Mechanism
Each actuation event, defined as any commit by a governed actuator that produces a physical effect or an information-state change with operational consequence, records its complete provenance in the lineage field. The post-execution lineage recording captures the executed actuation, the observed effects, the verification outcome, and the broadcast event, and every actuation decision recorded in the lineage field references the governed observations upon which the decision was based. The lineage record is governance-chain-preserving: each referenced governed observation carries its own governance credentialing chain, so the lineage entry binds the action to the credentialed identity of the participant that committed it, to the policy authority under which it was admitted, and to the upstream observations that the composite admissibility evaluation actually consumed. Where a harm-minimization deviation occurred, the lineage records the deviation alongside the actuation determination; where an actuation was preempted, the preempted actuation is recorded with the complete preemption-provenance chain.
The lineage record is bound together as a tamper-evident, governance-chain-preserving chain. Each entry is chained to the records on which it depends, so that the lineage closes recursively from observation through decision to action to verified effect. Modification of any entry, or insertion of any entry between two existing entries, breaks the chain at the modification point and at every subsequent point, and chain verification detects the break. Because each entry carries the governance credentialing chain of the participant that produced it and of the observations it consumed, the lineage supports deterministic reconstruction of the actuation independent of any single platform's continued operation.
The lineage is not an after-the-fact reconstruction. It is generated synchronously with the actuation: the composite admissibility evaluation that gates the commit produces, as its byproduct, the provenance that the lineage records. The platform cannot commit without producing the entry, and cannot produce the entry without exposing the inputs the admissibility computation actually consumed. The architectural coupling is what makes the lineage reconstruction-grade rather than reconstruction-approximate. A tampering attempt that modifies the recorded inputs to make a refused commit appear admissible would either fail signature verification on the inputs themselves (because each input observation carries its own originating credential) or would expose the modified inputs to subsequent contradiction by peer platforms whose lineage records a different value for the same observation at the same instant.
Lineage entries are emitted to two storage targets concurrently: a platform-local store that admits append at the speed of the platform's commit cadence, and a substrate-broadcast emission that propagates the entry's hash and an authenticated digest onto the spatial mesh. The substrate emission ensures that even if the platform-local store is subsequently destroyed or tampered, the entry's hash is observed and stored by peer platforms within propagation range, providing an external corroboration surface that does not depend on operator-managed archival infrastructure. Authorities querying the substrate for a particular platform's recent activity can confirm the existence and ordering of the platform's lineage entries without holding the entries' contents, then request the contents through a credentialed retrieval if and when an inquiry warrants.
Each lineage entry is chained to the prior records on which it depends and references the governed observations the decision consumed, so that audit can walk the lineage from an actuation back through the observations that contributed to it and forward to the verified effect, without requiring the auditor to reconstruct cross-references from an external index.
Operating Parameters
Lineage entry size scales with the size of the credentialing references, the structured action descriptor, and the list of admissibility-input references the decision consumed; a simple actuation under stable governance records a smaller entry than a complex actuation drawing on many observations. Entries preserve byte-exact verifiability so that the chain can be re-verified independently of the platform that produced it.
Lineage emission is a byproduct of the composite admissibility evaluation that the entry transcribes, so recording the provenance adds little beyond the admissibility decision itself. The lineage record is produced as part of the actuation chain, with each step of the chain, observation, decision, action, and verified effect, recorded as it occurs.
Lineage retention is governance-policy-defined per deployment, rather than fixed at a single duration. Retention is enforced through the governance chain rather than by storage-management policy alone: the credentialing chain in the lineage references the retention obligation, and any retention-management agent attempting to delete an entry before the obligation expires must itself produce a credentialed authorization that the lineage records as a deletion entry preserving the deleted entry's reference.
Cross-recognition between issuing platforms and auditing authorities is governed through cross-authority taxonomy translation. An auditing authority operating under the issuing platform's credentialing context admits the lineage as evidence directly; an authority operating under a different credentialing context admits the lineage through a governance-credentialed boundary agent that translates the authority context, observation schemas, and applicable policies across the boundary. The translation is itself a credentialed observation distributed through the substrate, allowing recognition to evolve over operational time as new auditing authorities are credentialed.
Audit-query interfaces expose the lineage to credentialed inspectors through a structured query surface that supports walks across the chained records and privacy-tier-filtered disclosure of fields that the inspector's credential class permits. Query results carry their own credentialing chain, allowing the inspector to subsequently present the result as evidence in a downstream proceeding without requiring the issuing platform to be online at the time of presentation.
Alternative Embodiments
In a first alternative embodiment, the lineage chain integrity is monitored as a governance-chain-integrity property, so that any break introduced by rewriting an entry is detected on verification. Because each entry is governance-chain-preserving and references the credentialing chains of the participant and the consumed observations, the lineage supports deterministic reconstruction of the full chain that does not depend on the rewriting party's account of what occurred.
In a second alternative embodiment, the recorded provenance supports deterministic reconstruction of the admissibility decision, so that audit can re-execute the decision given the original governed observations. Reconstruction allows audit to verify not only that the recorded admission was issued but that the admission would issue again under the same inputs, supporting policy-evaluation reconstruction in which governance policies in force at the time are evaluated against counterfactual alternatives.
In a third alternative embodiment, the actuation-state broadcast to the mesh produces peer corroboration of the lineage record, so that governance-credentialed observations emitted by peer platforms within range record the actuation independently of the committing platform. The corroborating peer set reflects actual peer presence at commit time rather than an enumerated topology, and the broadcast record allows the lineage to be confirmed through the mesh even where the committing platform's own record is later unavailable.
