Skip to content

SOVEREIGNPROVENANCE

Version 2.2 · Published 2026-09-17

A Non-Tokenized Provenance Protocol for the
Genesis Era of AI

Modern Ancients LLC

OutlineTap to jump
  1. SOVEREIGN\\PROVENANCE
  2. An Interoperable Lineage Protocol — Non-Tokenized, Rights-Aware, Trace-Priced
  3. Abstract
  4. I. Thesis
  5. The Genesis Era
  6. What Provenance Is Not
  7. The Missing Layer
  8. Protocol Landscape
  9. When the Protocol Applies
  10. Object Biography
  11. From Output-Priced to Trace-Priced Economies
  12. II. Ontology
  13. Material Layer
  14. Protocol Layer — Anchor
  15. Passport lineage fields
  16. Experience Layer
  17. Participation Layer — Human-Centered Provenance (HCP)
  18. Institutional Layer
  19. Economic Layer — Two Connected Systems
  20. III. Invariants
  21. Protocol Principles
  22. System Ethos
  23. HCP Foundational Rule
  24. What the Protocol Never Does
  25. IV. Architecture
  26. Interoperability Stack
  27. Layered Stack
  28. Rights and AI Authorization
  29. Public Proof vs Protected Content
  30. Runtime vs Publication Provenance
  31. Sovereign Zones
  32. HCP and Mission Implementation
  33. V. Economics
  34. Markets Determine Value
  35. Trace Formalism
  36. R-Function and Signals
  37. HCP Value States
  38. Value Dimensions
  39. Cooperative Allocation
  40. VI. Governance and Sovereignty
  41. Protocol Governance
  42. Cultural Protocols
  43. VII. Vision
  44. VIII. Conclusion
  45. Appendices
  46. A.1 Artifact Formats
  47. Manifest
  48. Passport
  49. Seal
  50. A.2 Cryptographic Specifications
  51. A.3 Ledger Event Types
  52. A.4 Glossary
  53. Accord
  54. Allocation Decision
  55. Auditor
  56. Capsule
  57. Contribution Receipt
  58. Decision Accounting
  59. Dependency Claim
  60. Demand Credential
  61. Economic Parameters Charter
  62. Economic Pool
  63. economic.snapshot
  64. Economic Signal
  65. Guardian Node
  66. Innovation Docket
  67. Interoperable Lineage Protocol
  68. Lineage DAG
  69. Lineage Fields
  70. Manifest
  71. Mirror Cycle
  72. Mirror Watch
  73. Mission Provenance
  74. Net Value Statement
  75. Obligation Passport
  76. Opening Position
  77. Passport
  78. Policy Pack
  79. Preservation-to-Discovery
  80. Proof Card
  81. Provenance Bar
  82. Purpose Covenant
  83. Regenerative Capacity
  84. Repository Stewardship
  85. RoleGrant
  86. Seal
  87. Settlement Receipt
  88. Sovereign Alloy / Tourmaline Core / Transmission Field
  89. Sovereign Identity
  90. Sovereign Zone
  91. SP Synthetic
  92. Trace
  93. Trace Valuation Engine (TVE)
  94. Trace Value
  95. Value Event
  96. VentureCell
  97. A.5 Architecture Decision Records
  98. A.6 Reference Documentation
  99. Version History
  100. Version 2.2 (2026-09-17) — Lineage protocol thesis
  101. Version 2.1 (2026-09-05) — Ontology refresh
  102. Version 2.0 (2026-08-03) — Structural rewrite
  103. Version 1.4 (2026-08-03)
  104. Version 1.2 (2026-02-21)
  105. Version 1.1 (2026-02-21)
  106. Version 1.0 (2025-01-15)

SOVEREIGN\PROVENANCE

An Interoperable Lineage Protocol — Non-Tokenized, Rights-Aware, Trace-Priced

Modern Ancients LLC

Version 2.2 — 2026


Abstract

SOVEREIGN\PROVENANCE is an interoperable lineage protocol. It preserves inheritance, contribution, transformation, and stewardship as artifacts move between people, machines, organizations, and systems—without blockchain tokens or proof-of-work consensus.

Category. Interoperable lineage protocol. Function. Continuity through change: every artifact can carry a biography that other protocols can evidence and none of them currently own. Philosophy. Contribution can remain visible without requiring creation to become possession.

The protocol does not replace the internet’s existing primitives. Identity, authenticity, storage, federation, credentials, and ledgers already answer their own questions. SOVEREIGN\PROVENANCE sits among them and owns the missing semantic layer: lineage. Native engines—Identity, Seal, Passport, Accord, Ledger, Guardian—are adapters and anchors, not replacements. A deployment may mint a sovereign identity or bind a DID; merkle-anchor events natively or commit hashes to an external timestamping service. The protocol owns the lineage graph either way.

Provenance is stacked: runtime events record what happened at operational volume; critical checkpoints and authorizations fail closed; publication exports a curated proof bundle; public proof commits hashes without exposing protected content. Accords authorize rights and consent. Policy Packs evaluate records against readiness criteria and never mutate source data.

