INEVRI develops APP, the Agentic Provenance Protocol. APP provides an independent assurance layer for agentic activity as it moves across tools, APIs, services and execution environments.
It does not depend on complete access to every system involved. Instead, APP establishes the strongest defensible view of an activity from the evidence available at each observation or enforcement point — and progressively strengthens that view as additional trusted evidence becomes available.
Agent & model platforms APP observes
Names shown are interoperability targets APP is designed to observe or enforce at — no customer, partnership or integration relationship is implied.
An agentic activity does not happen in one place. APP holds a live representation of it across every system it touches.
Who or what is acting
Who the activity is attributed to
What authority can be established
Which permissions and policies apply
What action is being attempted
Which systems are being accessed
What state is known at that moment
What changes as the activity progresses
What can and cannot be independently verified
Some systems expose detailed state. Some provide only an authenticated request. Some expose nothing beyond the interaction at their boundary. APP is designed for that reality — it never converts missing information into false certainty.
Verified
Independently corroborated by trusted evidence.
Asserted
Claimed by a participant, not independently confirmed.
Inferred
Derived from available signals, not directly observed.
Unresolved
Evidence is insufficient to establish the state.
Conflicted
Two trusted sources disagree; the conflict is preserved.
Stale
Established earlier; no longer guaranteed current.
Revoked
Previously valid authority that has been withdrawn.
Unavailable
No evidence is accessible at this observation point.
APP maintains an explicit distinction between these states, so an organisation can decide using the actual quality of evidence available at the moment an autonomous action occurs.
An unknown autonomous system approaches an API. That may already be enough to decide whether the activity should proceed, be rejected, or require additional verification.
APP does not need to understand the agent's entire internal architecture before protecting the system.
No single connector is required for APP to function. The assurance state becomes stronger as independently useful evidence accumulates.
Initially
APP can apply local policy using this state.
Verifiable authority presented
The agent presents organisational authority.
Runtime connector contributes
An agent-runtime socket adds evidence.
Execution provider returns
A deterministic execution reference arrives.
A single observation point can provide immediate protection and provenance. Additional sockets simply increase the amount of activity APP can independently corroborate.
More connectivity can produce stronger assurance.
Missing connectivity does not invalidate the state already established.
Each property can change independently. An agent can stay authenticated while its authority expires; a valid credential can coexist with unresolved delegated authority. APP preserves those distinctions.
This creates a much richer representation of autonomous activity than identity, authentication or transaction logging alone.
This is central to APP's independence.
If an agent's principal cannot be established, APP records the principal as unresolved.
If authority is claimed but cannot be independently verified, APP records it as asserted.
If two trusted systems provide conflicting state, APP preserves the conflict.
If an execution cannot be deterministically linked to an earlier request, APP does not present the relationship as proven.
The protocol preserves uncertainty rather than hiding it.
The same claim, backed by different evidence, is a fundamentally different thing. APP preserves that distinction throughout the activity.
Asserted
Delegated authority: Transfer up to $1,000,000
Source: Agent self-assertion
Status: ASSERTED
Verified
Delegated authority: Transfer up to $1,000,000
Source: Enterprise authority service
Evidence: Signed delegation
Status: VERIFIED
The same principle applies to identity, policy, execution, results and external state.
APP does not turn similarity into causation.
Deterministically Linked
A provider transaction carries the same signed identifier as the original agent request.
Corroborated
Two observations share multiple independent identifiers.
Probabilistically Correlated
Two records match only by time, value and context.
Unresolved
There is insufficient evidence to establish a link.
At an API, MCP server, service gateway or payment interface, APP evaluates the activity using the evidence available locally. The external agent does not need to run APP. The originating organisation does not need to expose its internal systems. The model provider does not need to participate.
Inside-Out increases the richness of provenance. It is not a prerequisite for Outside-In protection.
The architecture does not require the highest level in order to provide value at the lowest.
Boundary Assurance
APP sees the interaction at the protected system.
Local Provenance
APP correlates local identity, policy and activity state.
Connected Assurance
External sockets contribute additional evidence.
Cross-System Provenance
Multiple independently controlled environments corroborate the same activity.
Independent Verification
A third party validates the evidence without relying on one provider as the complete source of truth.
Each stage strengthens the evidence-backed view of the activity.
Receive relevant state at the points where agentic activity can be seen.
Establish the actor, origin and principal where the available evidence permits.
Evaluate the provenance, integrity and freshness of supplied evidence.
Determine which observations belong to the same ongoing activity.
Apply local authority, policy, behavioural and risk controls.
Where deployed in the execution path: allow, block, escalate or request additional evidence.
Maintain the evidence-backed state of the activity as it changes.
Produce independently verifiable evidence of what APP actually observed and established.
A generative oracle surface. Ask anything about agent provenance, delegated authority or independent evidence — answers are generated on demand and logged for review.
It is whether an organisation can determine, at the moment an autonomous action matters:
What is known
What is not known
What has been independently verified
What is only being asserted
What authority exists
What policy applies
Whether the action should continue
And what evidence will remain afterward
APP provides that independent assurance layer.
These sockets strengthen APP's view of the activity. They are not required to create it.
Defines how agentic state, provenance, evidence, interchange and verification are represented.
Observes activity, maintains state, correlates events, evaluates policy and creates evidence.
Integrate with external agent runtimes, tools, providers and execution systems.
Validates APP evidence independently of the system that originally produced the activity.
The Core Principle
APP begins with what can actually be observed.
It strengthens assurance when stronger evidence becomes available.
It preserves uncertainty when it does not.
And it never claims more than its evidence can support.
INEVRI
Independent Assurance Infrastructure for Agentic Systems
APP — Agentic Provenance Protocol
A vendor-neutral protocol for maintaining an independent, evidence-backed view of autonomous activity as it moves across systems.