Check whether the evidence can explain the agent's execution.
A provenance design defines what should be retained. This review tests whether the real execution evidence is actually complete and useful.
Logging is not the same as reconstructability.
The review examines whether selected agent runs can be reconstructed sufficiently to understand the process context, actions, tools, controls, human decisions, and outputs involved.
Verify that agent-execution provenance is complete, consistent, and usable for the assurance needs of the organization.
What the review can examine.
- Agent identity and version
- Process version
- Effective-process context
- Applied skills and rules
- Hook and gate results
- Tool calls
- Relevant inputs
- Outputs and modifications
- Approvals and interventions
- Execution history
- Relationships between the evidence
Five steps from selected runs to a better provenance model.
Select representative executions
Choose agent runs appropriate to the risk and assurance objectives.
Reconstruct the execution
Attempt to understand what happened from the retained evidence.
Identify gaps and inconsistencies
Find missing relationships, ambiguous records, unexplained actions, or evidence that cannot be tied back to the process.
Assess usability
Determine whether a reviewer can interpret the evidence efficiently and reliably.
Improve the provenance model
Recommend changes to evidence capture, structure, retention, or review.
- Provenance review
- Missing-evidence findings
- Consistency findings
- Reconstructability assessment
- Reviewability findings
- Improvement recommendations
- Find out before an audit whether the record actually explains the run.
- Distinguish evidence that exists from evidence that is usable.
- Expose relationships that were never captured.
- Improve the provenance model from real executions.
Findings become changes to what the design says should be captured and how.