The same four protocol functions—RECORD, AUTHORIZE, CONSTRAIN, VERIFY—compose a six-layer system (material, protocol, experience, participation, institutional, economic) specified in Part II. Applied to organizational decisions they constitute decision accounting: the provenance protocol that powers a Responsible Intelligence Operating System. That category message is for buyers; this document is the constitution of the protocol underneath it.

This document establishes the conceptual, mathematical, and architectural foundations that define SOVEREIGN\PROVENANCE as a system. Implementation detail—API endpoints, SDK signatures, product tiers, and operational runbooks—lives in linked specification documents (see Appendix A.6). Market sizing, GTM, and financial scenarios live in the investor memo and data room.

The alloy protects. The core remembers.


I. Thesis

The Genesis Era

Humanity has crossed an inflection point: synthetic content now exceeds human-originated volume at industrial scale. A scientist reads forty papers; a model traverses forty million. A designer prompts a system trained on billions of artifacts; a team modifies the output; another model incorporates the result; a company commercializes it; another community adapts it. Dataset provenance is existential. Trust in digital authorship, consent, and cultural integrity is eroding under opacity.

The structural failures are not incidental—they are architectural. Most artifacts still have no cryptographic proof of creation. Consent breaks at scale with no machine-readable enforcement. Identity is fragmented. Transformation chains are not verifiable. Rights declarations are static. Synthetic outputs omit model and dataset lineage. The internet remembers events better than it remembers inheritance.

Those failures share a single missing layer.

What Provenance Is Not

Identity is not provenance. Authenticity is not provenance. Ownership is not provenance. Custody is not provenance. Transaction history is not provenance. Attribution is not provenance. Provenance is not merely history.

A file can have a hash. A person can have an identity. A claim can have a credential. A photograph can have authenticity metadata. A product can have a supply-chain history. A post can move between federated networks. A transaction can be immutably recorded. And we can still lose the story of becoming.

Provenance is continuity through change. The question is not only what happened? It is what became of what came before?

The Missing Layer

Other protocols establish facts. SOVEREIGN\PROVENANCE preserves becoming.

It records relationships among states as artifacts move:

Origin → Inheritance → Contribution → Transformation → Transmission → Derivation → Consequence

Creation no longer has a single author. “Who made what?” is no longer a sufficient question. The better questions are: What was inherited? What was contributed? What transformed? What persisted? What deserves recognition? What obligations remain? What should travel forward?

Protocol Landscape

SOVEREIGN\PROVENANCE does not sit above the internet. It sits among the protocols that already make it work, and makes them legible to one another through lineage.

FamilyQuestion it answersQuestion it does not own
DID / VCWho are you? What can you prove?What was your relationship to what became?
ToIPWhy should this claim or relationship be trusted?What lineage should persist through the trusted relationship?
ATProto / ActivityPubHow does information move across a federated network?What survives as it moves?
W3C PROVWhat entities, agents, and activities produced something?How does inheritance persist through subsequent transformation?
C2PAIs this media authentic, and what happened to it?What larger lineage does the artifact belong to?
GS1 / EPCISWhere did a product go and what happened to it?What ecological, material, and human inheritance moved through it?
SolidWho controls and accesses data?What happened through its use and transformation?
IPFS / hashesWhat exact object is this?What is its biography?
LedgersWhat events were recorded and in what order?What do those events mean within a lineage?

A protocol should own as little as necessary. SOVEREIGN\PROVENANCE does not need its own identity system, blockchain, storage network, social network, credential system, or media-authenticity standard. It consumes those primitives. It is network-agnostic, storage-agnostic, ledger-agnostic, and identity-agnostic. The protocol owns the lineage.

SOVEREIGN\PROVENANCE is not another internet. It is a way for lineage to survive across the internet we already have.

When the Protocol Applies

The protocol is warranted when five conditions hold:

  1. Did something inherit from something else?
  2. Did multiple actors contribute?
  3. Did it transform?
  4. Will it move between systems?
  5. Does its lineage matter after it moves?

If those conditions are present—in science, culture, civic records, supply chains, creative work, models, or organizational decisions—facts about the object are not enough. The biography must travel with it.

Object Biography

Consider a photograph. IPFS can say which object it is. A DID can say who signed it. C2PA can say whether it is authentic and what edits occurred. ToIP can say whether its assertions can be trusted. ATProto can say how it circulates.

None of those answers, stacked, yields: what it inherited; who contributed to what it became; what transformations occurred; what it subsequently influenced; what obligations traveled forward; what descended from it.

The other protocols help establish facts about the artifact. SOVEREIGN\PROVENANCE preserves the artifact’s relationship to what came before and what comes after. Sequence is not inheritance. A Passport can resolve an artifact into lineage and reference evidence from other protocols rather than manufacturing all evidence itself.

