# Evidence and provenance

> Evidence and provenance is the practice of keeping observations distinguishable from the conclusions drawn about them, with an unbroken, checkable path from what was observed to what was decided.

Category: Systems
Also searched as: chain of custody, audit trail, data provenance
Source: Mediator Solutions — https://mediatorsolutions.io/learn/#evidence-and-provenance
License: free to read, learn, cite, and apply, with attribution to Mediator Solutions.

## What it is

When observed facts and the conclusions drawn from them blur together, a record cannot be trusted or reconstructed. Evidence and provenance keeps them distinct: raw observations stay separable from derived state, and every consequential step leaves a signed, reconstructible record so the path from detection to decision can be walked again.

## Why it matters

When observation and conclusion blur, a record cannot be reconstructed or trusted, and the first hard question from an adversary collapses it. Provenance is the unbroken, checkable path from what was seen to what was decided. The expensive version of getting this wrong is the finding that was probably right but cannot be shown to be — thrown out not because it was false but because its custody could not survive scrutiny. The discipline is to keep observation separable from interpretation at the moment of capture, when it is cheap, rather than trying to reconstruct it later, when it is impossible.

## When to use it

- Capturing an observation that may later support a finding or a decision.
- Any investigation, audit, or claim that an adversary may later contest.
- When observation and interpretation are at risk of being recorded as one thing.

## Principles

- Observed records stay distinguishable from the conclusions drawn about them.
- Every consequential action leaves a signed, reconstructible record.
- Provenance travels with the result, so the path can be re-walked by someone else.
- Receipts are evidence produced by the work, not the purpose of the work.

## Practice

1. Separate raw observation from derived conclusion at capture time.
2. Hash and sign consequential records so tampering is detectable.
3. Keep the path from observation to decision explicit and ordered.
4. Hand the provenance to the result, so it can be verified downstream.

## Where it fails

- **Observation-conclusion blur** — What was seen and what was concluded are captured together, so the finding cannot be reconstructed and collapses under the first hostile question.
- **Broken custody** — A handling step goes unrecorded, so the path from evidence to finding has a gap an adversary can drive through.
- **Right-but-unusable finding** — The conclusion was correct but its custody cannot be shown, so it is thrown out — not for being false, but for being unprovable.

## In practice

An analyst notices an anomaly and writes down the conclusion. Months later it is challenged and there is nothing behind it. The disciplined capture separates the two at the moment of observation: the raw observation with its source and timestamp, kept distinct from the interpretation, with every handling step logged. When the challenge comes, the path from what was seen to what was concluded can be walked by the adversary without trusting the analyst — which is the only kind of finding that survives.

## Verification

An independent reviewer can trace any conclusion back to its observations through a signed, ordered record, without trusting the party that produced it.

## Reference

### Every dataset should answer

- Where did it come from?
- When was it captured?
- Who captured it?
- What changed it?
- What is its current version?
- What is its allowed use?
- What confidence does it carry?

### Check before use

- Freshness
- Completeness
- Duplication
- Contradiction
- Source authority
- Bias
- Missing context
- Transformation error

---

Previous: https://mediatorsolutions.io/learn/#deterministic-state
Next: https://mediatorsolutions.io/learn/#saturation-discipline
