Type: Node / Traceable History
Working Definition: Provenance is the traceable history by which a record, claim, authority, or artifact remains intelligible and accountable over time — the structured account of where something came from, who created or transformed it, under what authorization, and through what chain of custody.
Function in the Grammar: Provenance is what makes the past usable. A record without provenance is a statement whose origin is unknown; it may be true, but it cannot be trusted, audited, or contested on principled grounds. Provenance gives records their epistemic and institutional weight: not by guaranteeing that they are correct, but by making it possible to assess how much weight to give them, who is responsible for their contents, and what conditions governed their creation. Where provenance is weak, accountability is fragile — acts cannot be traced, authority cannot be verified, and institutional memory cannot be distinguished from institutional fabrication.
Provenance is not merely origin. Knowing who made something is provenance in a thin sense. Full provenance traces the entire history of an artifact through its creation, transformation, transfers, and use — and links each stage to the conditions that governed it: who acted, under what authority, at what time, using what instruments, with what inputs, producing what outputs, and subject to what review. Provenance is the answer to: "Can you show your work, and can I verify that the work was legitimate?"
Formal Grammar Representation
Provenance(p, artifact: x) iff
p traces: Creator(x), CreatedAt(x), AuthorizingAct(x)
p traces: Inputs(x) — what x was derived from
p traces: Transformations(x) — what was done to x, by whom, when, under what authority
p traces: Chain-of-Custody(x) — who held x, in what state, from when to when
p traces: DerivativeOf(x, prior: y) — if x was derived from y, p includes Provenance(y)
p is reconstructable by a future actor who was not present at creation
Provenance(p, artifact: x) is adequate for governance iff
AuthorizingAct(x) is locatable in Ledger(I)
Creator(x) is traceable to a recognized Role in I
each Transformation(x) is itself a recorded, authorized act
p contains enough information to assess weight, reliability, and institutional validity
Semantic Constraints
The formal expression Provenance(p, x) is well-formed when p traces the creation, authorization, transformation, and custody of x through a chain reconstructable by future actors. Whether p functions as adequate provenance — whether it actually enables accountability, weight assessment, and contestation — depends on whether each stage of the chain was honestly recorded, whether authority sources were genuinely valid rather than fabricated, and whether the institution treats the provenance record as authoritative rather than as a formality. Provenance that is technically complete but systematically falsified enables a different kind of institutional failure: confident accountability to a false past.
Formal Pattern
Provenance(p, artifact: x, institution: I)
CREATED_BY(x, Agent(a), Role(r), at: t, under: AuthoritySource)
DERIVED_FROM(x, prior_artifact: y)
TRANSFORMED_BY(x, Agent(b), Act(α), at: t₂, producing: x′)
TRANSFERRED_TO(x, Agent(c), at: t₃, condition: s)
RECORDED_IN(p, Ledger(L))
ADEQUATE_FOR(p, purpose: audit) -- p contains enough to reconstruct legitimacy
ADEQUATE_FOR(p, purpose: weight) -- p contains enough to assess epistemic status
Core Relations
| Relation | Notes |
|---|---|
| Ledger records | Provenance chains must be reconstructable from the ledger. An event in the chain that is not recorded in any ledger is a provenance gap — the chain can assert that something happened, but cannot prove it. |
| Authority traces | Each link in the provenance chain must cite the authorization under which the act or transformation occurred. A link without an authority source is an assertion of origin without institutional grounding. |
| Creation initiates | The first link in a provenance chain is the creation event: who made this, when, under what authority, from what inputs. Creation events without records are unverifiable origins. |
| Transformation extends | Each modification or processing of an artifact adds a link to its provenance chain. Transformations that are not recorded break the chain at the point of transformation. |
| Chain of custody preserves | Between creation and current use, an artifact may pass through many hands. Chain of custody tracks who held it in what state. Gaps in custody are integrity vulnerabilities. |
| Receipt proves | A receipt is a specific kind of provenance record: the attestive artifact that proves a governed act occurred under specific authority. Receipts are the governance-grade instantiation of provenance claims. |
| Evidence activates | Provenance is what allows a record to function as evidence. Without adequate provenance, a record may be offered as evidence but its weight cannot be assessed. |
| Continuity requires | Institutional continuity depends on provenance: an institution that cannot trace its acts to their authority sources has provenance gaps that break the accountability chain. |
Typical Questions
- Can this artifact's origin be traced to a specific creation event by a specific authorized actor?
- Has this record been transformed since creation, and is each transformation documented?
- Is there a complete chain of custody from creation to current use?
- Under what authorization was each link in this chain performed?
- Does this artifact's provenance support the weight being placed on it?
- What would a future auditor need to reconstruct this artifact's legitimacy?
Examples
| Domain | Artifact | Provenance that matters |
|---|---|---|
| Art / museum | A painting attributed to a master | Chain of ownership from documented sale to present; prior attribution records; authentication history; any known gaps or disputed transfers |
| Law / forensics | A DNA sample used in evidence | Chain of custody from collection through testing: who collected it, who handled it, in what conditions, who analyzed it |
| Science / publishing | A dataset used in a paper | Who collected it, what instruments, what processing pipeline, what transformations, who reviewed it, where it was deposited |
| Corporate governance | A board resolution | Who proposed it, who voted, what authority authorized the meeting, how the vote was recorded, who certified the minutes |
| Archives / history | A diplomatic document | Authentication, dating, chain of custody from origin through all known holdings, any known alterations or restorations |
| Digital governance | An AI-generated interpretation | Who called the model, which model, what version, what inputs, what parameters, what certificate was produced, what human review occurred |
| Ordinary life | A receipt for a payment made | Amount, date, parties, and ideally: what authority governed the transaction, whether any dispute arose and was resolved |
Distinctions
Provenance ≠ Origin. Origin names the starting point: who made this, when. Provenance traces the entire history: creation, transformation, custody, and authorization at each stage. An artifact may have a known origin and broken provenance if the chain between origin and present is undocumented. The distinction matters for audit: a known origin is not sufficient if the custody chain has gaps that could have allowed alteration.