From Output-Priced to Trace-Priced Economies

For centuries, markets priced outputs because they could not observe origins. Tokens attempt to represent creative value as fungible units detached from lineage, context, and intent—producing speculative distortion, environmental cost, and misaligned incentives.

Markets already record ownership → transaction → price. Innovation actually happens through inheritance → contribution → transformation → adoption → downstream value. The market frequently sees only the final monetizable artifact.

Because lineage can be made machine-readable, economies can shift: from output-priced to trace-priced. A trace is a cryptographically provable, temporally anchored record:

Trace definition: identity, origin timestamp, and lineage graph

where i is sovereign identity (native or bound), t₀ is origin timestamp, and L is the lineage DAG of descendants. Traces capture identity, origin, intent, rights, transformations, cultural protocols, and synthetic disclosures in one verifiable structure. A trace cannot be forged; it grows in relational value as lineage expands.

The protocol records relationships. It should be capable of establishing that an artifact inherited X from a contribution, with evidence, transformation history, and subsequent lineage. It should not say Alice deserves 7%. Markets determine value. Once provenance is legible, participants can build royalties, licenses, reputation, procurement preference, grants, or simply recognition. The protocol preserves the optionality.

The Genesis Era made this shift existential. The missing layer makes it possible.

Markets saw only the event. Reality runs on the trace.


II. Ontology

SOVEREIGN\PROVENANCE is one system expressed through six layers. Each layer composes on those below; none replaces upstream semantics.

SOVEREIGN\PROVENANCE six-layer ontology: institutional, economic, participation, experience, protocol, and material layers

Material Layer

The material canon is a metaphor for protocol properties, not a product surface. It is how the system remembers origin while remaining tamper-evident under transmission.

LayerMeaningProtocol mapping
Tourmaline CoreIntrinsic origin, authorship, lineage-memoryIdentity adapter, Seal, temporal anchor
Alloy ShellTamper-evident integrity, rights, consent, proof without exposurePassport, Accord, ledger anchoring
Transmission FieldVisible knowledge proofs, resonance, accountability under pressureGuardian, Proof cards, Fractal overlays, ambient seals

Artifacts emit visible knowledge proofs—signal types (positive, negative, neutral charge) and contextual overlays tied to events, usage, and chain-of-custody—without revealing protected essence.

Protocol Layer — Anchor

Anchor engines construct, bind, and query lineage. Where a named engine overlaps an existing internet primitive, the engine is an adapter or anchor, not a replacement of that primitive.

EngineFunctionRestraint
SP IdentitySovereign cryptographic identity across contexts and jurisdictionsAdapter: mint native keys or bind DID / VC
SP SealAtomic fragment hashing; derivative detection (Rust/WASM)Complements content-addressed hashes; does not replace IPFS
SP PassportLineage biography binding identity, seal, rights, nine lineage fields, ledgerThe object the protocol owns
SP AccordMachine-readable, executable rights and consentAuthorizes; does not evaluate readiness
SP LedgerAppend-only, merkle-anchored event logAnchor: native chain or external timestamping / ledger commit
SP Guardian NodeRegional enforcement, mirroring, integrity alertsNot a social network or storage network
SP SyntheticAI output registration with model/dataset lineage disclosureConsumes model and dataset evidence; does not govern the model
SP LineageLineage DAG construction and querySemantic layer over facts established elsewhere
TVERead-only trace valuation over verified lineageNever mutates provenance; never assigns a market share
Mission ProvenanceAutonomous work: runtime events, critical checkpoints, publication export; optional Venture Cell hostRecord, authorize, constrain, and verify remain separable

Passport lineage fields

Every Passport can resolve an artifact into a biography. Fields reference evidence; they do not invent it.

FieldQuestion
OriginWhere does this begin?
InheritanceWhat came into it?
ContributionWho or what added something?
TransformationWhat changed?
EvidenceHow do we know?
StewardshipWho carried responsibility?
TransmissionWhere did it travel?
DerivationWhat emerged from it?
ConsequenceWhat happened afterward?

Parent and derivative identifiers remain a graph convenience. They are not a substitute for these fields.

The protocol owns four separable functions. RECORD answers what happened and never implies authorization. AUTHORIZE answers who had authority and never implies scientific truth. CONSTRAIN answers whether action was permitted and never implies correctness. VERIFY answers whether an outcome can be reconstructed and never returns truth=true.

Experience Layer

  • Mirror — Operational console: workflows, lineage dashboards, Proof cards, Auditor bundles, economic telemetry, organization and API key management, and Repository Stewardship capsules. Mirror Watch is specified as reuse detection across the web and model indexes; scan coverage is a deployment capability, not a global network claim.
  • Fractal — Context-intelligence layer: epistemic confidence, validation traces, metadata completeness, risk classification, and valuation overlays. Proprietary scoring remains server-side. Fractal add-ons compose on this layer; they do not substitute for protocol proofs.
  • Provenance Bar — Ambient sealing at the point of creation. Origin is bound in the tool where work happens, then issued as public proof without exposing protected content.
  • Repository Stewardship — Evolving context around an artifact (capsule, claims, evidence, stewardship authority). Git hosting is an evidence source and execution environment, not the provenance product. Stewardship is not the HCP Steward Workbench.

