{
  "tool_id": "art-459-sod-matrix-check",
  "kernel_id": "art-459-sod-matrix-check",
  "display_name": "Segregation-of-Duties Matrix Checker",
  "tool_version": "1.0.0",
  "mandate_type": "compliance_control",
  "purpose": "Evaluates a caller-declared role-assignment set against a caller-declared SoD conflict ruleset for SOX 404 / ICFR access controls. For every user, checks all pairs of assigned roles against the ruleset and returns any conflicts found, the count of affected users, and a clean/not-clean verdict. The ruleset is a versioned policy input, never derived by the kernel. Deterministic pairwise set evaluation only. Zero network, zero PII -- user_id and role names are caller-supplied opaque strings.",
  "control_description": "Evaluates a caller-declared role-assignment set against a caller-declared SoD conflict ruleset for SOX 404 / ICFR access controls. For every user, checks all pairs of assigned roles against the ruleset and returns any conflicts found, the count of affected users, and a clean/not-clean verdict. The ruleset is a versioned policy input, never derived by the kernel. Deterministic pairwise set evaluation only. Zero network, zero PII -- user_id and role names are caller-supplied opaque strings.",
  "declared_inputs": [],
  "declared_outputs": [],
  "kernel_digest": "sha256:991bda6ad22de1f56d310c7cfbe98b6a7a9e4fdace9805007b0cc161d05cd7cd",
  "trust_label": "independently verified -- zkVM execution proof (risc0/groth16-bn254)",
  "data_vintage": "2026-07-24",
  "last_validated": "2026-07-24",
  "conformance_fixtures_vendored": true,
  "compute_proof_ready": "ready",
  "wave": 74,
  "source_url": "https://ainumbers.co/chaingraph/art-459-sod-matrix-check.html",
  "generated_at": "2026-07-25T20:02:55.601Z"
}
