Skip to content

Provenance DAG

@kindgi/specs/provenance.schema.json, schema version 1.0.0.

Causal DAG for a run. Every output node has edges back to every input that influenced it — prompts, retrieved chunks, tool results, prior turns, model version, tenant policy in effect. This is the PRIMARY audit artifact, not a derivative of OTel spans. Signed with Ed25519 for verification outside the runtime.

  • id (string, required): Unique provenance record identifier.
  • runId (string, required): The kernel run this DAG describes.
  • tenantId (string, required): Tenant that owns this provenance record. Cross-tenant reads are denied by policy.
  • version (string, required): Schema version for this DAG document (semver).
  • createdAt (string (date-time), required): When this DAG was emitted (ISO-8601 UTC).
  • flowRef (object): The flow and version this run executed.
    • id (string, required)
    • version (string, required)
  • nodes (array of Node, required)
  • edges (array of Edge, required)
  • signature (Signature)
  • id (string, required)
  • kind ("input" | "prompt" | "retrieval" | "tool-call" | "tool-result" | "model-call" | "model-output" | "artifact" | "guardrail-check" | "event" | "policy-decision" | "memory-read" | "memory-write" | "wait" | "resume", required): What this node represents in the causal chain.
  • actor (string): Which agent/tool/subsystem produced this node (id or name).
  • timestamp (string (date-time), required)
  • contentHash (string): Content-addressed hash of the node's payload. Enables dedup + tamper detection without storing the payload inline.
  • contentRef (string): Optional blob reference for large payloads (e.g. full model outputs). Format: 'blob://<provider>/<bucket>/<key>'.
  • modelVersion (string): Model + version, for model-call and model-output nodes (e.g. 'anthropic/claude-opus-4-7@2026-06-01').
  • policyDecisionId (string): For policy-decision nodes: the ID that resolves to the full decision record.
  • attributes (map of any): Kind-specific attributes. Interpreted per node kind; consumers should tolerate unknown attributes for forward compatibility.
  • from (string, required)
  • to (string, required)
  • kind ("caused-by" | "influenced-by" | "retrieved-from" | "invoked" | "produced" | "checked-against" | "waited-on" | "resumed-from", required)

Cryptographic signature over the canonical serialization of (nodes, edges, id, runId, tenantId, createdAt, flowRef).

  • algorithm ("ed25519", required)
  • keyId (string, required): Identifier of the signing key (per-tenant or per-deployment).
  • value (string, required): Base64-encoded signature bytes.
  • signedAt (string (date-time), required)