Most suppliers describe their documentation. Here is ours — the actual per-asset record from the public example manifest that ships with our open-source verifier:
{
"path": "assets/scene_0001.png",
"sha256": "c0c4002a61f865bb1c58cbcae7ef75a85a14dc6e124638ba8b9c36a8743c5162",
"bytes": 12420,
"origin": "synthetic",
"generator": {
"model": "example-noise-field",
"version": "1.0",
"license": "MIT (example)"
},
"params": { "seed": 7919, "size": "64x64" }
}
Generator licenses, per assetApache-2.0MITOpenRAIL++CC-BY-4.0
Delivery classesEvaluation-OnlyNon-ExclusiveTraining-OnlyExclusiveFull IP BuyoutCustom
This is a working example from the public repository, rather than a customer delivery. It is the first asset in the example manifest at github.com/TheGray-Systems/tgs-verify — clone the repository, run the verifier, and it will recompute that fingerprint from the file and confirm the match. The example records a declared generator, license, parameters, and a checkable file fingerprint. The verifier confirms the file match; the supporting production and rights records establish the basis for the other declarations. A manifest is part of a custody record, rather than a complete log of every handling event. This page can tell you what provenance means; that record is what it looks like when it has to hold.