{
  "tool_id": "art-497-validator-change-control-receipt",
  "kernel_id": "art-497-validator-change-control-receipt",
  "display_name": "Validator Change-Control Receipt",
  "tool_version": "1.0.0",
  "mandate_type": "compliance_control",
  "purpose": "Turns one permissioned-validator event on an Avalanche Evergreen L1 -- a validator add, remove, or weight change -- into change-control evidence in the shape the SOX/ICFR control family already uses: the authorization chain of named identities, the weight delta and its share-of-total effect against a caller-supplied total network stake, and a quorum verdict comparing the caller's declared approval-quorum policy against what the caller states was achieved, plus a structural exceptions list (nonzero prior weight on an add, nonzero posterior weight on a remove, no delta on a weight change, an unauthorized change, an achieved-quorum count exceeding the number of named authorizers). No baked-in quorum threshold: quorum_required is the caller's own policy for that Evergreen L1, exactly as art-445/art-494 refuse to bake in their own thresholds. No chain observation, no P-Chain query, no RPC: the event is transcribed by the caller. Not X: use art-503 for a §27 dual-control certification that counts distinct approvers against a statutory-or-policy threshold across a subject; this node evidences one validator-set change event, not an approval-count certification. compliance_control. Zero PII: validator_ref and every authorizing identity are opaque references.",
  "control_description": "Turns one permissioned-validator event on an Avalanche Evergreen L1 -- a validator add, remove, or weight change -- into change-control evidence in the shape the SOX/ICFR control family already uses: the authorization chain of named identities, the weight delta and its share-of-total effect against a caller-supplied total network stake, and a quorum verdict comparing the caller's declared approval-quorum policy against what the caller states was achieved, plus a structural exceptions list (nonzero prior weight on an add, nonzero posterior weight on a remove, no delta on a weight change, an unauthorized change, an achieved-quorum count exceeding the number of named authorizers). No baked-in quorum threshold: quorum_required is the caller's own policy for that Evergreen L1, exactly as art-445/art-494 refuse to bake in their own thresholds. No chain observation, no P-Chain query, no RPC: the event is transcribed by the caller. Not X: use art-503 for a §27 dual-control certification that counts distinct approvers against a statutory-or-policy threshold across a subject; this node evidences one validator-set change event, not an approval-count certification. compliance_control. Zero PII: validator_ref and every authorizing identity are opaque references.",
  "declared_inputs": [],
  "declared_outputs": [],
  "kernel_digest": "sha256:54af35dcf6e35f959764ddf334f63dafbdf57047a8f810e47e3f980586a861b3",
  "trust_label": "independently verified -- zkVM execution proof (risc0/groth16-bn254)",
  "data_vintage": "2026-07-31",
  "last_validated": "2026-07-31",
  "conformance_fixtures_vendored": true,
  "compute_proof_ready": "ready",
  "wave": 78,
  "source_url": "https://ainumbers.co/chaingraph/art-497-validator-change-control-receipt.html",
  "generated_at": "2026-08-01T11:39:58.012Z"
}
