{
  "tool_id": "art-515-build-allocation-decision-receipt",
  "kernel_id": "art-515-build-allocation-decision-receipt",
  "display_name": "Build Allocation Decision Receipt",
  "tool_version": "1.0.0",
  "mandate_type": "attestation_mandate",
  "purpose": "Re-derives whether an allocation produced by an optimizer is explained by the objective and inputs that were true when it was made: the eligibility schedule snapshot, the inventory snapshot offered, the haircut table version, and the declared objective. Portable to any optimizer, not collateral only, so the same input shape covers a liquidity sweep, a treasury cash placement, a payment-routing choice, or an order allocation. Re-derives ONE candidate allocation for a declared objective (cheapest_to_deliver, preserve_hqla, or minimise_movements) using a fixed, published greedy rule, and compares it to the allocation the caller says was actually chosen: a reproducibility verdict, the delta versus the re-derived allocation in cost and in eligibility terms, and the binding constraint explaining each difference. A caller-named objective outside the three known ones is recorded but not solved, since this kernel has no fixed re-derivation rule for it. ADR_DIVERGENT is not a finding of error: a divergence means the chosen allocation is not explained by the declared objective and inputs, which is routinely legitimate (a trader override, an undeclared constraint, a stale snapshot); no output here characterises intent. This is not a competing optimizer and never claims the re-derived allocation is better than the one chosen. Eligibility, inventory, haircuts and the objective are every one of them a caller input, transcribed from the snapshot in force when the allocation was made; this kernel ships no eligibility table, no inventory feed and no haircut table of its own, and performs no lookups of any kind (zero-egress). Distinct from art-370-supervisory-scenario-replay, which replays the Fed's published macro scenario paths against caller loss/PPNR functions (a scenario replay over regulator-published inputs, not a decision re-derivation), and from art-236-build-ai-decision-log-record, which builds an EU AI Act Art 12(2) decision-log record (metadata about a decision, with no reproducibility verdict and no optimal-allocation computation). Reuses 505-tokenized-collateral-eligibility-checker for eligibility of each candidate and art-444-collateral-haircut-engine for the haircut applied; consumes their outcome as a caller-declared input and edits neither.",
  "control_description": "Re-derives whether an allocation produced by an optimizer is explained by the objective and inputs that were true when it was made: the eligibility schedule snapshot, the inventory snapshot offered, the haircut table version, and the declared objective. Portable to any optimizer, not collateral only, so the same input shape covers a liquidity sweep, a treasury cash placement, a payment-routing choice, or an order allocation. Re-derives ONE candidate allocation for a declared objective (cheapest_to_deliver, preserve_hqla, or minimise_movements) using a fixed, published greedy rule, and compares it to the allocation the caller says was actually chosen: a reproducibility verdict, the delta versus the re-derived allocation in cost and in eligibility terms, and the binding constraint explaining each difference. A caller-named objective outside the three known ones is recorded but not solved, since this kernel has no fixed re-derivation rule for it. ADR_DIVERGENT is not a finding of error: a divergence means the chosen allocation is not explained by the declared objective and inputs, which is routinely legitimate (a trader override, an undeclared constraint, a stale snapshot); no output here characterises intent. This is not a competing optimizer and never claims the re-derived allocation is better than the one chosen. Eligibility, inventory, haircuts and the objective are every one of them a caller input, transcribed from the snapshot in force when the allocation was made; this kernel ships no eligibility table, no inventory feed and no haircut table of its own, and performs no lookups of any kind (zero-egress). Distinct from art-370-supervisory-scenario-replay, which replays the Fed's published macro scenario paths against caller loss/PPNR functions (a scenario replay over regulator-published inputs, not a decision re-derivation), and from art-236-build-ai-decision-log-record, which builds an EU AI Act Art 12(2) decision-log record (metadata about a decision, with no reproducibility verdict and no optimal-allocation computation). Reuses 505-tokenized-collateral-eligibility-checker for eligibility of each candidate and art-444-collateral-haircut-engine for the haircut applied; consumes their outcome as a caller-declared input and edits neither.",
  "declared_inputs": [],
  "declared_outputs": [],
  "kernel_digest": "sha256:cfa8312a00a78e19af8654199d3cfbc6224cc85e41ade3919d9eca0e60f46b40",
  "trust_label": "independently verified: zkVM execution proof (risc0/groth16-bn254)",
  "data_vintage": "2026-08-01",
  "last_validated": "2026-08-01",
  "conformance_fixtures_vendored": true,
  "compute_proof_ready": "ready",
  "wave": 80,
  "source_url": "https://ainumbers.co/chaingraph/art-515-build-allocation-decision-receipt.html",
  "generated_at": "2026-08-15T11:12:17.704Z"
}
