{
  "schema": "vedokrok.public-item.v1",
  "release_id": "MHC-RPUB-20260920-75ad787a",
  "url": "/knowledge/bind-the-verification-to-the-exact-artifact-reviewed",
  "id": "MHC-D-RESEARCH-0422",
  "version": "0.1.0",
  "title": "Bind the verification to the exact artifact reviewed",
  "summary": "'I checked the file' is incomplete when the file can become a different file tomorrow.",
  "kind": "protocol",
  "body": "Record a stable content identity—hash, immutable revision, signed credential or another exact version reference—alongside the review. Bind conclusions to that artifact, not only to a mutable filename, page or link. If the content changes, require a new or explicitly inherited review decision.",
  "limits": [
    "A hash proves content identity, not that the content is trustworthy or authorized."
  ],
  "topics": [
    "union-provenance-verification"
  ],
  "intents": [],
  "source_ids": [
    "RS-3271B136C6377DC1"
  ],
  "evidence": [
    {
      "claim": "C2PA assertions can record declarations about how an asset originated or was transformed and can be cryptographically bound to the relevant asset.",
      "source_id": "RS-3271B136C6377DC1",
      "role": "supports",
      "note": "A cryptographically bound assertion establishes integrity of that assertion-to-asset relationship, not the truth of every declared fact.",
      "locator": "Assertions and content bindings"
    }
  ],
  "use_when": [
    "A claim says a document or file was verified but the artifact can later change under the same name or URL."
  ],
  "avoid_when": [
    "A hash proves content identity, not that the content is trustworthy or authorized."
  ],
  "example": "A migration input file is approved against its SHA-256 hash; a file with the same name but a different hash needs renewed validation.",
  "check": "The exact bytes or immutable version covered by the review can be recovered or compared later.",
  "steps": [
    "The exact bytes or immutable version covered by the review can be recovered or compared later."
  ],
  "sources": [
    {
      "id": "RS-3271B136C6377DC1",
      "title": "Content Credentials Specification 2.4",
      "url": "https://spec.c2pa.org/specifications/specifications/2.4/specs/ContentCredentials.html"
    }
  ],
  "relations": [],
  "collections": [
    {
      "id": "RC-3F875FF96207B5CE",
      "title": "Trace where information came from before deciding whether to trust it",
      "url": "/collections/trace-where-information-came-from-before-deciding-whether-to-trust-it"
    }
  ]
}
