Evidence Graph & Provenance Ledger
About this pattern
This is a generated FPF pattern page projected from the published FPF source. It is canonical FPF content for this ID; it is not a FPF Reference product feature page.
How to use this pattern
Read the ID, status, type, and normativity first. Use the content for exact wording, the relations for adjacent concepts, and citations to keep active work grounded without pasting the whole specification.
Type: Evidence and provenance pattern Status: Stable Normativity: Normative where conformance rows say so; examples and SoTA rows are informative guidance.
Use this pattern when a later user must cite, replay, audit, or refresh a path through several already established objects and relations rather than repeat their complete source account.
Keywords
- EvidenceGraph
- PathId
- PathSliceId
- PathCitationRecord
- provenance ledger
- exact represented objects
- exact direct relations
- direct governors
- obtaining claims
- unresolved gaps
- NotCarried
- source/currentness
- representation correspondence
- downstream work
- actual-use relation
- local refresh.
Relations
Content
Problem Frame
Use this pattern when a later user must cite, replay, audit, or refresh a path through several already established objects and relations rather than repeat their complete source account.
Use it when the working question is:
- which dated work occurrences, role assignments, actual participants or bindings, produced entities, domain results, result epistemes, outcomes, source publications, carriers, and provenance relations must remain addressable;
- which exact direct relations connect those objects, which pattern governs each relation, and whether each relation is already established as obtaining;
- which bounded context, reference plane, time window, bridge, edition, policy, source-currentness result, or reliance boundary limits the cited path;
- which downstream work and exact use relation may cite the path; and
- what stronger conclusion, assurance, permission, acceptance, gate passage, or decision the path does not carry.
Primary EntityOfConcern. The primary EntityOfConcern is an addressable provenance representation: one EvidenceGraph, its PathId or PathSliceId, and any ledger entry that makes the path replayable. G.6 governs path identity, slicing, citation, and local refresh. It does not create the represented work, participation, production, result, episteme, outcome, source, currentness, reliance, or representation correspondence.
First useful move. Name the relied-on claim or bounded use, then list the exact object refs and direct relation refs needed to replay it. For every relation record its direct governor and obtaining claim. Only then draw the path. Keep an unresolved relation as a gap; do not turn it into a graph edge asserted as obtaining.
What goes wrong if missed. A tidy graph makes an unperformed method look like work, a co-listed actor look like a participant, a carrier look like a produced result, a measurement or verdict look like generic evidence, or a provenance edge look like the world-side relation itself.
What this buys. Downstream work can cite one stable path while a reviewer can still recover the exact work, participants, products, subject results, result epistemes, sources, direct relations, currentness, and bounded use that the path represents.
Not this pattern when. Use A.2.4 for the first evidence-use or status-use classification, A.10 for source recovery and bounded reliance, A.15.1 and A.6.1 for performed work and actual bindings, A.15.PROD when production or inception is current, the exact domain pattern for its local result, C.2.1 for the result episteme, G.11 for currentness, C.29 for representation correspondence, and B.3 for assurance. If only one local source-to-use statement is needed, stay in A.10.
Here path means a path in a descriptive provenance graph. It is not an action route, method, workflow, transformation flow, universal evidence relation, or generic work-result relation.
Problem
Large projects often need to cite a chain that crosses measurement, evaluation, aggregation, production, publication, and later use. The chain becomes unsafe when the graph is allowed to supply facts missing from the governed objects.
The common failures are:
- Edge-to-fact inversion. A drawn edge is treated as proof that work, participation, production, measurement, evaluation, or use occurred.
- Generic relation fallback. Labels such as
verifiedBy,validatedBy,measuredBy,producedByWork, orevidencesreplace the exact direct relation and its governor. - Result collapse. Subject result, result episteme, carrier, outcome, assurance, and later decision become one generic result node.
- Declaration-to-runtime collapse. A
MethodDescription, operation signature, policy, clause, or plan is read as an actual run and its bindings. - Hidden crossing. A path silently crosses context, reference plane, edition, source order, or currentness window.
- Refresh fanout. One changed source or relation forces a global rerun because the smallest affected path slice cannot be found.
Forces
Solution — cite independently governed objects and relations
Create an EvidenceGraph only after the relied-on claim or bounded use and its supporting objects have been recovered. The graph is a declarative, addressable representation. Each node record cites one independently governed object; each asserted edge record cites one independently established direct relation. PathId, PathSliceId, and the provenance ledger add citation and refresh locality, not world-side facts.
Direct-owner map
G.6 does not substitute for any row. If the direct owner or relation cannot be recovered, the path records an unresolved gap and cannot present that edge as obtaining.
