---
title: "C2PA's manifest store is a genuine append-only chain — each edit adds a new manifest without deleting prior ones, and the active manifest is defined as the last entry in that list"
type: "claim"
status: "seedling"
audit_status: "capture-verified (batch bee read spec.c2pa.org official technical specification directly at capture, 2026-07-13; promotion did not re-fetch)"
source_url: "https://spec.c2pa.org"
source_title: "Redirecting"
source_author: "Coalition for Content Provenance and Authenticity (C2PA)"
source_date: "2026-07-13"
source_quote: "Each time an asset is changed, the existing provenance of the asset is preserved, with each new change being added to the provenance."
source_tier: 1
provenance: "Promotion from 10-inbox/raw/2026-07-13-do-c2pa-open-policy-agent-and-study-preregistration.md, 2026-07-15"
origin: "batch"
derived_from: "10-inbox/raw/2026-07-13-do-c2pa-open-policy-agent-and-study-preregistration.md (id 20260713-0230-do-c2pa-open-policy)"
writer_model: "claude-sonnet-5"
date_created: "2026-07-15T00:00:00.000Z"
tags: ["c2pa","provenance","append-only-log","media-authenticity","cross-domain-bridge"]
---


The C2PA technical specification states the mechanism directly: "Each time an asset is changed, the existing provenance of the asset is preserved, with each new change being added to the provenance" (§1.1, Overview). The "active manifest" — the one whose content bindings are validated — is defined structurally as "the last manifest in the list of C2PA Manifests inside of a C2PA Manifest Store" (§2.3.7). Redaction does not erase: per §6.8, "an update manifest should be used to document the redaction... to indicate that digital content was not changed" — the redaction becomes a new appended entry rather than a deletion.

Of the three systems tested against [[question-c2pa-opa-preregistration-append-only-log-criterion]] — C2PA, [[claim-opa-decision-is-stateless-computation-not-log-derived|Open Policy Agent]], and [[claim-preregistration-is-frozen-snapshot-not-append-only-log|study preregistration]] — C2PA is the one whose record-keeping structurally matches the narrow append-only-log-as-truth criterion already confirmed for CANONIC ([[claim-canonic-deliverable-is-an-append-only-evidence-ledger]]), ActiveGraph ([[claim-activegraph-rebuilds-babyagi-on-event-log]]), and R-LAM ([[claim-rlam-third-noncitng-subfield-append-only-log-with-verdict-separation]]). CANONIC's own related-work table names C2PA among its precedents ([[claim-canonic-situates-its-ledger-in-a-named-immutability-lineage]]).

> [!note] Seek's commentary:
> The one of the three that actually earns the narrow reading — an ordered, additive list standing as the record of truth. But C2PA doesn't gate admission the way OPA or preregistration do: nothing stops non-C2PA content from existing or publishing. The manifest is opt-in metadata riding along with the asset, not a checkpoint anything has to clear. It supplies the log half without the gate half, and the authenticity verdict is still rendered externally, by a relying party checking the claim signature against a trust list — not by the chain itself.
> The redaction mechanism (§6.8) is worth a second look someday against the vault's "correct by surrounding, never by erasing" thread ([[claim-early-modern-printers-corrected-print-with-cancel-slips]]) — an update manifest documenting a redaction is structurally the same move as a cancel slip. Not chasing it this pass. — Seek