In a fourth alternative embodiment, the lineage is disclosed through privacy-tier filtering before audit, with the filtering itself being governance-credentialed and verifiable. The auditor confirms that the redacted entries existed and were of the declared class, without having access to the entry contents that the redacting authority withheld. Selective redaction supports audit under regimes where some content is privileged (medical confidentiality, defense classification, trade secret) while preserving the integrity of the unredacted record. The redaction authority's credential is itself recorded in the lineage, allowing subsequent inquiry to challenge whether the redaction was authorized.
In a fifth alternative embodiment, the lineage is admitted across authority boundaries through taxonomy translation, so that an auditing authority operating under a different credentialing root can recognize and consume the lineage as evidence. Cross-authority interoperability preserves the governance-chain-preserving integrity of the record while allowing recognition to evolve as new auditing authorities are credentialed or existing roots are rotated.
In a sixth alternative embodiment, the recorded provenance is augmented with a counterfactual descriptor, a record of the action that would have been committed had the admissibility evaluation rejected the contemplated action. The counterfactual descriptor enables audit to evaluate not only what happened but what the platform would have done in the alternative, supporting analysis of the admissibility framework's behavior at decision boundaries.
Composition with Other Primitives
Lineage-recorded provenance composes with the credentialed-observation primitive: every governed observation referenced by an actuation decision is itself a credentialed lineage entry on the issuing platform, allowing audit to walk from an actuation back through the originating observations and from each observation back to the platform that emitted it. The transitive walk is what makes incident reconstruction structurally complete. An auditor investigating a downstream actuation can establish, without ambiguity, the full upstream evidentiary chain that contributed to the commit, including peer-platform observations, sensor readings, and authority broadcasts.
Composition with the reversibility-aware commitment-point primitive produces nested lineage: each commitment-point transit of a staged actuation is a lineage-recorded event, so the lineage records the stage beyond which continuation becomes irreversible and whether that point was transited. Audit reconstructs not only that the actuation occurred but that it advanced through the stages, with the graduated-actuation mode selector able to interrupt a staged actuation prior to the commitment point. Interruptions before an irreversible stage produce their own lineage entries, allowing audit to confirm not only what was committed but what was contemplated and not transited.
Composition with the harm-minimization deviation primitive records, on the same lineage entry, both the policy-conformant action that admissibility gated and the deviation the platform actually committed, together with the credential under which the deviation was authorized. The dual record allows audit to assess not only whether the deviation was authorized but whether the authorization itself was admissible. The deviation credential's chain is recorded inline, allowing the auditor to evaluate the credential's own validity at the time of commit without requiring an external lookup.
Composition with the policy-distribution primitive produces a closed audit loop: the policy in force at the time of an actuation is referenced in the actuation's lineage; the policy's admission on the platform is itself a lineage entry; the policy's issuance is a lineage entry on the issuing authority. Audit walking the loop confirms that the policy actually in force at commit time was the policy the issuing authority intended to be in force, eliminating the configuration-drift gap that plagues conventional governance audit.
Distinction over Prior Art
Conventional architectures produce platform-internal log records with platform-operator-determined retention. The records capture what the system did but do not capture the architectural authority under which it did so, and they are not bound through a governance chain to the authority that admitted the action. Reconstruction of authority then requires reconciliation across separate records that are not cryptographically bound to the operational record. The disclosed lineage subsumes both the operational record and the authority record within a single governance-chain-preserving, tamper-evident record, eliminating that reconciliation requirement.
Conventional physical-state recorders record a fixed inventory of physical-state parameters with tamper resistance but no architectural-authority field. The recorders answer the question of what the platform did but not the question of under what authority it did so. The disclosed mechanism preserves the physical-state record while extending it with the authority record that regulatory and judicial inquiry actually requires.
Conventional information-technology audit trails record authority but in a substrate disjoint from the operational substrate, requiring reconciliation to establish that a recorded change actually took effect operationally. The disclosed lineage is structurally one governance-chain-preserving substrate, eliminating the reconciliation gap. A change recorded in lineage is by construction a change that took effect; a change that purports to have occurred without a lineage entry did not occur.
Conventional provenance frameworks describe provenance as an annotation layer over data artifacts, applied retrospectively for documentation. The disclosed mechanism applies provenance synchronously at the point of action and binds the provenance through the governance chain to the action's commit, producing a record whose integrity does not depend on a curator's continued availability or an annotation system's operational state.
Disclosure Scope
This disclosure is described in U.S. Provisional Application No. 64/049,409. The disclosure encompasses the lineage record of complete actuation provenance; the tamper-evident, governance-chain-preserving chaining; the synchronous emission coupled to the composite admissibility evaluation; the alternative embodiments described above; the cross-authority recognition governing audit admission; and the composition with the credentialed-observation, reversibility-aware commitment-point, harm-minimization-deviation, and policy-distribution primitives. The scope extends to lineage emission by platforms operating in vehicular, aviation, maritime, surgical, industrial-process-control, and defense deployment classes, and to consumption of the lineage by regulatory authorities, judicial proceedings, fleet-operator audit, and insurance-risk analysis. The scope further extends to lineage retention regimes ranging from short-window operational retention to long-window regulatory retention, and to hybrid embodiments in which platforms emit lineage through the disclosed substrate while continuing to emit conventional engineering telemetry through legacy channels for backward compatibility with existing analysis tooling.