Agentic Provenance Protocol

Independent assurance for agentic activity under partial visibility.

INEVRI develops APP, the Agentic Provenance Protocol. APP provides an independent assurance layer for agentic activity as it moves across tools, APIs, services and execution environments.

It does not depend on complete access to every system involved. Instead, APP establishes the strongest defensible view of an activity from the evidence available at each observation or enforcement point — and progressively strengthens that view as additional trusted evidence becomes available.

See the demos

Agent & model platforms APP observes

OpenAI Assistants
Anthropic Claude
Google Vertex AI
Microsoft Autogen
LangGraph
CrewAI
AutoGPT
Semantic Kernel
LlamaIndex
Magentic-One
OpenAI Assistants
Anthropic Claude
Google Vertex AI
Microsoft Autogen
LangGraph
CrewAI
AutoGPT
Semantic Kernel
LlamaIndex
Magentic-One

Names shown are interoperability targets APP is designed to observe or enforce at — no customer, partnership or integration relationship is implied.

A Continuous Representation

APP maintains an evidence-backed view of the activity as it evolves.

An agentic activity does not happen in one place. APP holds a live representation of it across every system it touches.

01

Who or what is acting

02

Who the activity is attributed to

03

What authority can be established

04

Which permissions and policies apply

05

What action is being attempted

06

Which systems are being accessed

07

What state is known at that moment

08

What changes as the activity progresses

09

What can and cannot be independently verified

Built for Incomplete Visibility

Autonomous activity does not occur inside a perfectly integrated environment.

Some systems expose detailed state. Some provide only an authenticated request. Some expose nothing beyond the interaction at their boundary. APP is designed for that reality — it never converts missing information into false certainty.

Verified

Independently corroborated by trusted evidence.

Asserted

Claimed by a participant, not independently confirmed.

Inferred

Derived from available signals, not directly observed.

Unresolved

Evidence is insufficient to establish the state.

Conflicted

Two trusted sources disagree; the conflict is preserved.

Stale

Established earlier; no longer guaranteed current.

Revoked

Previously valid authority that has been withdrawn.

Unavailable

No evidence is accessible at this observation point.

APP maintains an explicit distinction between these states, so an organisation can decide using the actual quality of evidence available at the moment an autonomous action occurs.

Protect From the First Interaction

APP can begin providing value from a single protected boundary.

An unknown autonomous system approaches an API. That may already be enough to decide whether the activity should proceed, be rejected, or require additional verification.

The requested action
The credential being presented
The protected resource
Local permissions
Origin signals
Recent interaction behaviour
Applicable local policy

APP does not need to understand the agent's entire internal architecture before protecting the system.

Trust Is Built Progressively

Additional evidence strengthens the APP state as activity continues.

No single connector is required for APP to function. The assurance state becomes stronger as independently useful evidence accumulates.

Initially

Agent identityUnresolved
PrincipalUnavailable
CredentialValid
Requested actionKnown
Delegated authorityUnavailable

APP can apply local policy using this state.

Verifiable authority presented

PrincipalVerified
DelegationVerified
AuthorityEstablished

The agent presents organisational authority.

Runtime connector contributes

RuntimeVerified
Agent sessionCorrelated
Tool activityObserved

An agent-runtime socket adds evidence.

Execution provider returns

ExecutionVerified

A deterministic execution reference arrives.

Connectors Increase Assurance

APP connectors are independent sources of additional evidence — not a brittle integration chain.

A single observation point can provide immediate protection and provenance. Additional sockets simply increase the amount of activity APP can independently corroborate.

Agent identity
Principal identity
Delegated authority
Runtime state
Policy state
Provider acknowledgement
Execution state
Settlement or outcome state

More connectivity can produce stronger assurance.

Missing connectivity does not invalidate the state already established.

An Independent State Thread

APP treats an autonomous activity as a stateful object that evolves over time.

Each property can change independently. An agent can stay authenticated while its authority expires; a valid credential can coexist with unresolved delegated authority. APP preserves those distinctions.

Actor
Principal
Authority
Permissions
Policy
Behaviour
Session
Tool
Resource
Action
Provider
Execution
Outcome
Evidence

This creates a much richer representation of autonomous activity than identity, authentication or transaction logging alone.

APP Does Not Guess

APP only asserts what the available evidence justifies.

This is central to APP's independence.

01

If an agent's principal cannot be established, APP records the principal as unresolved.

02

If authority is claimed but cannot be independently verified, APP records it as asserted.

03

If two trusted systems provide conflicting state, APP preserves the conflict.

04

If an execution cannot be deterministically linked to an earlier request, APP does not present the relationship as proven.

The protocol preserves uncertainty rather than hiding it.

Not All Evidence Is Equal

APP tracks both a state and the evidence supporting that state.

The same claim, backed by different evidence, is a fundamentally different thing. APP preserves that distinction throughout the activity.

