payloadDigest property
The binding between what the approver sees and what executes. Multibase-encoded
multihash over the RFC 8785 (JCS) canonicalization of the payload, the task type,
and the challenge as salt. The decision echoes it; the executor re-derives it
from the payload it is about to run and refuses on mismatch. Salted because an
unsalted digest over a low-entropy payload is a confirmation oracle for anyone who
observes it in transit.
Implementation
final DigestMultibase payloadDigest;