C2PA Ingredient Assertions: How to Trace Source Assets and Edits
Start with the asset you actually received
Save the file before reading its provenance. Record the download page, time, filename, and file size. If a platform offers several renditions, label the exact copy you inspect. This preservation step is an editorial recommendation from this guide. It keeps later notes tied to one file instead of an unspecified preview.
The C2PA specification distinguishes derived and composed assets. A derived asset begins with an existing asset whose digital content is modified. A composed asset is built from parts or fragments of digital content called ingredients. The specification gives a video assembled from existing video clips and audio segments, and an image with another image placed over it, as examples.
That distinction gives an ingredient record a limited job. It can help a reviewer follow recorded inputs through a media workflow. Check for source material outside the manifest, and verify the scene and caption separately.
Copy the ingredient entry before interpreting it
Open the Content Credential with a compatible verifier and copy what it displays for each ingredient. Keep the displayed title or identifier, media format, relationship value, linked manifest information, and validation wording when those fields are available. Do not translate a technical status into a broader verdict. If a field is absent, record it as absent rather than guessing.
C2PA defines an assertion as a statement concerning an asset. The statement may be created by the signer or gathered when the claim is generated, and it becomes part of the C2PA Manifest. The claim references a set of assertions and is digitally signed. Record the displayed ingredient entry together with the claim and signature information shown by the verifier.
Create a simple table with one row per displayed ingredient and one column for each field the verifier exposes. Preserve the original spelling of identifiers and status codes. A screenshot can support the notes, but retain the file and copied text so another reviewer can repeat the check.
Draw only the relationship the record supports
Use each ingredient entry to draw a link between the current asset and the recorded source asset. Mark the link with the exact relationship value shown by the verifier. If an ingredient has its own manifest, keep that manifest's result beside the link. If the verifier cannot resolve it, preserve the failure or informational wording without inventing the missing history.
A useful diagram may contain several branches because a composed asset can contain multiple parts. It may also contain a sequence when one asset was derived from another. Use the diagram as a reading aid. Keep unrecorded steps visibly unknown, and check separately for edits or contributors outside the record.
Compare two copies only after labeling them. A different ingredient list may reflect different files, renditions, or records; the difference alone does not establish who changed the asset or why. Return to the saved copies and their exact provenance results before making a claim.
Separate provenance from file analysis and fact-checking
Maintain three notes. The first contains the ingredient map and the verifier's exact output. The second contains observations about the saved file. You can submit an image, video, audio, or text file to DeepFakeCheck for a probabilistic risk signal. Use a dedicated C2PA verifier to check signatures and ingredient history.
Automated detectors can produce false positives and false negatives. Keep the analyzed copy and result together, and continue the provenance and factual checks regardless of the risk signal.
The third note addresses the real-world claim. Open the original publication page, identify the account or organization presenting the media, record the claimed date and context, and look for independent evidence about the event. A provenance record and external evidence can inform the same review, but each answers a different question.
Leave a review another person can repeat
Finish with the saved file identifier or hash if your tool provides one, the verifier name, its exact ingredient and validation text, the source page, and unresolved questions. Do not fill missing fields from memory or from a badge image.
The next reviewer should be able to open the same file, reproduce the provenance check, compare each displayed ingredient, and continue the factual investigation from the recorded gaps.
Sources
- C2PA, “Content Credentials: C2PA Technical Specification”: https://spec.c2pa.org/specifications/specifications/2.2/specs/C2PA_Specification.html
Suspect an image might be AI-generated?
Use our advanced deepfake detection tool to analyze images with high precision.
Analyze Image Now