{
  "tool_id": "art-515-build-allocation-decision-receipt",
  "tool_version": "1.0.0",
  "display_name": "Build Allocation Decision Receipt",
  "mcp_name": "build_allocation_decision_receipt",
  "mandate_type": "attestation_mandate",
  "wave": 80,
  "gpu": false,
  "url": "https://ainumbers.co/chaingraph/art-515-build-allocation-decision-receipt.html",
  "description": "Re-derives whether an allocation produced by an optimizer is explained by the objective and inputs that were true when it was made: the eligibility schedule snapshot, the inventory snapshot offered, the haircut table version, and the declared objective. Portable to any optimizer, not collateral only, so the same input shape covers a liquidity sweep, a treasury cash placement, a payment-routing choice, or an order allocation. Re-derives ONE candidate allocation for a declared objective (cheapest_to_deliver, preserve_hqla, or minimise_movements) using a fixed, published greedy rule, and compares it to the allocation the caller says was actually chosen: a reproducibility verdict, the delta versus the re-derived allocation in cost and in eligibility terms, and the binding constraint explaining each difference. A caller-named objective outside the three known ones is recorded but not solved, since this kernel has no fixed re-derivation rule for it. ADR_DIVERGENT is not a finding of error: a divergence means the chosen allocation is not explained by the declared objective and inputs, which is routinely legitimate (a trader override, an undeclared constraint, a stale snapshot); no output here characterises intent. This is not a competing optimizer and never claims the re-derived allocation is better than the one chosen. Eligibility, inventory, haircuts and the objective are every one of them a caller input, transcribed from the snapshot in force when the allocation was made; this kernel ships no eligibility table, no inventory feed and no haircut table of its own, and performs no lookups of any kind (zero-egress). Distinct from art-370-supervisory-scenario-replay, which replays the Fed's published macro scenario paths against caller loss/PPNR functions (a scenario replay over regulator-published inputs, not a decision re-derivation), and from art-236-build-ai-decision-log-record, which builds an EU AI Act Art 12(2) decision-log record (metadata about a decision, with no reproducibility verdict and no optimal-allocation computation). Reuses 505-tokenized-collateral-eligibility-checker for eligibility of each candidate and art-444-collateral-haircut-engine for the haircut applied; consumes their outcome as a caller-declared input and edits neither.",
  "input_schema_ref": "chaingraph/art-515-build-allocation-decision-receipt.html#manifest",
  "consumes": [],
  "feeds": [],
  "status": "live",
  "conformance_fixtures": true,
  "compute_capability": "server",
  "compute_images": [
    {
      "system": "sha256-source",
      "image_id": "sha256:cfa8312a00a78e19af8654199d3cfbc6224cc85e41ade3919d9eca0e60f46b40",
      "valid_from": "2026-07-10"
    },
    {
      "system": "risc0",
      "image_id": "sha256:a1a0bc89b5b1febaeda3519f6dbade0fa5ac16beeb143c4e1b01689573567bc6",
      "valid_from": "2026-08-01"
    }
  ],
  "export_capability": [
    "pdf",
    "xlsx"
  ],
  "compute_proof_ready": "ready",
  "compute_proof": {
    "type": "ZkVmReceipt",
    "system": "risc0",
    "receiptFormat": "groth16-bn254",
    "imageId": "sha256:a1a0bc89b5b1febaeda3519f6dbade0fa5ac16beeb143c4e1b01689573567bc6",
    "seal": "EMLZXPw7FJRQQwVehm5T129y4Gc53TzvyRExpESD4IgY+c9Wq5v9DDY46X7fx/07nmkWEyIfU16ebmakNbyUkRG+i8dumPNOB75wWtSW1Z0ZZIYKJWrczz9mA5LlM9sXL6xlf3lrelH2WisRuZEvEbAz55LcaHjgBZ7DZOKpreIUtSO8t2GhrApWAJUVceqDTBCcOf5EMUmhnIxKpn0dTBkeamziY5FafsKNGX3cwndLq26bAutDWqgw4VhHvy7fDY0T3WAA2UFEcOhnrLpkX3pg5osO4I+8JMBtx3IsMO4RQOQrAtFy3Hp9yo2vOsv5dGXydwLHeQxzpdos5FqtyA==",
    "journal": {
      "chaingraph_version": "0.4.0",
      "kernel_digest": "sha256:cfa8312a00a78e19af8654199d3cfbc6224cc85e41ade3919d9eca0e60f46b40",
      "output": {
        "as_of": "2026-06-30",
        "binding_constraints": [],
        "delta": {
          "cost_chosen": "3200000.00",