Provenance ≠ Authentication. Authentication determines whether an artifact is what it claims to be. Provenance provides the evidence base for authentication, but the two are different operations. Authentication is a judgment; provenance is the chain of evidence that informs it. An artifact may have excellent provenance and still be fraudulent (if the provenance was fabricated); an artifact may be authentic and have poor provenance (if its history was undocumented but it happens to be genuine).
Provenance ≠ Authorship. Authorship identifies the creator. Provenance traces the full lifecycle. A document's author may be well-known while its provenance is poor — if the document passed through undocumented custody, was altered without record, or lacks an authority chain back to the institution that commissioned it.
Provenance ≠ Record. A record is a durable institutional artifact. Provenance is the history of that artifact — including the records that constitute it. Provenance is the chain; a record is one link. An artifact may be a record without being its own provenance; it requires separate documentation of its own history.
Common Failure Modes
| Mode | Description |
|---|---|
| Provenance gap | A link in the chain is missing — an undocumented transfer, an unrecorded transformation, or a creation event whose authorization is unverifiable. Future actors cannot reconstruct the chain through the gap. Where to look: any point in an artifact's history where custody changed hands without a documented record. |
| Authority-free provenance | Each stage of the chain is recorded, but without reference to the authorization under which the transformation occurred. The provenance is complete as a sequence of events but lacks institutional grounding. Where to look: provenance chains that record who did what but not under what authority. |
| Chain of custody break | An artifact passed through custody in a condition or under circumstances that are not documented. The gap creates an integrity vulnerability: the artifact could have been altered during the undocumented period. Where to look: periods in an artifact's history where it was held without formal custody records. |
| Provenance fabrication | The provenance chain exists and appears complete, but one or more links have been fabricated — custody records were created after the fact, transformation records were falsified, or authorizations were invented. Technically complete but dishonest provenance enables confident but false accountability. Where to look: provenance chains where independent verification of specific links is not possible. |
| Provenance-weight mismatch | An artifact is given more institutional weight than its provenance supports. A record with poor provenance is treated as authoritative; an LLM output without a certificate is treated as evidenced. Where to look: consequential decisions based on artifacts whose provenance was not examined before the decision was made. |
Minimum Viable Test Case
x = "AlwaysBecoming encyclopedia entry: Institution"
p = Provenance(x):
CREATED_BY(x,
Agent: model_assistant,
Role: model_assistant (AlwaysBecoming),
at: 2026-06-29T14:00:00Z,
under: CLAUDE.md collaboration protocol + /substrate-entry skill
)
DERIVED_FROM(x,
wiki/architecture/institutional-grammar.md,
wiki/architecture/substrate-constitution.md
)
TRANSFORMED_BY(x,
Agent: human_author,
Act: editorial review,
at: [review timestamp],
producing: x′ (revised draft)
)
RECORDED_IN(x, content/encyclopedia/institution.md, Ledger: publication log)
A future reader consulting the entry can determine:
- who produced the draft (model_assistant, under documented protocol)
- what sources it drew from (wiki architecture pages, on specific dates)
- whether it received human review (tracked by human_reviewed field)
- under what authority the collaboration protocol governed (CLAUDE.md)
Without this chain, the entry's epistemic status would be "text of unknown origin"
rather than "AI-drafted, human-reviewed, source-traceable philosophical entry."
In Substrate
In Substrate, provenance is constitutionally required for every consequential act. The architecture distinguishes several provenance layers that together constitute full institutional provenance:
- Evidence profile: producer, provenance completeness, authentication, corroboration, review, relevance, and support direction
- Bridge rule version: which rule governed the act, identified by hash, with the full rule text retrievable from the RuleVersionHash index
- L5A anchor status: whether the constitutional anchor the rule depended on was compatible at the time
- LLM certificate: for AI-generated interpretations, the certificate records model identity (with attestation strength), inference parameters, input and output hashes, and known limitations
- Receipt: the attestive artifact that ties these elements together into a proof that a specific governed act occurred under specific authority
- Consolidation snapshot: periodic cryptographic summaries that commit the completeness of the provenance record
The Substrate provenance principle: historical legitimacy depends on exact reconstruction. Approximate provenance is not adequate provenance. The ability to say "the model was probably llama3" or "the rule probably looked like this" is not the ability to say what actually acted under what actual authority.
Cross-References
Required
- Ledger — provenance chains must be reconstructable from the ledger; the ledger is the medium of institutional provenance
- Institution — institutions require provenance for their acts to be accountable
- Authority — each link in a provenance chain must cite the authority under which it occurred
Consequential
- Evidence — provenance is what allows a record to function as evidence; without it, the record cannot be assessed
- Claim — provenance is what allows a claim to be assessed rather than merely asserted
- Receipt — the governance-grade provenance artifact for a specific governed act
- Recognition — recognized acts are the links in provenance chains
Evidential
- Continuity — continuity holds only if provenance chains are unbroken from current acts to founding instrument
- Commitment — provenance is required to verify that a commitment was properly created and that fulfillment was genuine
- Interpretation — interpretive acts must carry provenance for their outputs to be institutionally usable
- Amendment — amendments must carry provenance tracing back to the constitutional provision they amend