{
  "tool_id": "art-523-identity-proofing-assurance-level",
  "tool_version": "1.0.0",
  "display_name": "Identity-Proofing Assurance Level Evaluator",
  "mcp_name": "compute_identity_proofing_assurance_level",
  "mandate_type": "regulatory_reporting",
  "wave": 72,
  "gpu": false,
  "url": "https://ainumbers.co/chaingraph/art-523-identity-proofing-assurance-level.html",
  "description": "Rates whether a DECLARED identity-evidence set reaches a DECLARED target level of a caller-supplied, versioned assurance-level framework (the art-444 policy-input pattern) -- never a hardcoded framework such as NIST 800-63-3 or eIDAS. The level definition supplies levels ordered lowest-to-highest rigor, each with criteria naming a required evidence type and a numeric min_strength on a caller-normalized 0-100 scale; the kernel never interprets a framework's own named tiers. A criterion the definition cannot express (no required_evidence_type or no min_strength) is flagged IAL_DEFINITION_INSUFFICIENT, distinct from IAL_SHORTFALL (evidence present but not meeting a well-formed criterion) -- the two are never conflated. When the target level is not met, achieved level falls back to the highest fully-met level below it. This node rates an evidence set against a declared policy; it does NOT assert that a person is who they claim to be, and no output or copy implies verification of a natural person. No identity attributes are ever computed over -- evidence items are types, strengths and verification methods, with an optional opaque attribute reference (caller-supplied, no commitment scheme claimed by this node) carried through unread, never a plaintext value. No approver identity, signature, approval field or role -- manual review/EDD escalation is a separate signed §27 human_accountability_record, not minted by this kernel. This is the assurance-LEVEL evaluator specifically, distinct from any private-check-receipt evidencing scheme or a re-verification-cadence evaluator (neither built in this exercise). Not 490-eudi-kyc-flow-designer (an eIDAS/LoA-specific flow-design tool) -- this is framework-agnostic by construction and takes any structurally-expressible level definition as a policy input, with no dependency on any named jurisdiction or procurement.",
  "input_schema_ref": "chaingraph/art-523-identity-proofing-assurance-level.html#manifest",
  "deadline": null,
  "deadline_note": "An ongoing identity-assurance evidencing capability, jurisdiction-neutral by design -- every regime fact is a caller-supplied policy input, so there is no filing deadline of its own.",
  "consumes": [],
  "feeds": [],
  "status": "live",
  "conformance_fixtures": true,
  "compute_capability": "server",
  "compute_images": [
    {
      "system": "sha256-source",
      "image_id": "sha256:f691517dd02006a5787bea91055d22c567fb6049e1f3d15c3bb2a474032cd335",
      "valid_from": "2026-07-10"
    },
    {
      "system": "risc0",
      "image_id": "sha256:a1a0bc89b5b1febaeda3519f6dbade0fa5ac16beeb143c4e1b01689573567bc6",
      "valid_from": "2026-08-01"
    }
  ],
  "export_capability": [
    "json"
  ],
  "compute_proof_ready": "ready",
  "compute_proof": {
    "type": "ZkVmReceipt",
    "system": "risc0",
    "receiptFormat": "groth16-bn254",
    "imageId": "sha256:a1a0bc89b5b1febaeda3519f6dbade0fa5ac16beeb143c4e1b01689573567bc6",
    "seal": "EChOWFKr39lwrZ8zEWd2aolUizs6sdRVHlGBlEY1xy8GXoiW4a4QGEqr54RKvuHW2aftEDCROnVboOzjx0gpwCMgrlPdC2lOSqzeiS1JowpOxrv7TThlmg5JzM6RLip3Ac5sczD0Pxl+IM+6DmSYew2kHfeTvtDl98TN/iQ0wZYkl06v3AolQYz0Fe8e1cl20+UFzbUXlANJSR65VfOAZh3JuAxWUrH3PbAtorJ/tbuy+onJDCMp8+WHMatav6CwIvrdLTqKhsUvTOcR07kxD60onHR7T32nlji07ZHGTisq3cqVbtylDVSR1FVCSCzaGzmTy9HUot8HM4dthNe2ZA==",
    "journal": {
      "chaingraph_version": "0.4.0",
      "kernel_digest": "sha256:f691517dd02006a5787bea91055d22c567fb6049e1f3d15c3bb2a474032cd335",
      "output": {
        "achieved_level": "tier-2",
        "as_of": "2026-08-01",
        "criteria_evaluated": 2,
        "criteria_met": 2,
        "criteria_shortfall_count": 0,
        "criteria_undecidable_count": 0,
        "declared_target_level": "tier-2",
        "evidence_item_count": 2,
        "framework_id": "vendor-framework-A-tiers",
        "framework_version": "2026-01",
        "levels_defined": 3,
        "note": "Rates a DECLARED evidence set against a caller-supplied, versioned assurance-level framework -- never a hardcoded one. Does not assert a person is who they claim to be: this evidences that a declared evidence set was measured against a declared policy, not the truth of the declarations. A criterion the definition cannot express (no required_evidence_type or no min_strength) is reported as IAL_DEFINITION_INSUFFICIENT, distinct from IAL_SHORTFALL (evidence present but not meeting a well-formed criterion) -- the two are never conflated. No identity attributes are ever computed over; evidence items are types, strengths and verification methods, with an optional opaque attribute reference (caller-supplied, no commitment scheme claimed by this node) carried through unread.",
        "shortfall": [],
        "target_level_found": true,
        "target_met": true,
        "undecidable": []
      }
    }
  }
}