          "cost_delta": "0.00",
          "cost_optimal": "3200000.00",
          "eligibility": {
            "ineligible_amount_total": "0.00",
            "ineligible_assets_in_chosen": []
          }
        },
        "eligibility_schedule_ref": "ELIG-2026-06",
        "exceptions": [],
        "fence": "Eligibility, inventory, haircuts and the declared objective are every one of them a caller input, transcribed from the snapshot in force when the allocation was made. This kernel ships no eligibility table, no inventory feed and no haircut table of its own, performs no lookups of any kind (zero-egress by contract), and re-derives against the SAME declared objective and inputs the caller supplied — it is not a competing optimizer and does not claim to find a better allocation.",
        "haircut_table_version": "HC-2026Q2",
        "inventory_ref": "INV-2026-06-30",
        "judgment_required": null,
        "not_proven": [
          {
            "detail": "The eligibility schedule snapshot is a caller input, transcribed from whatever was in force when the allocation was made. This kernel does not verify it against a live eligibility feed and holds no eligibility table of its own.",
            "item": "Eligibility accuracy"
          },
          {
            "detail": "The inventory snapshot (available amounts, movement cost, HQLA flag, haircut) is asserted at the values supplied. No independent valuation or market data is read.",
            "item": "Inventory accuracy"
          },
          {
            "detail": "This kernel re-derives ONE candidate allocation for the declared objective using a fixed, published greedy rule. A divergence from the caller's allocation is not proof the caller's allocation was wrong, and a match is not proof no better allocation exists — only that this re-derivation agrees or disagrees with what was chosen.",
            "item": "Optimality of the caller's allocation"
          },
          {
            "detail": "ADR_DIVERGENT records that the chosen allocation is not explained by the declared objective and inputs. It never characterises why: a trader override, an undeclared constraint and a stale snapshot are all consistent with the same flag.",
            "item": "Intent"
          }
        ],
        "objective": "cheapest_to_deliver",
        "obligation": {
          "amount": "1000000.00",
          "positive": true
        },
        "obligation_ref": "OBL-DEMO-01",
        "rationale": [
          "Objective \"cheapest_to_deliver\" was re-derived against 2 eligible inventory items using this kernel's fixed greedy rule for that objective.",
          "The declared eligibility schedule, inventory snapshot and obligation amount were sufficient to attempt a re-derivation.",
          "The chosen allocation exactly matches this kernel's re-derivation of the declared objective over the declared inputs.",
          "This kernel re-derives one candidate allocation using a fixed, published rule. It is not a competing optimizer and does not claim the re-derived allocation is better than the one chosen."
        ],
        "reproducibility": {
          "chosen_allocation": [
            {
              "amount": "600000.00",
              "asset_id": "A2"
            },
            {
              "amount": "400000.00",
              "asset_id": "A1"
            }
          ],
          "obligation_covered_by_chosen": true,
          "obligation_covered_by_optimal": true,
          "optimal_allocation": [
            {
              "amount": "600000.00",
              "asset_id": "A2"
            },
            {
              "amount": "400000.00",
              "asset_id": "A1"
            }
          ],
          "verdict": "ADR_REPRODUCED"
        },
        "rounding": {
          "decimal_places": 2,
          "mode": "half_up"
        }
      }
    }
  },
  "deadline": null,
  "deadline_note": "No statutory deadline. The eligibility schedule, inventory snapshot, haircut table version and objective are every one of them a caller input, because a bundled version of any of them would be a standing duty that goes silently false when the terms change."
}