Participation Layer — Human-Centered Provenance (HCP)

HCP extends the protocol for bounded human collaboration. People participate naturally. The Cell remembers responsibly. Humans confirm only what matters. Value is calculated only when something consequential occurs.

Venture Cells are collaboration containers organized around a Purpose Covenant, with scoped RoleGrants. Before contribution, each participant completes an Opening Position—a versioned statement of inheritance, background assets, protected boundaries, opportunity cost, and reciprocity preferences.

Domain chain (ordered; no layer may skip upstream semantics):

Human-Centered Provenance domain chain from person through opening position, permission, contribution, shared work, consequence, value event, allocation, settlement, and regenerative capacity

Five experience surfaces: Personal Mirror, Collective Mirror, Steward Workbench, Adjudication Workbench, Network Mirror. Interaction follows: presence → confirm meaning → confirm consequence.

Missions may optionally attach to a Venture Cell (host_cell_id). Mission charter authority remains independent of Cell RBAC. Mission provenance establishes causal evidence; HCP allocation may consume it and must not collapse provenance into finance.

Institutional Layer

  • SP Market — Innovation claims, append-only proofs, settlement events, and governance instruments (provisional licenses, risk co-signs, formal challenges). Connects provenance to outcome settlement without tradable tokens. The institutional form is a clearinghouse of claims and evidence, not a speculative venue.
  • Obligation Passports — Passport specialization for debt/obligation provenance with deterministic Accord evaluation and append-only lifecycle events.
  • Policy Packs — Versioned rule sets that evaluate provenance records against readiness criteria. They never modify source records, never issue certifications, and are not Accords. Accords authorize rights; Policy Packs score explainability and control completeness.
  • Preservation-to-Discovery — Knowledge stewardship: preserved material is not automatically computationally legible. Atlas locates opportunity, Network makes it reachable, Journey sequences responsible next action, and SOVEREIGN\PROVENANCE is why each assertion can be trusted.
  • Decision Accounting — The same protocol applied to AI-mediated organizational decisions. RECORD becomes a reasoning ledger (claims, assumptions, limits). AUTHORIZE and CONSTRAIN become a decision journal and Policy Pack readiness evaluation. VERIFY becomes a consequence register, drift detection, and outcome reconciliation. Learning compounds across artifacts. We do not govern AI systems; we govern decisions influenced by AI. SOVEREIGN\PROVENANCE is the provenance protocol that powers that operating system. Enterprise module names and buyer messaging live in GTM documents; they do not replace the protocol functions named here.

Economic Layer — Two Connected Systems

SystemQuestion it answersMutability
TVEWhat is trace value given verified lineage and signals?Read-only
HCP valueWhat value was created, verified, and distributable—and who authorized allocation?Append-only; human-governed

TVE outputs may inform allocation proposals; they never substitute for human Allocation Decisions. They never assign a percentage share.

Commercial offerings (Creator Shield, Platform Integrity, Dataset Passport, Lab Provenance, Guardian Node, Sovereign Vault, Venture Cell, and others) compose these layers for specific personas. See Product Catalog and Developer Documentation.


III. Invariants

Protocol Principles

  1. Sovereign Identity — Cryptographically verifiable, persistent, rights-aware; native or bound to interoperable identity standards
  2. Atomic Provenance — Fragment-level hashing and derivative detection
  3. Rights-Aware by Default — Executable, non-strippable, survives replication
  4. Cultural Sovereignty — Cultural protocols as first-class enforceable rights
  5. Tamper-Evident Records — Append-only, merkle-anchored ledger (native or externally committed)
  6. Non-Tokenized Architecture — Traces, not tokens; no speculative layer
  7. Governance-Friendly Evolution — Transparent proposals, backward compatibility
  8. Runtime ≠ Publication — Operational events are not public proofs; Git is never the runtime ledger
  9. Lineage Interoperability — Inherit existing primitives; own only the missing semantic layer
  10. Contribution without Possession — Visibility of contribution does not require exclusive ownership

System Ethos

  • Origin cannot be severed · Lineage is memory · Integrity is structural
  • Protection without extraction · Visibility without exposure · Verification without surrender
  • Sovereignty as a material condition
  • Stewardship with provenance · The freer ideas become, the more important provenance becomes

HCP Foundational Rule

Sovereignty precedes attribution. Attribution precedes valuation. Valuation precedes allocation. Allocation never defines human worth.

