{
  "tool_id": "art-503-build-dual-control-certification",
  "tool_version": "1.0.0",
  "display_name": "Dual Control Certification Evidence",
  "mcp_name": "build_dual_control_certification",
  "mandate_type": "compliance_control",
  "wave": 78,
  "gpu": false,
  "url": "https://ainumbers.co/chaingraph/art-503-build-dual-control-certification.html",
  "description": "Decides whether a required number of distinct named identities have each filed a signed section 27 approval record over one sealed subject in one required role, and reports every record it could not count and why. This is the first production use of the section 27.3 integer threshold construction, and it is regime agnostic by design: the regime label is free text that is never interpreted, so one surface serves a chief executive plus chief financial officer certification at a threshold of two, a chief executive or chief operating officer certification at a threshold of one, and an audit sign-off, without a separate node per regime. The trap it exists to catch is identity. Counting is by distinct identity, never by record and never by signing key, so one human rotating keys counts once and one human signing twice counts once, and every collapse is reported with the record hashes and the distinct verification methods folded together rather than applied silently. A threshold over fewer than the required number of distinct approvers is unsatisfied and never auto-passes; an absent subject, an unstated threshold, an unrecognised role, a read-only examiner role and an empty record set each resolve to a stated reason rather than a fall-through. An unsigned approval record is not conformant evidence and is rejected with its reason, including where the caller declared it signed and the record carries no proof bound to the named identity. Section 27.8 parity is enforced in the verdict: an agent-filed record counts only when a human principal delegated that exact role in a signed mandate whose validity window contains the caller-supplied as-of date, and an agent that prepared the subject can never approve it. No clock is read anywhere, so a time-boxed record can never resolve to a silent permanent pass. It counts approvals and computes nothing about what was certified: no reserve composition, no eligible-asset determination and no ratio. Stated boundary: this evidences that named humans took responsibility. It carries no claim of regulator acceptance, it does not serve as a filing, and it makes no assertion that the certified numbers are correct.",
  "input_schema_ref": "chaingraph/art-503-build-dual-control-certification.html#manifest",
  "consumes": [],
  "feeds": [],
  "status": "live",
  "conformance_fixtures": true,
  "compute_capability": "server",
  "compute_images": [
    {
      "system": "sha256-source",
      "image_id": "sha256:a57bc96bcfdea16261374e636c9a22668fd91415abc1e441540e6d48306026b0",
      "valid_from": "2026-07-10"
    },
    {
      "system": "risc0",
      "image_id": "sha256:a1a0bc89b5b1febaeda3519f6dbade0fa5ac16beeb143c4e1b01689573567bc6",
      "valid_from": "2026-07-31"
    }
  ],
  "compute_proof_ready": "ready",
  "export_capability": [
    "json"
  ],
  "compute_proof": {
    "type": "ZkVmReceipt",
    "system": "risc0",
    "receiptFormat": "groth16-bn254",
    "imageId": "sha256:a1a0bc89b5b1febaeda3519f6dbade0fa5ac16beeb143c4e1b01689573567bc6",
    "seal": "BnjygZY9Th1F1TcqhhU91MyBYp3ueOU62ge9lwVWRm8X14QemdFdnunfn31lSUcOz3t20qi4dXiLrVX5KizNOQqf4GyKX3PWvjAFOjT1pHZ5Cndg4PWIwVoA4MxlTkZBJpaPKHtlsODmR/QCW9orbcnUT+22Bg62KSbe/57BI2MCQyJQiHs+jY+5KUM/HcCq2V//JKpybGBo27/LVAF0cwkgNF1anlzEX0ZHLg/ILBjLbexuhwPYLtNQPKAxR+XbLPpMVTZqqvgr2Y2Bo42bkYIWs1LnLI5adpaCHc+kP7kjRSd73W9DPcgJw6EZpC9ACuKdngAYiS4gsVnM+3Jqdg==",
    "journal": {
      "chaingraph_version": "0.4.0",
      "kernel_digest": "sha256:a57bc96bcfdea16261374e636c9a22668fd91415abc1e441540e6d48306026b0",
      "output": {
        "agent_parity_findings": [],
        "as_of_date": "2027-02-15",
        "boundary": "This evidences that named humans took responsibility for the subject named here. It carries no claim that a regulator has accepted anything, it does not serve as a filing, and it makes no assertion that the certified numbers are correct. A satisfied threshold means the stated number of distinct identities each filed a signed approval record over this subject in this role, and it means nothing beyond that.",
        "counted_identities": [
          "did:key:zChiefExecSynth",
          "did:key:zChiefFinanceSynth"
        ],
        "counted_records": [
          {
            "actor_type": "human",
            "identity_id": "did:key:zChiefExecSynth",
            "record_hash": "sha256:aa01",
            "record_ref": "sha256:aa01",
            "verification_method": "did:key:zChiefExecSynth#key-1"
          },
          {
            "actor_type": "human",
            "identity_id": "did:key:zChiefFinanceSynth",
            "record_hash": "sha256:aa02",
            "record_ref": "sha256:aa02",
            "verification_method": "did:key:zChiefFinanceSynth#key-1"
          }
        ],
        "distinct_identities_counted": 2,
        "distinctness_basis": "Counting is by distinct identity_id (SPEC.md section 27.3), never by record and never by signing key. One human rotating keys counts once, and one human signing twice counts once. Every collapse is reported rather than applied silently.",
        "duplicate_identities_collapsed": [],
        "foreign_subject_records_rejected": [],
        "no_arithmetic_claim": "This surface counts approvals. It computes nothing about what was certified: no reserve composition, no eligible-asset determination, no outstanding-balance reconciliation and no ratio. Whether the certified figures are right is decided by the people who signed and by whoever examines their work, never here.",