Do not add a local U.EvidenceRole or turn proof, measurement, benchmark, source, or status labels into roles. A producer, verifier, laboratory, issuer, or maintainer participates only through an independently established work-facing role assignment and exact work relation.
EvidenceGraph as a representation
An EvidenceGraph is a typed directed graph used for provenance citation and replay. It may project a dependency-closed slice of independently governed objects and relations. It is not a holarchy, work plan, method, transformation flow, result algebra, or proof that its contents obtain.
Minimal graph fields:
A node record is a projection, not a new universal object kind:
The node set may cite exact work occurrences, role assignments, actual bindings, produced entities, measurement or other subject results, evaluation or aggregation results, C.2.1 result epistemes, outcomes, source publications, carriers, currentness results, reliance dispositions, and later work. Co-listing creates no relation among them.
An asserted edge is also a projection:
Before the edge enters a relied-on path, the exact direct relation must already be established under its governor. The participant refs in the edge must match that relation; adjacency, direction, shared identifiers, timestamps, source order, or visual layout cannot supply them. RepresentationRef points outward to the applicable C.29 correspondence when that correspondence is current.
G.6 defines no fallback core edge vocabulary. Legacy or display labels such as verifiedBy, validatedBy, measuredBy, producedByWork, derivedFrom, usesMethodDescription, citesSource, or evidences are navigation prompts only. Replace each with the exact formal, measurement, work, production, publication, representation, provenance, temporal, status-use, premise, reference, argument, or other direct relation before asserting the edge as obtaining.
PathId and PathSliceId
A PathId identifies one claim-local path inside an EvidenceGraph. A PathSliceId identifies the same path under a declared time window, reference plane, bounded context, edition, bridge, policy, or selected object/relation subset.
Use this compact record:
NotCarried names every stronger use that the path does not establish: work occurrence, participation, production, claim truth, assurance, approval, permission, gate passage, release, causal identification, benchmark superiority, acceptance, or decision. Actual downstream use requires dated work and one exact premise, reference, operation-argument, decision-use, or other direct relation; path availability or citation is not actual use.
Provenance ledger
A ProvenanceLedger is a citable replay index over PathCitationRecord entries. It is not a work-progress log, result registry, review-comment log, process-status log, or ontic source.
The ledger may cite work, participants, produced entities, domain results, result epistemes, outcomes, sources, transformations, representation correspondences, provenance, and later uses. A row establishes none of them. Use a ledger when several downstream consumers need the same path family; do not create one merely because a local A.10 account is easy to write.
Refresh and source return
Reopen the smallest affected PathId, PathSliceId, node projection, or relation-edge projection when any cited object, direct relation, governor, source, bridge, representation correspondence, edition, policy, time window, currentness result, or reliance boundary changes.
If the direct relation no longer obtains or its proof becomes unavailable, remove it from the relied-on path or mark the exact unresolved gap. Do not preserve the edge from graph history, infer a replacement relation, rerun unrelated paths, or certify a new downstream result through refresh alone.
Declarative representation discipline
EvidenceGraph, PathId, PathSliceId, and ProvenanceLedger tell a reader which already governed account is being cited. They do not tell a worker what to do and they do not reconstruct missing world-side facts.
Extension wiring without core drift
Selector, benchmark, assurance, refresh, or telemetry patterns may require additional pins in PathCitationRecord. They may cite PathId or PathSliceId, but they do not mint a universal edge, result, evidence, or criterion-participant relation. Any added graph record still names the exact represented object or direct relation and its governor.
G.5 may cite a path for selector explanation, G.9 for benchmark replication, G.11 for local refresh, and B.3 for an assurance input. Their selection, benchmark, currentness, and assurance results remain their own.
Archetypal Grounding
Measurement, acceptance, and decision
C.16 dated measurement work binds the pressure measurand, detector, calibration, model, input quantities, and uncertainty propagation and obtains a pressure measurement result. A distinct C.2.1 episteme states that result. Later G.4 EvaluationWork applies one declared acceptance clause through exact A.6.1 bindings and obtains unknown; another C.2.1 episteme states that verdict. Later C.11 decision work uses the verdict episteme through an exact premise relation and defers.
G.6 may give this chain one PathId only after the measurement, work, binding, result, episteme, clause-application, premise, and decision relations are independently established. Its nodes keep raw detector output, indication, actual pressure, measurement result, verdict, and decision distinct. Its edges cite the exact relations; none produces the work, verdict, or decision.