What the Protocol Never Does

  • Infer or mutate provenance for valuation purposes
  • Treat projected value as realized value
  • Recompute historical snapshots with new economic parameters
  • Expose protected content in public projections
  • Allow self-adjudication on conflicted high-risk actions
  • Conflate model inference permission with model training permission (default deny on protected sources)
  • Create tradable tokens or speculative instruments
  • Conflate runtime telemetry with publication proof
  • Let Policy Packs mutate source records or issue certifications
  • Collapse mission provenance into financial allocation
  • Replace DID, C2PA, W3C PROV, GS1, ToIP, or other fact-establishing protocols
  • Assign percentage shares, royalties, or market value as protocol truth
  • Require a native identity, ledger, storage network, or social graph in order to record lineage

IV. Architecture

Interoperability Stack

Applications (science, AI, culture, civic systems, supply chains, creative work, knowledge systems) sit above a lineage layer. That layer—inheritance, contribution, transformation, stewardship, derivation, consequence—is what SOVEREIGN\PROVENANCE owns. Beneath it: interoperability with W3C PROV, C2PA, ToIP, DID / VC, and GS1 / EPCIS; network and data with ATProto, ActivityPub, Solid, IPFS, and the Web; verification and compute with cryptography, ledgers, databases, and cloud or edge.

Inherit existing primitives. Own only the missing semantic layer.

Layered Stack

SOVEREIGN\PROVENANCE layered architecture stack from Venture Cells and Mirror Cycles through applications, API, SDKs, Guardian Nodes, the global append-only ledger, and Seal, Passport, and Accord engines

The stack diagram names deployment engines. It does not require every engine to be the system of record for the primitive it touches. Identity may be bound. Ledger events may be anchored externally. Guardian Nodes enforce and mirror; they do not constitute a new public internet.

Rights and AI Authorization

Accord rules are machine-readable and non-strippable. They are enforced at protocol boundaries—upload, API, and Guardian—and are designed to survive transformation. Universal enforcement across every third-party platform is an adoption condition, not a completed network fact. Model inference (ephemeral processing) and model training (weight updates, fine-tuning corpora) remain distinct permission purposes, both requiring explicit consent with default deny for protected sources. Redaction occurs at projection boundaries before prompt assembly.

Public Proof vs Protected Content

Public projections carry hash-linked proofs and disclosure-mode-appropriate metadata only. Protected source content remains behind permission boundaries. Withdrawal and tombstone records block future re-ingestion.

Runtime vs Publication Provenance

Artifact publication and autonomous mission execution have different volume, latency, and disclosure requirements. They share one protocol and must not share one store.

RUNTIME PROVENANCE      → high-volume mission events
CRITICAL PROVENANCE     → signed checkpoints, authorization decisions
PUBLICATION PROVENANCE  → curated manifest and proof bundle
PUBLIC PROOF            → hash commitments without exposing protected content

Authorization and integrity-critical events fail closed. Informational telemetry may batch asynchronously. Git and external timestamping remain publication-only; they are never the runtime ledger. Every publication artifact retains mission_id and source_event_ids linking back to runtime records.

Sovereign Zones

Provenance truth is anchored per jurisdiction. Artifacts carry sovereignZoneId, jurisdiction, and proofPolicyId. Zones define residency, replication allowlists, and Guardian assignment. Cross-zone operations require explicit authorization.

HCP and Mission Implementation

HCP logic lives in packages/cell-core/ (types, state machines, invariants) with Cell-scoped APIs and deny-by-default row-level security. Consequential records are append-only or versioned via supersede semantics. Idempotency keys govern retried writes; outbox events handle side effects.

Mission Provenance lives in packages/mission-core/, composing on provenance-core and policy-engine. Missions are org-scoped and domain-independent. Scientific missions may optionally host in a Venture Cell; they are not a Cell subtype.

Full API, schema, and SDK reference: see Appendix A.6.


V. Economics

Markets Determine Value

The protocol’s economic claim is restraint first, then formalism.

SOVEREIGN\PROVENANCE records relationships. It does not adjudicate desert. Participants may later construct royalties, licenses, reputation, procurement preference, grants, or recognition on top of machine-readable lineage. Those constructions are markets, contracts, and governance—not protocol truth.

Legible provenance produces a flywheel: more legible provenance → greater trust → lower diligence cost → safer sharing → more contribution → more recombination → more innovation → more economic value → greater reason to preserve provenance. Compliance may be a beachhead. The larger proposition is increased economic velocity without collapsing contribution into possession.

Stewardship with provenance. The more confidently people can contribute without disappearing from the lineage, the more confidently knowledge can circulate.

Trace Formalism

Let artifacts be nodes in lineage DAG G = (𝒜, E). Let R(a) be direct payoff of artifact a, and Desc(a) its verified descendants.

Trace value equation: direct payoff plus weighted downstream value

Trace value by identity: sum of trace values for an identity's artifacts

where α weights direct vs inherited value and wₐ,ᵦ ∈ [0,1] attributes downstream value to ancestor a. Only verified lineage counts; provenance is never mutated by valuation. T(a) and wₐ,ᵦ are read-only signals available to human allocation; they are not an assigned share.