        "note": "Deterministic dual control certification evidence. Single-run and stateless: it holds no records, runs on no schedule, and retains nothing. It decides one thing, whether N distinct named identities each filed a signed approval record over a sealed subject in a required role, and it reports every record it could not count and why. It is regime agnostic: the regime label is free text and no statute is interpreted. It computes nothing about what was certified. It is not a filing and not legal advice.",
        "off_role_records_ignored": [],
        "override_handling": "A section 27.5 override changes which gate policy applies. It does not produce a distinct human approver, so it never satisfies a threshold here. Override records are carried and counted separately and are never folded into the distinct-identity count, which is what stops a time-boxed record resolving to a silent permanent pass.",
        "override_records": [],
        "prepared_by": {
          "actor_type": "unstated",
          "identity_id": null
        },
        "rationale": [
          "Dual control evidence assembled for certification reference CERT-SYNTH-0007 under the caller-supplied regime label Payment stablecoin monthly reserve report certification. The label is free text and nothing in this computation branches on it.",
          "The certification is bound to subject sha256:3333333333333333333333333333333333333333333333333333333333333333, carried as a attested_artifact and not recomputed here.",
          "2 distinct attestor identities each filed a signed approval record over this subject, which meets the required threshold of 2.",
          "2 records supplied: 2 counted, 0 rejected as unsigned, 0 rejected for naming another subject, 0 not relevant to this role, 0 rejection, 0 override.",
          "No identity filed more than one counted approval, so no collapse was required. Counting remains by distinct identity rather than by record.",
          "This evidences that named humans took responsibility for the subject named here. It carries no claim that a regulator has accepted anything, it does not serve as a filing, and it makes no assertion that the certified numbers are correct. A satisfied threshold means the stated number of distinct identities each filed a signed approval record over this subject in this role, and it means nothing beyond that.",
          "This surface counts approvals. It computes nothing about what was certified: no reserve composition, no eligible-asset determination, no outstanding-balance reconciliation and no ratio. Whether the certified figures are right is decided by the people who signed and by whoever examines their work, never here."
        ],
        "records_summary": {
          "agent_finding_count": 0,
          "counted_record_count": 2,
          "distinct_identities_counted": 2,
          "duplicate_identity_count": 0,
          "foreign_subject_rejected_count": 0,
          "off_role_ignored_count": 0,
          "override_record_count": 0,
          "rejection_record_count": 0,
          "supplied_count": 2,
          "unsigned_rejected_count": 0
        },
        "regime": {
          "basis": "regime_label is free text supplied by the caller and is never interpreted. Nothing in this computation branches on it, no statute is matched against it, and no citation is emitted for it. It records which certification the evidence was assembled for so a reader is not left guessing.",
          "certification_ref": "CERT-SYNTH-0007",
          "regime_label": "Payment stablecoin monthly reserve report certification",
          "regime_label_is_free_text": true
        },
        "rejection_records": [],
        "role_policy": {
          "permitted_roles": [
            "preparer",
            "reviewer",
            "approver",
            "attestor",
            "submitter",
            "model_owner",
            "compliance_officer",
            "examiner"
          ],
          "read_only_roles": [
            "examiner"
          ],
          "reason": "The required role is one of the closed section 27.1 roles and can carry approval authority.",
          "required_role": "attestor",
          "role_eligible": true,
          "role_known": true,
          "role_read_only": false
        },
        "subject": {
          "subject_binding_source": "art-502-bind-attested-subject",
          "subject_class": "attested_artifact",
          "subject_hash": "sha256:3333333333333333333333333333333333333333333333333333333333333333",
          "subject_limit": "This subject is a section 27.4 attested artifact. It evidences producer pinning, input binding and content integrity, and it carries no section 18 compute proof and no section 16 or 17 re-execution claim. It never evidences that the arithmetic inside the producer output is correct.",
          "subject_present": true,
          "subject_recomputed_here": false
        },
        "threshold_policy": {
          "dual_control": true,
          "reason": "A threshold of 2 distinct attestor identities is required over this subject.",
          "threshold_construction": "in-toto integer threshold, applied per SPEC.md section 27.3: satisfied when at least N distinct identities have each filed a signed approval record naming this role and this subject.",
          "threshold_n": 2,
          "threshold_valid": true
        },
        "threshold_satisfied": true,
        "threshold_shortfall": 0,
        "unsigned_records_rejected": [],
        "verdict_reason": "2 distinct attestor identities each filed a signed approval record over this subject, which meets the required threshold of 2."
      }
    }
  }
}
