Provenance DAG
@kindgi/specs/provenance.schema.json, schema version 1.0.0.
Causal DAG for a run. Every output node has edges back to every input that influenced it — prompts, retrieved chunks, tool results, prior turns, model version, tenant policy in effect. This is the PRIMARY audit artifact, not a derivative of OTel spans. Signed with Ed25519 for verification outside the runtime.
id(string, required): Unique provenance record identifier.runId(string, required): The kernel run this DAG describes.tenantId(string, required): Tenant that owns this provenance record. Cross-tenant reads are denied by policy.version(string, required): Schema version for this DAG document (semver).createdAt(string (date-time), required): When this DAG was emitted (ISO-8601 UTC).flowRef(object): The flow and version this run executed.id(string, required)version(string, required)
nodes(array of Node, required)edges(array of Edge, required)signature(Signature)
Definitions
Section titled “Definitions”id(string, required)kind("input"|"prompt"|"retrieval"|"tool-call"|"tool-result"|"model-call"|"model-output"|"artifact"|"guardrail-check"|"event"|"policy-decision"|"memory-read"|"memory-write"|"wait"|"resume", required): What this node represents in the causal chain.actor(string): Which agent/tool/subsystem produced this node (id or name).timestamp(string (date-time), required)contentHash(string): Content-addressed hash of the node's payload. Enables dedup + tamper detection without storing the payload inline.contentRef(string): Optional blob reference for large payloads (e.g. full model outputs). Format: 'blob://<provider>/<bucket>/<key>'.modelVersion(string): Model + version, for model-call and model-output nodes (e.g. 'anthropic/claude-opus-4-7@2026-06-01').policyDecisionId(string): For policy-decision nodes: the ID that resolves to the full decision record.attributes(map of any): Kind-specific attributes. Interpreted per node kind; consumers should tolerate unknown attributes for forward compatibility.
from(string, required)to(string, required)kind("caused-by"|"influenced-by"|"retrieved-from"|"invoked"|"produced"|"checked-against"|"waited-on"|"resumed-from", required)
Signature
Section titled “Signature”Cryptographic signature over the canonical serialization of (nodes, edges, id, runId, tenantId, createdAt, flowRef).
algorithm("ed25519", required)keyId(string, required): Identifier of the signing key (per-tenant or per-deployment).value(string, required): Base64-encoded signature bytes.signedAt(string (date-time), required)