R-Function and Signals

Direct payoff function: weighted revenue, usage, compliance, contract, and custom value

Weights β and attribution rules w are governance parameters under the Economic Parameters Charter: Protocol Council approval, versioning, immutability of past snapshots. Default weights and proprietary tuning remain governance-controlled, not hard-coded in client surfaces.

Attribution strategies include fragment-proportional, lineage-depth discount:

Lineage depth discount: base weight multiplied by gamma to the power of depth

Accord-constrained, and contract-defined overrides.

Optional economic.snapshot ledger events record point-in-time trace value without altering provenance.

HCP Value States

Consequential value progresses: projected → committed → realized → verified → distributed, with revised and reversed via superseding Correction records.

Economic pool invariant: sum(approved_allocations) + sum(reserves) = authorized_pool

Network consolidation eliminates internal double-counting across Cells.

Value Dimensions

Beyond scalar trace price, SOVEREIGN\PROVENANCE recognizes lineage value, rights-awareness value, origin protection value, contextual interaction value, cultural integrity value, misuse-prevention savings, and compliance/risk-reduction value. Organizations quantify cost-avoidance from theft, misattribution, legal exposure, dataset contamination, and unauthorized training.

Cooperative Allocation

The protocol supports Shapley-compatible allocation approximations through lineage depth, rights constraints, and derivative attribution—structural support for fair origin compensation, not a token market, and not a protocol-assigned split.

Value originates at origins, not endpoints.


VI. Governance and Sovereignty

Protocol Governance

Protocol proposals are transparent with impact analysis and migration paths. Backward compatibility preserves existing records across upgrades. Guardian Nodes are specified as participants in proposal review; a live multi-region Guardian electorate is a governance capability, not a deployed global vote.

Economic Parameters Charter governs TVE: who may set β and w, per sovereign zone or deployment. Past snapshots are never recomputed.

Accord and Policy Pack are distinct. Accords bind executable rights and consent to artifacts. Policy Packs evaluate records against versioned readiness criteria and never mutate those records. Readiness scores are operational signals—not audit opinions, attestations, or certifications.

HCP and Mission governance is codified in sixteen accepted Architecture Decision Records (Appendix A.5): module boundaries, cell isolation, disclosure modes, two-layer permission evaluation, public/protected separation, append-only versioning, evidence integrity, idempotency, human review boundaries, allocation conservation, retention/tombstones, AI-purpose authorization, runtime versus publication provenance, mission event-store architecture, event criticality, and the mission–Venture Cell relationship.

Allocation policies are versioned and pinned at decision time. Conflicted actors cannot self-approve. Policy changes never rewrite history.

Cultural Protocols

Sacred content, geographic restrictions, usage conditions, attribution customs, and community governance are first-class Accord capabilities—not edge cases. Cultural module packs extend those rights by community and jurisdiction; enforcement depth follows deployment. SOVEREIGN\PROVENANCE treats cultural sovereignty as core infrastructure.


VII. Vision

Lineage will survive across the internet we already have. Every artifact that moves between people, machines, organizations, and systems will be able to carry a biography: origin, inheritance, contribution, transformation, evidence, stewardship, transmission, derivation, and consequence—sealed in creative tools through Provenance Bar, bound at publication, evidenced by C2PA, DID, PROV, GS1, and hashes where those protocols already speak, verified without exposing protected content.

In Venture Cells, Opening Positions will preserve contributor sovereignty, mirror cycles will make attribution visible and contestable, and value return will follow verified consequence under human authority—not speculation, and not a protocol-assigned share.

Creators will be valued for contribution and ecosystem enablement without being forced into possession. AI systems will respect consent by design. Cultural protocols will have enforcement infrastructure as real as commercial licenses. Civic truth will remain verifiable as synthetic media proliferates. Organizations will account for AI-mediated decisions on the same fabric that accounts for artifacts.

This is the economic and cultural shape of digital civilization when aligned to reality: relational, lineage-based, origin-priced, and interoperable.

The freer ideas become, the more important provenance becomes.


VIII. Conclusion

SOVEREIGN\PROVENANCE is the provenance protocol that preserves becoming. It binds origin, intent, lineage, rights, synthetic disclosure, cultural sovereignty, human-centered collaboration, autonomous mission provenance, and governed value return into a single fabric—without replacing the protocols that already establish facts, and without becoming a token market or an arbiter of desert.

It restores what digital civilization lost: truth in authorship, clarity in lineage, accountability in use, respect for culture, and economic recognition of origin—extended through Venture Cells to responsible human participation, and through decision accounting to AI-influenced institutional action.

It is non-tokenized, rights-aware, governance-friendly, identity-agnostic where it should be, and built to endure.

The alloy protects. The core remembers.

As AI accelerates into the Genesis Era, provenance becomes existential. SOVEREIGN\PROVENANCE provides the missing layer upon which a truthful digital civilization can stand.


Appendices

A.1 Artifact Formats

Illustrative. Authoritative schemas live in protocol specification documents (Appendix A.6).

