Skip to main content

Provena

CI PyPI Downloads Python 3.10+ License: Apache 2.0 Code style: ruff Docs

Context governance for agentic AI systems.

Your AI agent just made a decision based on data from 6 different sources. Can you tell me which ones? Can you prove the data wasn't tampered with? Can you verify it was still current?

Provena adds tamper-evident audit trails to any AI agent's context pipeline — in 3 lines of Python.

from provena import ContextTrail

trail = ContextTrail()

@trail.track(source="retriever")
def search(query):
    return retriever.search(query)

Every call to search() is now logged with a SHA-256 content hash, provenance validation, and a hash-chained audit trail that detects tampering.

Why Provena?

AGT governs what agents DO. Guardrails AI governs what agents SAY. Provena governs what agents KNOW.

No existing tool governs the context input layer. Provena fills this gap with:

  • Tamper-evident audit trails — SHA-256 hash-chained (Merkle-style) logging with optional HMAC signing
  • Provenance validation — Verify that context carries proper source metadata (VALID / MISSING / INCOMPLETE)
  • Freshness checking — Detect stale context via metadata timestamps and regex temporal detection (FRESH / STALE / UNKNOWN)
  • Policy enforcement — Block, warn, or log governance violations with configurable rules
  • Multi-agent governance — Aggregate and query across multiple agent trails with handoff tracking
  • Any context source — RAG retrievers, tool outputs, agent messages, memory recalls, MCP resources
  • Sub-1ms overhead — Pure Python, no ML models, no downloads
  • Zero core dependencies — Core library uses only the Python standard library

Install

pip install provena                # core (zero dependencies)
pip install provena[cli]           # + CLI tools (click, rich)
pip install provena[otel]          # + OpenTelemetry export
pip install provena[postgres]      # + PostgreSQL backend
pip install provena[mcp]           # + MCP server for governance-aware agents
pip install provena[pdf]           # + PDF compliance reports
pip install provena[yaml]          # + YAML config file support
pip install provena[all]           # core + cli + otel + postgres + mcp + pdf + yaml

Framework adapters (install individually):

pip install provena[langchain]     # LangChain callback
pip install provena[llamaindex]    # LlamaIndex postprocessor
pip install provena[crewai]        # CrewAI event listener
pip install provena[autogen]       # AutoGen hook
pip install provena[openai-agents] # OpenAI Agents SDK hooks
pip install provena[google-adk]    # Google ADK callbacks

Quick Start

from provena import ContextTrail, ProvenanceMetadata
from datetime import datetime, timezone

trail = ContextTrail(storage_path="audit.db")

# Track any function that produces context
@trail.track(source="retriever")
def search(query):
    return retriever.search(query)

@trail.track(source="tool:pricing_api")
def get_price(product_id):
    return api.get(f"/price/{product_id}")

# Manual logging with provenance metadata
trail.log(
    content="The enterprise plan costs $499/month.",
    source="tool:pricing_api",
    provenance=ProvenanceMetadata(
        source_url="https://api.example.com/pricing",
        created_at=datetime.now(timezone.utc),
    ),
)

# Verify the audit trail hasn't been tampered with
verdict = trail.verify_chain()
print(f"Chain intact: {verdict.intact}")
print(f"Total records: {verdict.total_records}")

Policy Enforcement

Move from observe-only to enforce. Block stale or unverified context before it reaches the LLM:

from provena import ContextTrail, freshness_check, provenance_check, EnforcementLevel

trail = ContextTrail(
    storage_path="audit.db",
    policies=[
        provenance_check(status="MISSING", enforcement=EnforcementLevel.BLOCK),
        freshness_check(status="STALE", enforcement=EnforcementLevel.WARN),
    ],
)

Three enforcement levels: LOG (record only), WARN (callback + pass through), BLOCK (raise PolicyViolation). Blocked entries are still logged for compliance — the audit trail shows what was rejected and why.

Multi-Agent Governance

Aggregate governance across multiple agents with handoff tracking:

from provena import ContextTrail, TrailAggregator

researcher = ContextTrail(storage_path="researcher.db")
writer = ContextTrail(storage_path="writer.db")

agg = TrailAggregator()
agg.add(researcher, label="researcher")
agg.add(writer, label="writer")

# Record agent-to-agent handoffs
agg.record_handoff(from_label="researcher", to_label="writer", record_id=5)

# Query across all agents
summary = agg.summary()
gaps = agg.detect_gaps()  # find missing provenance, broken chains, unlinked handoffs

CLI

Install with pip install provena[cli], then:

# Verify hash chain integrity
provena --db audit.db verify
# PASS — Chain intact (42 records verified)

# Query the audit log
provena --db audit.db audit --source retriever --format json

# Generate a governance report
provena --db audit.db report --format text

# Quick summary
provena --db audit.db summary

# Retention management
provena --db audit.db retain --max-age 180 --dry-run

# Start MCP server for governance-aware agents
provena mcp serve --db audit.db

# Migrate between backends
provena migrate --from audit.db --to postgresql://localhost/provena

For HMAC-signed trails, pass --signing-key or set PROVENA_SIGNING_KEY.

