{
  "tool_id": "art-502-bind-attested-subject",
  "kernel_id": "art-502-bind-attested-subject",
  "display_name": "Attested Artifact Subject Binder",
  "tool_version": "1.0.0",
  "mandate_type": "compliance_control",
  "purpose": "Computes the SPEC.md section 27.4 attested-artifact subject identifier for the sealed output of a pinned non-OCG producer: a spreadsheet, a reconciliation export, a report builder's PDF, anything with a content-addressed manifest but no kernel, no node and no chain. The identifier is sha256 over the JCS canonicalisation of exactly three members, tool_ref plus inputs_digest plus artifact, on the single canonical hash path; there is no fourth member and no wall clock, run identifier, host or session state enters it, so a verifier that never executed the producer recomputes the same value offline from the echoed preimage. tool_ref.manifest_digest is the chainless analogue of the section 17 kernel_digest and is what makes the producer tamper-evident rather than merely its output; its absence is reported, never assumed. Digest strings are hashed verbatim as declared and are never rewritten, so a malformed digest is named rather than silently normalised. Stated limit, normative: an attested-artifact subject carries no section 18 compute proof and no section 16 or 17 re-execution claim, it never evidences that the producer's arithmetic is correct, and the artifact omits replay_verified entirely rather than setting it false because no replay was attempted. This node identifies a subject so that separately signed section 27 approval records can name it; it signs nothing itself and asserts no regulator acceptance or filing sufficiency.",
  "control_description": "Computes the SPEC.md section 27.4 attested-artifact subject identifier for the sealed output of a pinned non-OCG producer: a spreadsheet, a reconciliation export, a report builder's PDF, anything with a content-addressed manifest but no kernel, no node and no chain. The identifier is sha256 over the JCS canonicalisation of exactly three members, tool_ref plus inputs_digest plus artifact, on the single canonical hash path; there is no fourth member and no wall clock, run identifier, host or session state enters it, so a verifier that never executed the producer recomputes the same value offline from the echoed preimage. tool_ref.manifest_digest is the chainless analogue of the section 17 kernel_digest and is what makes the producer tamper-evident rather than merely its output; its absence is reported, never assumed. Digest strings are hashed verbatim as declared and are never rewritten, so a malformed digest is named rather than silently normalised. Stated limit, normative: an attested-artifact subject carries no section 18 compute proof and no section 16 or 17 re-execution claim, it never evidences that the producer's arithmetic is correct, and the artifact omits replay_verified entirely rather than setting it false because no replay was attempted. This node identifies a subject so that separately signed section 27 approval records can name it; it signs nothing itself and asserts no regulator acceptance or filing sufficiency.",
  "declared_inputs": [],
  "declared_outputs": [],
  "kernel_digest": "sha256:8680e25172057485acdc9fae8651fab076d8ebe76824abf35bf75b8f186568fa",
  "trust_label": "independently verified: zkVM execution proof (risc0/groth16-bn254)",
  "data_vintage": "2026-07-31",
  "last_validated": "2026-07-31",
  "conformance_fixtures_vendored": true,
  "compute_proof_ready": "ready",
  "wave": 77,
  "source_url": "https://ainumbers.co/chaingraph/art-502-bind-attested-subject.html",
  "generated_at": "2026-08-15T11:12:17.704Z"
}
