Agent provenance

Who built it. What changed.Unknown beats a plausible story.

When an agent does something surprising, the first questions are historical: who created it, which prompt version was live, which tool had just been added, which document it read. No connector records an agent's origin, prompts or session context, so Trustivan reports lineage as unknown rather than reconstructing it. What it keeps is evidence: when each identity and tool was first discovered, who owns it, the credentials it holds, and an immutable record of every runtime decision.

Not builtBuild, change and context lineage, by design · runtime decision records are available

Provenancesupport-copilot
Sample records
  1. DiscoveredJun 12AWS connectorIdentity first discovered from an IAM role; owner read from its owner tag
  2. UnknownJun 12no connectorWho built the agent and from which template: not recorded, so shown as unknown
  3. DeclaredJul 03M. OkaforAutonomy declared human in the loop; entitlement to crm.export_records declared
  4. ToolJul 18mcp://crm-toolscrm.export_records first discovered · effect: write, publisher declared
  5. CredentialAug 02policy evaluationAccess key 412 days old · rotation-overdue finding raised for the owner
  6. DecisionAug 19runtime gateRequested export of 1,200 records → CHALLENGE · a grant, approved by someone else, allowed the retry
Illustrative · sample records the platform keeps, shown together here rather than as a console view

The problem

You cannot govern what you cannot reconstruct.

Agents change continuously and from many directions. Without evidence, every review of agent behaviour depends on whoever remembers what was true at the time, and a reconstructed story is only as good as its guesses.

Change Without Deploys

A prompt edit, a new tool listing or a new document changes what an agent does, with no release to point at

Many Authors

Humans, pipelines and other agents all modify an agent, and the log of who did what lives in none of their tools

Actions Without Context

Audit logs show the action an agent took, not the instruction, tool output or document that caused it

The model

Four lineages, one honest answer each

Provenance answers different questions at different times. For each one, Trustivan either keeps the evidence or says plainly that it does not have it.

Build Lineage

Creator, template, framework and the approvals that let the agent exist. No connector reports them, so origin is shown as unknown

Not built

Change Lineage

Prompt versions and edits by people, pipelines or agents. Prompts are never read; tools carry first-discovered and absent-since instead

Not built

Context Lineage

The prompts, tool outputs and documents an agent saw in a session. Nothing collects them: the platform has nowhere to put them, by design

Not built

Decision Lineage

Each authorization decision with the acting identity, the intent it stated and the rules that decided it, immutable once written

Available

How it works

Discover. Attribute. Decide. Report.

Provenance here is assembled from what the platform observed or was told, never from what would make a timeline look complete.

  1. Discover

    Every identity and tool carries when a connector first discovered it, when it was last seen and the evidence the provider returned.

  2. Attribute

    Ownership, autonomy, tool effect and entitlements each name their basis: reported by a provider or declared by an operator.

  3. Decide

    Every runtime decision is written once with the rules that fired, and a database trigger refuses any later change to it.

  4. Report

    Where lineage is asked for and nothing recorded it, the lineage finding reports its fact as unavailable instead of a clean result.

What you get

Answers an incident review can use

Each answer links to the record that supports it: the connector evidence, the declaration, the decision.

Who Owns It

The accountable owner for every agent, read from provider tags or assigned by a person, and a finding when there is none

When It Appeared

First discovered and last seen for every identity and tool, and marked absent when a provider stops reporting it

What It Holds

The credentials bound to the agent, with age, rotation and exposure state, and the tools it is entitled to call

Entitlement Drift

Declared tools not used, and use nothing declared, compared on read and available through the API

Audit Evidence

An append-only, hash-chained audit trail and an evidence export that can be verified offline

Decision Records

Every ALLOW, CHALLENGE and DENY about the agent, with the rules that fired and the intent it stated

Evidence before claims

Provenance is the evidence model, applied over time

A finding answers nine questions about an identity right now. The records behind it say when each fact arrived and who supplied it.

Same nine questions

Why, what, who, where, how, with the record attached

The finding on the right is about a service account, and an agent finding carries the same fields: the connector evidence behind the identity, its owner and credentials, the tools it is entitled to and the decisions made about it. Where an agent came from and what it read are not recorded, so Trustivan shows unknown rather than reconstructing a plausible story.

  • Source records with timestamps, not summaries of them.
  • Evidence export on demand, verifiable offline, for audits and incident reviews.
Read why risk must be explainable
HighOrphaned identityLong-lived credential

Orphaned service identity with reachable production data

Why
Orphaned service account still holds active production credentials
What
svc-billing-export (service identity)
Who
Owner unknown — no owner tag and no assigned owner
Where
cloud account prod-core · region eu-west-1
How
Long-lived access key (age 611 days), still active, on a machine IAM user
Blast radius
2 production databases, 1 backup bucket, 4 downstream services
Recommendation
Assign owner, rotate to short-lived credential, scope role to export-only
Action
Propose remediation · assign owner · quarantine in platform
Evidence
AWS IAM sync 2026-08-19 · access-key metadata · owner tag absent
Evidence before claims — when evidence is missing, Trustivan shows unknown, never a fabricated score.Illustrative finding · sample environment

Decide what an agent may do before it acts.

See how TRUSTIVAN connects identity, credential, access, agent and action context into one control plane.