Integrations

LangChain

from provena.integrations.langchain import ProvenaCallback

chain = RetrievalQA.from_chain_type(
    llm=llm,
    retriever=retriever,
    callbacks=[ProvenaCallback(trail=trail)],
)

LlamaIndex

from provena.integrations.llamaindex import ProvenaPostprocessor

query_engine = index.as_query_engine(
    node_postprocessors=[ProvenaPostprocessor(trail=trail)]
)

CrewAI

from provena.integrations.crewai import ProvenaCrewListener

listener = ProvenaCrewListener(trail=trail)
crew = Crew(agents=[...], tasks=[...])
crew.kickoff()

OpenAI Agents SDK

from provena.integrations.openai_agents import ProvenaRunHooks

result = Runner.run(agent, input="...", hooks=ProvenaRunHooks(trail))

OpenTelemetry

trail = ContextTrail(
    storage_path="audit.db",
    otel_enabled=True,
    otel_service_name="my-agent",
)
# Every log() call now emits an OTel span with governance attributes

Configuration Files

# TOML (zero dependencies on Python 3.11+)
trail = ContextTrail(config="provena.toml")

# YAML (requires provena[yaml])
trail = ContextTrail(config="trail.yaml")

Architecture

Your Application
|
|  Retriever ---+
|  Tool Call ---+
|  Agent Msg ---+---> ContextTrail ------> LLM Context Window
|  Memory    ---+        |
|  MCP       ---+        |
|                  +-----+----------------------+
|                  | ProvenanceValidator         |
|                  | FreshnessChecker            |
|                  | PolicyEngine (block/warn)   |
|                  | HashChain (SHA-256 / HMAC)  |
|                  | WriteBuffer (10K+ entries/s)|
|                  | SQLite / PostgreSQL Backend |
|                  | OTel Exporter              |
|                  +----------------------------+
|
|  TrailAggregator (multi-agent)
|  RetentionEngine (lifecycle)
|  ComplianceReport (EU AI Act / OWASP)
|  MCP Server (governance-aware agents)

Compliance

Provena maps directly to EU AI Act requirements:

Article Requirement Provena Feature
Art. 9 Risk management Policy engine with configurable enforcement
Art. 10 Data lineage Provenance validation for every context input
Art. 12 Tamper-evident logging SHA-256 hash-chained audit trail with HMAC signing
Art. 13 Transparency trail.summary(), source tracking, compliance reports
Art. 14 Human oversight trail.annotate() for reviewer decisions
Art. 26 Log retention Retention engine with 6-month minimum enforcement

Also addresses OWASP ASI06 (Memory & Context Poisoning).

Generate compliance reports: provena --db audit.db report --format pdf

See the full compliance documentation.

Documentation

Full documentation at rajfirke.github.io/provena — guides, API reference, integration docs, and compliance mapping.

Contributing

We welcome contributions! See CONTRIBUTING.md for development setup, architecture guide, and PR process.

Please read our Code of Conduct before participating.

License

Apache 2.0

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

provena-1.0.1.tar.gz (121.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

provena-1.0.1-py3-none-any.whl (57.4 kB view details)

Uploaded Python 3

File details

Details for the file provena-1.0.1.tar.gz.

File metadata

  • Download URL: provena-1.0.1.tar.gz
  • Upload date:
  • Size: 121.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for provena-1.0.1.tar.gz
Algorithm Hash digest
SHA256 ebd830d631320a510ea7ecbf8a4465e6dfbab553c23ceb98a48c25bb4fd57346
MD5 9eb48f7b478db0b01fc728992af05c7c
BLAKE2b-256 7f23a82a4196ae36f38f1e1c9c50e3d5e5793d1ba5eb9fce1fc60ff96e4af92f

See more details on using hashes here.

Provenance

The following attestation bundles were made for provena-1.0.1.tar.gz:

Publisher: publish.yml on rajfirke/provena

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file provena-1.0.1-py3-none-any.whl.

File metadata

  • Download URL: provena-1.0.1-py3-none-any.whl
  • Upload date:
  • Size: 57.4 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for provena-1.0.1-py3-none-any.whl
Algorithm Hash digest
SHA256 75821a526d156fe08cc7c34f9cc039cf496a83911b0f69d20d61748e2758c461
MD5 64d0584084ef0f77cbba535a8b4d8e6a
BLAKE2b-256 306f61c67b5c3d98623f55468b736472a72a409cbc31adb44b0f7db0d0929e63

See more details on using hashes here.

Provenance

The following attestation bundles were made for provena-1.0.1-py3-none-any.whl:

Publisher: publish.yml on rajfirke/provena

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

1.1.0

2 files

This release

1.0.1 This release

2 files

1.0.0

2 files

0.15.0

2 files

0.14.0

2 files

0.13.0

2 files

0.12.0

2 files

0.7.0

2 files

0.6.0

2 files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page