Manifest

{
  "id": "urn:sp:manifest:...",
  "artifactType": "text|image|audio|video|code|dataset",
  "createdAt": "2026-09-17T10:30:00Z",
  "identityId": "urn:sp:identity:...",
  "seal": {
    "algorithm": "sha256-frag-v1",
    "hash": "abc123...",
    "fragments": []
  },
  "metadata": {
    "title": "Artifact Title",
    "description": "Description",
    "tags": ["tag1", "tag2"]
  }
}

Passport

{
  "id": "urn:sp:passport:...",
  "identityId": "urn:sp:identity:...",
  "sealId": "urn:sp:seal:...",
  "accordId": "urn:sp:accord:...",
  "metadata": {},
  "lineage": {
    "origin": { "statement": "...", "evidence": [] },
    "inheritance": [{ "from": "urn:sp:passport:...", "relation": "inherited_from" }],
    "contribution": [{ "actor": "urn:sp:identity:...", "relation": "contributed_by" }],
    "transformation": [{ "through": "urn:sp:passport:...", "relation": "transformed_through" }],
    "evidence": [
      { "protocol": "c2pa", "ref": "..." },
      { "protocol": "did", "ref": "..." },
      { "protocol": "ipfs", "ref": "sha256:..." }
    ],
    "stewardship": [{ "actor": "urn:sp:identity:...", "relation": "stewarded_by" }],
    "transmission": [{ "to": "urn:sp:passport:...", "relation": "transmitted_to" }],
    "derivation": [{ "id": "urn:sp:passport:...", "relation": "derived_from" }],
    "consequence": [{ "id": "urn:sp:passport:...", "relation": "resulted_in" }],
    "parentIds": ["urn:sp:passport:..."],
    "derivativeIds": ["urn:sp:passport:..."]
  },
  "ledgerAnchor": {
    "merkleRoot": "...",
    "blockHeight": 12345,
    "timestamp": "2026-09-17T10:30:00Z",
    "externalCommit": null
  }
}

parentIds and derivativeIds index the graph. The nine fields carry meaning. evidence entries reference foreign protocols; they do not duplicate those protocols’ payloads.

Seal

{
  "id": "urn:sp:seal:...",
  "algorithm": "sha256-frag-v1",
  "contentHash": "sha256:...",
  "fragments": [
    { "offset": 0, "length": 1024, "hash": "sha256:..." }
  ],
  "createdAt": "2026-09-17T10:30:00Z"
}

A.2 Cryptographic Specifications

DomainSpecification
Primary hashSHA-256
Fragment hashingSHA-256, configurable fragment size (default 1 KB)
Merkle treesSHA-256 binary tree; path proofs leaf-to-root
SignaturesEd25519 (recommended); secp256k1 (compatibility)
Key derivationEd25519 keypair with versioning for rotation
External proofsOpenTimestamps, IPFS, or other commits where required; native ledger optional

Proprietary scoring heuristics (Fractal drift detection, hazard signals, allocation weights beyond structure) are server-side trade secrets—not specified in this document.


A.3 Ledger Event Types

Protocol events: identity.created · identity.bound · seal.generated · passport.issued · passport.derived · accord.bound · lineage.linked · guardian.alert · synthetic.registered

Obligation events: obligation.created · obligation.terms.updated · obligation.payment.recorded · obligation.renegotiated · obligation.default.triggered · obligation.closed

Economic events: economic.snapshot

HCP events: cell.created · membership.invited · opening_position.confirmed · contribution.receipt.confirmed · value.event.recorded · allocation.decided · settlement.receipt.recorded

Mission events: mission.created · charter.created · mission.authorized · permission.granted · permission.denied · checkpoint.created · claim.asserted · human.decision.recorded

lineage.linked carries relation type (inherited_from, contributed_by, transformed_through, stewarded_by, transmitted_to, derived_from, resulted_in). identity.bound records a DID / VC or other foreign identity binding. All events are append-only with merkle chaining. Event payload schemas: see Protocol Specification (Appendix A.6).


A.4 Glossary

Accord

Machine-readable, executable rights declaration: attribution, derivatives, AI training, commercial use, cultural protocols, geographic restrictions. Accords authorize. Policy Packs evaluate.

Allocation Decision

Human-authorized approval or rejection of an allocation proposal. Automation proposes; humans confirm. The protocol never assigns a percentage share as truth.

Auditor

Compliance bundle export (EU AI Act, ISO 42001, NIH/NSF/DARPA-style) on demand via Mirror and API.

Capsule

Stewardship context around an artifact: claims, evidence, rights, and authority over time. The artifact is not the capsule.

Contribution Receipt

Record of participant contribution under specific permissions, with confirm/contest/withhold states.

Decision Accounting

Institutional application of RECORD / AUTHORIZE / CONSTRAIN / VERIFY to AI-mediated decisions: reasoning ledger, decision journal, consequence register, learning graph. Category positioning for strategy, risk, and policy buyers; not a second protocol.

Dependency Claim

Reviewed assertion linking artifact or decision to upstream sources. Dependency ≠ causality.

