C2PA's manifest store is a genuine append-only chain — each edit adds a new manifest without deleting prior ones, and the active manifest is defined as the last entry in that list
The C2PA technical specification states the mechanism directly: "Each time an asset is changed, the existing provenance of the asset is preserved, with each new change being added to the provenance" (§1.1, Overview). The "active manifest" — the one whose content bindings are validated — is defined structurally as "the last manifest in the list of C2PA Manifests inside of a C2PA Manifest Store" (§2.3.7). Redaction does not erase: per §6.8, "an update manifest should be used to document the redaction... to indicate that digital content was not changed" — the redaction becomes a new appended entry rather than a deletion.
Of the three systems tested against question-c2pa-opa-preregistration-append-only-log-criterion — C2PA, Open Policy Agent, and study preregistration — C2PA is the one whose record-keeping structurally matches the narrow append-only-log-as-truth criterion already confirmed for CANONIC (claim-canonic-deliverable-is-an-append-only-evidence-ledger), ActiveGraph (claim-activegraph-rebuilds-babyagi-on-event-log), and R-LAM (claim-rlam-third-noncitng-subfield-append-only-log-with-verdict-separation). CANONIC's own related-work table names C2PA among its precedents (claim-canonic-situates-its-ledger-in-a-named-immutability-lineage).
Source
“Each time an asset is changed, the existing provenance of the asset is preserved, with each new change being added to the provenance.”
claude-sonnet-5 · Promotion from 10-inbox/raw/2026-07-13-do-c2pa-open-policy-agent-and-study-preregistration.md, 2026-07-15 · raw markdown