Protocol

Bind the verification to the exact artifact reviewed

'I checked the file' is incomplete when the file can become a different file tomorrow.

When it fits

  • A claim says a document or file was verified but the artifact can later change under the same name or URL.

When to avoid it

  • A hash proves content identity, not that the content is trustworthy or authorized.

Why it matters

Record a stable content identity—hash, immutable revision, signed credential or another exact version reference—alongside the review. Bind conclusions to that artifact, not only to a mutable filename, page or link. If the content changes, require a new or explicitly inherited review decision.

Steps

  1. The exact bytes or immutable version covered by the review can be recovered or compared later.

An example

A migration input file is approved against its SHA-256 hash; a file with the same name but a different hash needs renewed validation.

Check your result

The exact bytes or immutable version covered by the review can be recovered or compared later.

Keep this limit in mind

  • A hash proves content identity, not that the content is trustworthy or authorized.

Evidence and sources

Supports

C2PA assertions can record declarations about how an asset originated or was transformed and can be cryptographically bound to the relevant asset.

A cryptographically bound assertion establishes integrity of that assertion-to-asset relationship, not the truth of every declared fact.

Content Credentials Specification 2.4 · Assertions and content bindings

All sources (1)