?
“Why did the agent do that?”
Logs often miss context, approver, and prior codebase state.

Provenance
Approver, brief, model, and diff on one audit trail.
The category
Git blame stops at the commit. Provenance answers who approved, which brief, which context, and which model produced the change, as a signed record.
Every agent run snapshots brief, context blocks, codebase state, and the approving human.
Model ID, version, and parameters recorded.
Each diff line mapped to the agent step that produced it.
Append-only, signed records you can query, replay, and export.

The gap
Boards, auditors, and clients ask who is accountable for what the AI did. Most tooling cannot answer.
?
Logs often miss context, approver, and prior codebase state.
EU AI Act
EU AI Act, NIST AI RMF, ISO 42001.
Liability
Provenance gives root cause instead of blaming whoever was on call.
Stale
It misses prompt, brief, context, model version, and approval chain.
A typed, queryable, append-only record of how the work came to be.
Named human approval with role, timestamp, and SSO identity.
Stays in the workspace with plan and checks
Versioned brief or ticket snapshot you can replay after later edits.
Stays in the workspace with plan and checks
Context blocks, retrieved files, and meeting snippets as a graph.
Stays in the workspace with plan and checks
Provider, model ID, version, temperature, and overrides.
Stays in the workspace with plan and checks
Each line mapped to the agent step that produced it.
Stays in the workspace with plan and checks
Overrides captured with reviewer rationale.
Stays in the workspace with plan and checks
Append-only storage with cryptographic signatures.
Stays in the workspace with plan and checks
Query by path, quarter, or context block. Real query layer.
Stays in the workspace with plan and checks
Arvad sits where the thread keeps the plan, staging, spend, and checks.
| Capability | Standard audit logs | Arvad provenance |
|---|---|---|
| Captured granularity | API calls | Agent decisions, approvals, context |
| Human approval | Maybe | Required, named, SSO-bound |
| Brief at time of run | Not captured | Versioned snapshot |
| Context graph | None | Every block, every file |
| Model version | Sometimes | Always, with parameters |
| Tamper-evident | Depends on infra | Signed, append-only |
| Queryable | grep | Real query layer |
| Mapped to controls | Manual | Mapped toward SOC 2, ISO 42001, EU AI Act |
Every agent run is wrapped, signed, and stored. Replay any decision or export the bundle.
Every agent run is wrapped, signed, and stored. Replay any decision or export the bundle.
EU AI Act
Article 12, record-keeping
Supports traceable, automatically generated logs for AI-mediated changes.
SOC 2
CC7, CC8 controls mapped
Change evidence auditors can review, not screenshots.
ISO 42001
AI management system aligned
Supports transparency and traceability controls until certified.
Limits stated plainly. No demo theater.
One question
If you cannot, you still have a chat log. Arvad keeps that work in one workspace.
Keep exploring
Brief, context, approval, diff, and model on one trail.