Asserted

Delegated authority: Transfer up to $1,000,000

Source: Agent self-assertion

Status: ASSERTED

Verified

Delegated authority: Transfer up to $1,000,000

Source: Enterprise authority service

Evidence: Signed delegation

Status: VERIFIED

The same principle applies to identity, policy, execution, results and external state.

Not All Correlation Is Equal

APP also distinguishes how strongly one event can be linked to another.

APP does not turn similarity into causation.

Deterministically Linked

A provider transaction carries the same signed identifier as the original agent request.

Corroborated

Two observations share multiple independent identifiers.

Probabilistically Correlated

Two records match only by time, value and context.

Unresolved

There is insufficient evidence to establish a link.

Outside-In

APP can protect systems from agents it does not control.

At an API, MCP server, service gateway or payment interface, APP evaluates the activity using the evidence available locally. The external agent does not need to run APP. The originating organisation does not need to expose its internal systems. The model provider does not need to participate.

Observe the request
Classify the origin
Evaluate local access
Apply policy
Assess available behavioural signals
Request stronger evidence
Allow, block or escalate
Preserve the resulting state
Inside-Out

Where an organisation controls the agent itself, APP can operate closer to the runtime.

Inside-Out increases the richness of provenance. It is not a prerequisite for Outside-In protection.

Known agent identity
Known principal
Delegated authority
Session context
Tool activity
Policy context
Runtime state
Execution intent
One Protocol, Multiple Assurance Levels

APP operates across a continuum.

The architecture does not require the highest level in order to provide value at the lowest.

01

Boundary Assurance

APP sees the interaction at the protected system.

02

Local Provenance

APP correlates local identity, policy and activity state.

03

Connected Assurance

External sockets contribute additional evidence.

04

Cross-System Provenance

Multiple independently controlled environments corroborate the same activity.

05

Independent Verification

A third party validates the evidence without relying on one provider as the complete source of truth.

From Observation to Assurance

APP operates across a simple lifecycle.

Each stage strengthens the evidence-backed view of the activity.

01

Observe

Receive relevant state at the points where agentic activity can be seen.

02

Identify

Establish the actor, origin and principal where the available evidence permits.

03

Verify

Evaluate the provenance, integrity and freshness of supplied evidence.

04

Correlate

Determine which observations belong to the same ongoing activity.

05

Evaluate

Apply local authority, policy, behavioural and risk controls.

06

Enforce

Where deployed in the execution path: allow, block, escalate or request additional evidence.

07

Preserve

Maintain the evidence-backed state of the activity as it changes.

08

Prove

Produce independently verifiable evidence of what APP actually observed and established.

Ask the Protocol

Ask the protocol a question

A generative oracle surface. Ask anything about agent provenance, delegated authority or independent evidence — answers are generated on demand and logged for review.

Why This Matters

The problem is not simply whether an agent has an identity.

It is whether an organisation can determine, at the moment an autonomous action matters:

01

What is known

02

What is not known

03

What has been independently verified

04

What is only being asserted

05

What authority exists

06

What policy applies

07

Whether the action should continue

08

And what evidence will remain afterward

APP provides that independent assurance layer.

The Role of the Sockets

APP maintains an extensible socket architecture.

These sockets strengthen APP's view of the activity. They are not required to create it.

AI agent runtimes
MCP
A2A
OpenAPI
OpenTelemetry
Enterprise identity
Policy systems
Cloud infrastructure
Exchanges
Payment systems
Wallets
Custody platforms
Quantum infrastructure
External tools and services
The APP Architecture

Four parts of one protocol.

01

APP Protocol

Defines how agentic state, provenance, evidence, interchange and verification are represented.

02

APP Runtime

Observes activity, maintains state, correlates events, evaluates policy and creates evidence.

03

APP Connectors

Integrate with external agent runtimes, tools, providers and execution systems.

04

APP Verifier

Validates APP evidence independently of the system that originally produced the activity.

The Core Principle

Protect first. Identify second. Trust progressively.

APP begins with what can actually be observed.

It strengthens assurance when stronger evidence becomes available.

It preserves uncertainty when it does not.

And it never claims more than its evidence can support.

INEVRI

Independent Assurance Infrastructure for Agentic Systems

APP — Agentic Provenance Protocol

A vendor-neutral protocol for maintaining an independent, evidence-backed view of autonomous activity as it moves across systems.

INEVRI

Independent Evidence Infrastructure for Autonomous Systems.

APP

Agentic Provenance Protocol — a vendor-neutral protocol for independent state provenance.

Third-party names referenced on this site are illustrative examples of relevant ecosystems and interoperability targets. No customer, partnership or integration relationship is implied unless expressly stated. APP is under active development; protocol contracts and implementations may change.

© 2026 INEVRI. Independent Evidence Infrastructure for Autonomous Systems.