
    "type": "ZkVmReceipt",
    "system": "risc0",
    "receiptFormat": "groth16-bn254",
    "imageId": "sha256:a1a0bc89b5b1febaeda3519f6dbade0fa5ac16beeb143c4e1b01689573567bc6",
    "seal": "JtTGWPiAGo97JS9hG24pWZtYXLzjRGx17R8PG1v8TqMPvrzfIa9ONyRdM0FYj0qb4n8jwCdMUf2PDebczY/1ISCr8Ca1ow3mJCJa/DvTV+RVr4RY7oK7UGfYKLMeXodPLXfI2U/QZioJvirwM6Dpxi6gl9FQ5H6foLcdSKoS8ZoDUWhDWq4tIqkkTH8mpug2Uk4arShkNK4T1qxGcX1loRNARlghEN26AC4qCRl86UuambFvR+9RO+SE4zImtJTNIKNu4siG4H0O4j/vitbfR3v5vx90piaDhTHQBmD7JhQCG5o9ogFOFyw1EIZA9bX/M1XE8f0I0s5Gp0CwA+SL0g==",
    "journal": {
      "chaingraph_version": "0.4.0",
      "kernel_digest": "sha256:54af35dcf6e35f959764ddf334f63dafbdf57047a8f810e47e3f980586a861b3",
      "output": {
        "as_of": "2026-07-30",
        "authorization_chain": [
          "ID-A",
          "ID-B",
          "ID-C"
        ],
        "authorized": true,
        "change_type": "weight_change",
        "change_type_valid": true,
        "effective_epoch": "epoch-4821",
        "exceptions": [],
        "posterior_weight": 1500,
        "prior_weight": 1200,
        "quorum_achieved": 3,
        "quorum_required": 3,
        "quorum_status": "MET",
        "share_of_total_pct": 0.6,
        "total_stake_weight": 50000,
        "validator_ref": "VAL-07",
        "weight_delta": 300
      }
    }
  }
}
