Trace How Every Action Happened
When your CISO asks "how did that agent get access to our CRM?", Execution Lineage gives you the full chain in seconds: from the human who authorized it, through every delegation hop and policy decision, to the downstream resource.
The Reconstructability Gap
Authorization tells you if an action was permitted. Lineage tells you how it came to be.
The Missing Middle
You see the first request and the final API call. Everything in between is invisible. Delegation hops, policy decisions, and credential use are disconnected events.
Reconstruction Takes Hours
When an incident occurs, teams spend hours correlating timestamps across systems to reconstruct what happened. By the time the chain is assembled, the damage is done.
Compliance Cannot Prove Authorization
Auditors ask "who authorized this agent to access that system?" The answer requires forensic archaeology across logs, policy records, and delegation grants.
How It Works
A tree-structured audit model that connects every delegation hop, policy decision, and resource access into a single reconstructable chain.
Tree-Structured Audit Model
Every agent action is a node in a directed graph. Parent-child edges represent delegation. Each node carries execution identity, agent identity, declared intent, policy decision, and timestamp.
Cross-Boundary Propagation
Lineage context follows the chain across service boundaries automatically, so every hop is correlated without modifying the services in between.
Policy-Aware Context
Lineage attributes are available to the policy engine during evaluation. Policies can reference delegation depth, chain validity, intent category, and trust state.
Persistent Execution Graph
Executions are stored as a tree with parent-child references. Recursive queries reconstruct the full chain from any node. One execution ID returns the complete lineage.
Drift and Anomaly Detection That Acts
The lineage graph detects broken chains, denied-after-allowed-parent, deep delegation, unusual fan-out, and orphan executions. When an agent drifts from its declared plan, it is quarantined at machine speed, not queued as an alert.
Signed and Tamper-Evident
Lineage records are signed, hash-chained, append-only, and immutable once written. Server-authoritative fields are never trusted from client requests, so a chain cannot be forged or quietly edited.
The Agent Execution Graph
A queryable graph of every governed agent action, built from event streams as they flow through the runtime control plane.
Real-Time Visibility
See every agent action as it happens, with full governance context attached.
Forensic Reconstruction
Query by any execution ID to get the full chain back: every hop, every decision, every resource.
Drift Quarantine
Suspicious patterns surface automatically, and drift from a declared plan triggers quarantine, not just an alert.
Cross-Service Correlation
Events from proxy, policy engine, and agent frameworks correlated by a single execution ID.
Compliance Evidence
Every node carries identity, intent, authority, policy version, and timestamp.
Durable Event Stream
Append-only events with durable delivery and replay, so lineage is never lost or reordered.
Three Questions It Answers
For CISOs: "Who authorized that agent to access our CRM?"
The lineage chain shows the full path: Sarah Chen (analyst, authenticated via Okta SSO) delegated to the orchestrator, which sub-delegated a CRM query to the senior-researcher agent, authorized by the research-access policy under a DataAnalysis intent within the Q4 Research goal. Every hop audited. Full chain reconstructable from a single execution ID.
For Compliance: "Can we prove this action was authorized?"
Yes. The execution record links to the delegation grant (who delegated, what scope, when it expires), the policy evaluation (which policies were checked, which one decided), the intent declaration (why the agent claimed it needed access), and the goal (under what business objective). All persisted, all queryable, all immutable.
For Platform Teams: "How do I add lineage to my agents?"
Start with zero changes. The proxy correlates every request into an execution automatically. Delegation and intent context are added incrementally through the in-process plugin, and everything stays backward compatible.
Drift and Anomaly Detection That Acts
The lineage graph detects suspicious patterns in real time. Drift from a declared plan triggers quarantine at machine speed; the patterns below surface for review.
Broken chain
A step claims a parent that never authorized it
Denied after allowed parent
A sub-agent attempted something its parent was allowed to do but it was not
Deep delegation
A chain has grown further than policy expects
Unusual fan-out
One agent spawned far more helpers than its task warrants
Orphan execution
Activity with no authorizing decision behind it
Key Outcomes
Grounded in Governance Principles
Every capability traces back to the 12 non-negotiable principles for Agent Runtime Governance.
Common questions
What is execution lineage?
A tree-structured record of how every agent action happened: from the human who authorized it, through each delegation hop and policy decision, to the downstream resource it touched. Any chain can be reconstructed from a single execution ID.
Can execution lineage records be altered?
No. Lineage records are signed, hash-chained, append-only and immutable once written. Server-authoritative fields are never trusted from client requests, so a chain cannot be forged or quietly edited.
How do we add lineage without changing our agents?
Start with zero changes: the enforcement proxy correlates every request into an execution automatically. Delegation and intent context are added incrementally through the in-process plugin, and everything stays backward compatible.
Every Action Explainable. Every Chain Reconstructable.
Execution Lineage is the difference between "the AI accessed your CRM" and a complete, auditable chain of who authorized it, how it got there, and why.
Request a Demo