Trust, in writing.
In work where the objects are irreplaceable and the records are the product, governance is a feature. This page publishes the rules Provenance's AI is bound by, the Operations Adviser System Card, alongside the platform's broader posture: propose→approve everywhere, an append-only audit trail, per-workspace isolation, and a hard not-advice boundary.
The platform's posture
- Propose → approve. Assistants propose; a person approves. Anything that touches money or custody waits for you, and every applied action is logged and reversible.
- Append-only audit trail. Field-level history on assets, jobs, invoices, quotes, and clients, who changed what, before and after, with a no-mutate guard.
- Workspace isolation. Row-level security scopes every query to your workspace; there are no cross-tenant views of prices, rates, or wages.
- Your data is yours. Encrypted, exportable as CSV at any time, and erasable: whole-workspace deletion removes everything, including AI records.
- Not advice, by design. Provenance documents your own records. It never gives valuation, appraisal, insurance, or legal advice, it builds the file your broker and appraiser work from.
Operations Adviser. System Card
What it is
An operations adviser inside Provenance. It reads the workspace's own business data (jobs, invoices, quotes, expenses, assets, valuations, storage, custody, contractors, customers), computes deterministic findings, answers natural-language data questions through a governed query layer, and writes a nightly business brief. Language models phrase answers and briefs; all arithmetic is deterministic, and every recommendation renders its math on demand.
Architecture, how the guarantees are enforced
- The model never writes SQL. It emits a query plan validated against a semantic catalog and compiled inside the database with a hard column allow-list, scoped to the workspace and row-capped.
- Sensitive data is unreachable, not blocked. SSNs/TINs, bank details, tokens, signatures, document contents, free-text notes, and per-person payroll are absent from the catalog, no query plan can reference them.
- Personal names are pseudonymized before anything enters a model prompt; real names render only client-side to the authorized user.
- Propose → approve everywhere. Model output becomes a state change only through typed, validated actions the app applies after its own permission checks. There is no direct write path from a model to the database.
- People-adjacent outputs are never autopilot-eligible in any mode, flagged at the engine level, enforced in schema and app code.
- Untrusted content is data, never instructions. Third-party text is wrapped in data envelopes; instruction-shaped content inside it is flagged and logged, never executed.
- Full-loop logging. Every executed query, brief, refusal, block, and applied action lands in an append-only event log with a purge guard.
Intended uses
Business analytics on the tenant's own data · contractor-vs-in-house economics (aggregate) · feature-adoption suggestions · anomaly surfacing (duplicate invoices, spend spikes, stale valuations) · compliance deadlines (insurance and policy expiry, storage billing stalls, quote expiry, AR aging) · marketing channel economics · deterministic what-if scenarios · scheduled reporting.
Prohibited uses, enforced in software
- No adverse-action recommendations about named individuals, termination, discipline, demotion, targeted hour or pay cuts, or "worst performer" framing. A classifier blocks and logs attempts; per-person performance data is pseudonymized or aggregated before any model sees it.
- No candidate screening. No such feature exists, and none ships without an independent bias audit first.
- No employee-to-contractor conversion advice. Contractor-to-employee break-even math only; classification questions deflect to a professional.
- No cross-tenant benchmarking of prices, rates, or wages. Workspace isolation is structural; no cross-tenant aggregate views exist.
- No protected-class data or proxies in any model input or deterministic feature.
- No people-adjacent features for EU-established tenants, hard-refused by country, not warned.
- No consumer reports or background-check data. Such documents are outside the reachable data entirely.
Human oversight
Decisions stay with people: every suggestion is an input to your judgment, and each recommendation's "show the math" view is the authoritative basis. A master toggle in Settings disables people-adjacent economics entirely. Adverse decisions affecting a person must be made and communicated by a person, the product offers no automation for them.
Data
The Adviser reads operational business records the tenant already stores in Provenance, financial aggregates, and pseudonymized name handles. Model provider: Anthropic (Claude), called with zero-training API defaults, no tenant data is used to train models.
Records & retention
Every people-adjacent recommendation and event is retained at least four years and is exportable from Settings as a decision log. The broader audit trail retains seven years. Adviser records participate in whole-workspace erasure.
Known limitations
- Deterministic detectors use fixed thresholds; they can miss edge cases or over-flag businesses with sparse data.
- Model phrasing can be imprecise even over correct numbers, the math and table views are authoritative.
- The adverse-output classifier is lexicon-based; outputs are sampled monthly and misses feed the lexicon.
- Query answers cover the cataloged entities only; the Adviser refuses questions outside the catalog rather than guessing.
Flat monthly plans from $59, a 30-day money-back guarantee, and your first workspace ready in minutes.
Open your workspace
Provenance