Provenance Chain
↓
Authoritative Artifact
↓
Canonical Representation
↓
Integrity-Generation Process
↓
Integrity Reference
Each step should remain reconstructable enough for later integrity review.
Provenance defines the chain of origin behind an Integrity Reference: where the Source Artifact came from, which representation was used, how integrity material was generated, and how that material became an Anchor-owned record.
Provenance strengthens reviewability without making Anchor the source authority for the artifact it preserves.
Each step should remain reconstructable enough for later integrity review.
Identifies the institution, Source-System Identifier, and authoritative origin of the artifact being anchored.
CoreRecords how the Authoritative Artifact became the exact Canonical Representation governed by the Integrity Reference.
CoreRecords which process, method, algorithm, signer, timestamp service, or commitment mechanism produced the integrity material.
CoreRecords how the generated integrity material was assembled, reviewed, Versioned, and preserved as an Anchor Integrity Reference.
CoreProvenance explains origin and transformation. It does not redefine institutional ownership.
Anchor may document that integrity material originated from a Certifier, Registry, Chronicle, Attestor, or other Source Artifact while that institution remains authoritative for the artifact itself.
Relationships and Provenance overlap, but answer different questions.
A Source Artifact relationship may be one component of a larger provenance chain.
Source provenance preserves enough information to identify:
Source provenance should establish origin without copying unnecessary Source-system metadata into Anchor.
Representation provenance records how Anchor determined exactly what representation was anchored.
If a transformation occurs, that transformation must be reproducible or clearly documented.
Some artifacts may require normalization or transformation before integrity material is generated.
Potential transformations may include:
Anchor should never silently transform a Source Artifact.
Generation provenance explains how the Integrity Value or related verification material was created.
The goal is reproducibility, not unnecessary implementation logging.
Where materially relevant, Provenance may preserve who or what process performed an integrity-generation or review step.
Attribution should follow the minimum-necessary-data principle.
Time is part of provenance when sequence matters.
Potential timestamps may include:
Not every timestamp should be required. The schema should preserve only times that materially support later reconstruction.
Where Anchor uses external commitments, provenance should connect the Integrity Reference to the process that created the external evidence.
Bitcoin, timestamp services, transparency logs, or future commitment systems should remain external evidence rather than sources of institutional authority.
An Integrity Reference may use more than one Integrity Method or external evidence source.
Provenance must preserve the sequence and dependency of those steps where their order affects Verification.
Anchor's first production candidate applies this provenance model to the machine-readable Satoshium Certified Record generated by Satoshium Certifier:
The intended Representation Boundary is the complete SCRD JSON document. Objects referenced by that JSON—including the Certification Package, Atlas records, SCPR, SCR, SCRD HTML, Registry, and Chronicle records—remain outside the Representation Boundary unless separately anchored.
The exact canonicalization or serialization method remains a downstream production decision. Provenance must record that decision explicitly before integrity material is generated.
First Production CandidateProvenance is complete when a later reviewer can reconstruct the integrity-preservation path sufficiently to understand and repeat the Verification process.
Completeness does not require preserving every operational event.
Reproducibility is a central test of useful provenance.
Where exact reproduction is impossible because an external method is time-dependent or stateful, Provenance should preserve enough evidence to verify the historical operation.
Provenance must preserve which Version of each relevant element applied.
These Versions must remain distinct.
A Correction may change Anchor-owned provenance information if Anchor recorded the provenance incorrectly.
Correction must not silently replace the historical provenance record.
Verification depends on Provenance.
Missing provenance may make otherwise valid integrity material impossible to interpret later.
The Integrity Reference Base Schema now provides structured provenance containers for the provenance layers defined by this architecture.
Exact internal field structure remains intentionally extensible where the first production Integrity Reference has not yet proven that tighter typing is necessary.
Production provenance should preserve, at minimum where applicable:
Formal Anchor Validation now confirms that required provenance information is present and internally consistent for the production candidate.
Missing or contradictory required provenance produces a Validation failure or blocks progression until governed remediation is complete.
Anchor should preserve enough provenance to make integrity independently reviewable without turning every Integrity Reference into a complete operational audit log.
Provenance should make the origin and production of integrity material reconstructable while preserving the authority of the Source Institution.