{
  "bundle_version": "1.0",
  "continuity_version": "1.6.0",
  "issued_by": {
    "algorithm": "Ed25519",
    "public_key": "9974a723dcac2f8136fad7fe96ad2421caafb3bf7e5b5bc9109e18402e3f3429",
    "public_key_at": "/x/continuity/pubkey"
  },
  "decision": {
    "evaluation": "e_b67489a423d34295a8ee",
    "grant_exercised": "demo_4437603d4e_3",
    "action": "demo.pay",
    "params_digest": "2aebb9f72e8106be2a0ae60d4ec040adeb2fc3054a802cd0f779f608e5a77219",
    "lineage_digest": "52b4d057edf0a0edd64bca1a4c59f3206b4ad16723c13b27c905940e205ba603",
    "verdict": "ALLOW",
    "authority_verdict": "ALLOW",
    "risk_verdict": "ALLOW",
    "reasons": [],
    "broken_at": null,
    "broken_invariant": null,
    "evaluated_at": "2026-10-03T23:42:00.924504+00:00",
    "evaluated_at_epoch": 1791070920.9245043
  },
  "request": {
    "action": "demo.pay",
    "params": {
      "amount": 20
    },
    "purpose_tag": "demo"
  },
  "lineage": [
    {
      "audit_hash": "cfb030ceea6ce8b7548efd79274a62e8d0441587cfaa0c6bea255689748f6001",
      "block_index": 7146,
      "constraints": {
        "max_amount": 50
      },
      "created": 1791070920.9175038,
      "delegations_left": 0,
      "depth": 0,
      "digest": "9a1c3d583d771fffbe26ebfb47f494d42cd43ddca35c74c80e6669d459ebf775",
      "id": "demo_4437603d4e_3",
      "issuer": "demo-human",
      "issuer_kind": "human",
      "not_after": 1791071820.744608,
      "not_before": 1791070920.9175038,
      "parent": null,
      "purpose": "demo purchase",
      "purpose_tags": [
        "demo"
      ],
      "revoked_at": null,
      "risk_accepted_by": "demo-human",
      "scope": [
        "demo.pay"
      ],
      "subject": "demo-agent-4437603d4e",
      "subject_kind": "agent"
    }
  ],
  "chain": {
    "audit_hash": "f005529d4f3524415c96eeb8d9e841493b4df7ea6cd55efbf2c0094f7529958d",
    "block_index": 7147,
    "inclusion": "/api/inclusion?hash=f005529d4f3524415c96eeb8d9e841493b4df7ea6cd55efbf2c0094f7529958d",
    "whole_chain": "/api/verify-chain",
    "external_anchor": "/api/anchor-status",
    "note": "The signature stands on its own. These make the decision locatable in an externally anchored log as well, which is a second and independent thing to check."
  },
  "rules": {
    "derivation": "/x/continuity/spec",
    "grant_digest": "sha256('AILEASH-GRANT-v1:' || canonical JSON of the grant's semantic fields, keys sorted, no whitespace)",
    "lineage_digest": "sha256('AILEASH-AUTHEVAL-v1:' || canonical JSON of the ordered list of grant digests, root first)",
    "params_digest": "sha256('AILEASH-AUTHEVAL-v1:' || canonical JSON of {action, params})",
    "signature": "Ed25519 over 'AILEASH-AUTHORITY-PROOF-v1:' || canonical JSON of every field of this bundle except signature itself",
    "canonical_json": "keys sorted, separators (',',':'), UTF-8"
  },
  "what_this_proves": "That this decision was reached against this exact authority path, on these exact parameters, at this time, by the holder of the named key. A verifier can re-derive the verdict from the lineage alone and disagree with it.",
  "what_a_verifier_can_re_derive": "The authority verdict, in full, from the lineage in this bundle. The risk verdict cannot be re-derived without the scoring engine and is reported here rather than proved; the composed verdict is the worse of the two, so an authority BLOCK stands whatever the engine said.",
  "what_this_does_not_prove": "That the root grant should have been issued, or that the parameters describe something that really happened. It proves derivation, not merit and not truth.",
  "verify_with": "Any Ed25519 implementation, or the standalone verifier published alongside this system. Remove the signature field, canonicalise what remains, prepend the prefix above, and check.",
  "signature": "c447db76aa211e51273dae5db464a29363979867a535aa2f9120ba494208c0c094d4def35d4c58d4a32240c9b44ed5b09975a455942e559dcfb4da5af477ec08"
}