Resource aggregation
An engine programme has several C.16 resource measurements, dated test-run work occurrences, exact phase and overlap relations, and a shared warm-up allocation rule. B.1.6 dated aggregation work applies ProgrammeResourcePolicy-v3 and obtains a typed resource vector with propagated uncertainty; a distinct C.2.1 episteme states it.
The G.6 path cites every measurement result and episteme, the work-set and overlap relations, the edition-pinned policy, aggregation work, aggregation result, sources, and representation refs. The ledger does not make epoch labels into work parts, allocate the warm-up energy, perform uncertainty propagation, or turn the aggregate into an emissions verdict.
Produced model and benchmark use
Dated training work has exact actual bindings and, when the production claim is current, an A.15.PROD-governed relation to one produced model edition. Separate benchmark-evaluation work applies its declared method and dataset edition and obtains a result under the benchmark's direct governor; a C.2.1 episteme states that result. A source publication and model card expose selected claims under E.17/C.29 relations. G.11 supplies currentness when later use depends on edition or freshness.
A G.6 PathSliceId may cite that dependency chain for replication. The graph does not infer training from the model's presence, participation from a roster, evaluation from the protocol, superiority from the score, or deployment permission from the model card.
Dashboard status cue
A dashboard cell shows Ready. F.10 governs the status-use classification; A.10 recovers the source, query work, provenance, currentness, bounded reliance, and rival explanation. G.6 is entered only when a downstream audit or release package needs a stable path through those already established relations. The visible cue, graph path, and ledger row establish neither gate passage nor release.
Bias-Annotation
Conformance Checklist
Common Anti-Patterns and How to Avoid Them
Consequences
Benefits:
- downstream records cite evidence-provenance paths without copying evidence tables;
- source, bridge, policy, edition, and time changes reopen the smallest path slice;
- evidence, assurance, causal use, status, gate, work, and publication claims stay in their governing patterns;
- provenance becomes replayable and privacy-minimizable through scoped refs.
Costs:
- path identity, node typing, and source-currentness refs add overhead;
- graph paths can look like routes unless declarative representation discipline is kept visible;
- users must resist treating one complete path as a complete downstream decision.
Rationale
A.10 recovers one relied-on claim, its source/provenance account, and bounded reliance. G.6 adds stable graph-path identity, slicing, shared citation, and path-local refresh when several downstream consumers need the same dependency-closed representation.
That representational gain does not justify a second ontology of evidence edges. Work, participants, products, subject results, result epistemes, outcomes, sources, provenance, currentness, and later uses already have direct governors. G.6 therefore projects their exact refs and direct relations, and C.29 governs the representation correspondence when current. This makes a complex chain readable without allowing graph topology to create facts.
The ledger is likewise an index over established provenance, not a result store or process log. Missing relation evidence remains a visible gap; it is never repaired by drawing a more persuasive path.
SoTA-Echoing
Source qualification was checked against the publishers' current surfaces on 2026-07-30. These decisions remain qualified through 2027-07-30 unless a new Recommendation, specification edition, maintenance status, or replacement changes the adopted contract earlier. Internal FPF neighbour authority stays in Relations; it is not presented as an external source decision.
Source refresh is local: replay the changed row's named record fields, rule or case, and checklist rows first. Widen only when that replay contradicts another current G.6 locus; a changed source cannot by itself create a represented object, obtaining relation, work occurrence, result, currentness, reliance, assurance, permission, or decision.
Relations
- Builds on:
A.10for source recovery, provenance, bounded reliance, and graph-edge discipline;A.2.4for first-use evidence/status classification;C.2.1for claim and result epistemes;C.29for representation correspondence. - Coordinates with:
A.15.1,A.2.1, andA.6.1for dated work, role assignment, and actual bindings;A.15.PRODfor production/inception when current;C.16for measurement results;G.4for runtime evaluation results;B.1.6for work-resource aggregation results;C.28for causal use;F.10for status use;F.9for bridge and loss;E.18/E.18.2for transformation-flow structure;G.11for currentness;B.3for assurance;E.17for publication; and every exact formal, diagnostic, conformance, comparison, selection, acceptance, gate, permission, commitment, or decision owner cited by a path. - Used by: selector, benchmark, replication, audit, refresh, assurance, maturity, and release patterns that need stable provenance-path citation, including
G.5,G.9, andG.11. - Does not govern: any represented work occurrence, participation, production, local result, result episteme, outcome, source publication, representation correspondence, currentness result, assurance, later use, or stronger conclusion named in
NotCarried.
G.6:End
Last Updated: 2026-08-04 — upstream FPF commit 8b727cba (github.com/ailev/FPF)