{
  "tool_id": "art-523-identity-proofing-assurance-level",
  "kernel_id": "art-523-identity-proofing-assurance-level",
  "display_name": "Identity-Proofing Assurance Level Evaluator",
  "tool_version": "1.0.0",
  "mandate_type": "regulatory_reporting",
  "purpose": "Rates whether a DECLARED identity-evidence set reaches a DECLARED target level of a caller-supplied, versioned assurance-level framework (the art-444 policy-input pattern) -- never a hardcoded framework such as NIST 800-63-3 or eIDAS. The level definition supplies levels ordered lowest-to-highest rigor, each with criteria naming a required evidence type and a numeric min_strength on a caller-normalized 0-100 scale; the kernel never interprets a framework's own named tiers. A criterion the definition cannot express (no required_evidence_type or no min_strength) is flagged IAL_DEFINITION_INSUFFICIENT, distinct from IAL_SHORTFALL (evidence present but not meeting a well-formed criterion) -- the two are never conflated. When the target level is not met, achieved level falls back to the highest fully-met level below it. This node rates an evidence set against a declared policy; it does NOT assert that a person is who they claim to be, and no output or copy implies verification of a natural person. No identity attributes are ever computed over -- evidence items are types, strengths and verification methods, with an optional opaque attribute reference (caller-supplied, no commitment scheme claimed by this node) carried through unread, never a plaintext value. No approver identity, signature, approval field or role -- manual review/EDD escalation is a separate signed §27 human_accountability_record, not minted by this kernel. This is the assurance-LEVEL evaluator specifically, distinct from any private-check-receipt evidencing scheme or a re-verification-cadence evaluator (neither built in this exercise). Not 490-eudi-kyc-flow-designer (an eIDAS/LoA-specific flow-design tool) -- this is framework-agnostic by construction and takes any structurally-expressible level definition as a policy input, with no dependency on any named jurisdiction or procurement.",
  "control_description": "Rates whether a DECLARED identity-evidence set reaches a DECLARED target level of a caller-supplied, versioned assurance-level framework (the art-444 policy-input pattern) -- never a hardcoded framework such as NIST 800-63-3 or eIDAS. The level definition supplies levels ordered lowest-to-highest rigor, each with criteria naming a required evidence type and a numeric min_strength on a caller-normalized 0-100 scale; the kernel never interprets a framework's own named tiers. A criterion the definition cannot express (no required_evidence_type or no min_strength) is flagged IAL_DEFINITION_INSUFFICIENT, distinct from IAL_SHORTFALL (evidence present but not meeting a well-formed criterion) -- the two are never conflated. When the target level is not met, achieved level falls back to the highest fully-met level below it. This node rates an evidence set against a declared policy; it does NOT assert that a person is who they claim to be, and no output or copy implies verification of a natural person. No identity attributes are ever computed over -- evidence items are types, strengths and verification methods, with an optional opaque attribute reference (caller-supplied, no commitment scheme claimed by this node) carried through unread, never a plaintext value. No approver identity, signature, approval field or role -- manual review/EDD escalation is a separate signed §27 human_accountability_record, not minted by this kernel. This is the assurance-LEVEL evaluator specifically, distinct from any private-check-receipt evidencing scheme or a re-verification-cadence evaluator (neither built in this exercise). Not 490-eudi-kyc-flow-designer (an eIDAS/LoA-specific flow-design tool) -- this is framework-agnostic by construction and takes any structurally-expressible level definition as a policy input, with no dependency on any named jurisdiction or procurement.",
  "declared_inputs": [],
  "declared_outputs": [],
  "kernel_digest": "sha256:f691517dd02006a5787bea91055d22c567fb6049e1f3d15c3bb2a474032cd335",
  "trust_label": "independently verified: zkVM execution proof (risc0/groth16-bn254)",
  "data_vintage": "2026-08-01",
  "last_validated": "2026-08-01",
  "conformance_fixtures_vendored": true,
  "compute_proof_ready": "ready",
  "wave": 72,
  "source_url": "https://ainumbers.co/chaingraph/art-523-identity-proofing-assurance-level.html",
  "generated_at": "2026-08-15T11:12:17.704Z"
}