Demand Credential

Evidence that demand is mature enough to authorize value events.

Economic Parameters Charter

Governance charter for TVE: who sets β and w; versioning; immutability of past snapshots.

Economic Pool

Authorized allocatable amount within a Cell. Conservation: allocations + reserves = pool.

economic.snapshot

Point-in-time trace value record; does not alter provenance.

Economic Signal

Structured input for R(a): directRevenue, usageScore, complianceValue, contractValue, customValue.

Guardian Node

Regional node: rights enforcement, violation detection, integrity alerts, ledger mirroring. Not a social or storage network.

Innovation Docket

Structured innovation claim with evidence and demand maturity; feeds SP Market.

Interoperable Lineage Protocol

Category of SOVEREIGN\PROVENANCE: preserves inheritance, contribution, transformation, and stewardship across systems that already establish facts.

Lineage DAG

Directed acyclic graph of passport nodes and typed derivation edges (inheritance, contribution, transformation, stewardship, transmission, derivation, consequence).

Lineage Fields

Nine Passport biography fields: origin, inheritance, contribution, transformation, evidence, stewardship, transmission, derivation, consequence.

Manifest

Structured metadata describing artifact type, creator, seal, and metadata.

Mirror Cycle

Published Cell activity summary (draft → proposed → published).

Mirror Watch

Specified reuse detection across the web and model indexes. Operational scan coverage is deployment-dependent.

Mission Provenance

Domain-independent provenance for autonomous work. Record, authorize, constrain, and verify are separable. Optional Venture Cell host; never a Cell subtype.

Net Value Statement

Reconciled benefits, costs, externalities, liabilities for an intervention.

Obligation Passport

Passport specialization for debt/obligation provenance with deterministic evaluation.

Opening Position

Versioned pre-engagement statement: inheritance, assets, boundaries, cost, reciprocity.

Passport

Cryptographic certificate binding identity, seal, metadata, rights, nine lineage fields, and a ledger or external anchor. The object the protocol owns.

Policy Pack

Versioned rule set that evaluates provenance records against readiness criteria. Never mutates source records. Not an Accord, not a certification.

Preservation-to-Discovery

Knowledge-stewardship path: Atlas (where opportunity exists), Network (how it becomes reachable), Journey (responsible next action), provenance (why an assertion can be trusted). Preserved material is not automatically computationally legible.

Proof Card

Shareable, jurisdiction-tagged proof-of-origin card via Mirror.

Provenance Bar

Ambient sealing at the point of creation. Origin is bound in the working tool; public proof does not expose protected content.

Purpose Covenant

Versioned statement of why a VentureCell exists.

Regenerative Capacity

Portable individual, Cell, or network capacity after authorized allocation.

Repository Stewardship

Evolving context (capsule) around an artifact: origin, authorship, claims, evidence, and stewardship authority. Git hosting is evidence, not the product. Distinct from the HCP Steward Workbench.

RoleGrant

Scoped Cell authorization (participant through system_service roles).

Seal

Cryptographic hash of artifact fragments via atomic fragment hashing.

Settlement Receipt

Append-only record of what actually occurred on the ledger.

Sovereign Alloy / Tourmaline Core / Transmission Field

Material metaphor layers: protection shell, origin soul, interaction/resonance field. Metaphor for protocol properties, not a product SKU.

Sovereign Identity

Cryptographically verifiable identity with public keys and jurisdictional context. May be minted natively or bound to DID / VC.

Sovereign Zone

Jurisdiction and data residency anchor with replication allowlists.

SP Synthetic

AI output registration with model and dataset lineage disclosure.

Trace

Fundamental economic unit:

Trace definition: identity, origin timestamp, and lineage graph

Identity, origin timestamp, and lineage DAG.

Trace Valuation Engine (TVE)

Read-only lineage valuation; never mutates provenance; never assigns a market share.

Trace Value

Direct utility plus weighted downstream value from verified descendants:

Trace value equation: direct payoff plus weighted downstream value

Value Event

Consequential outcome (financial, social, cultural, ecological, capacity) in HCP layer.

VentureCell

Bounded collaboration container with Purpose Covenant and tenant isolation.


A.5 Architecture Decision Records

ADRTitleCore decision
0001Bounded contextscell-core package; apps compose; DB is source of truth
0002Cell tenant isolationVentureCell wraps org; deny-by-default RLS
0003Disclosure modesSix modes; preserved in derived records
0004Permission runtimeLegal consent + Accord purpose evaluation
0005Public vs protectedHash-linked proofs; no secrets in projections
0006Append-only recordsSupersede, never erase
0007Evidence integritySHA-256 content hash; proofs ≠ truth
0008IdempotencyIdempotency keys; outbox for side effects
0009Human reviewAutomation proposes; no self-adjudication
0010Allocation invariantsConservation pools; network elimination
0011Retention/tombstonesWithdrawal blocks re-ingestion
0012AI-purpose authInference ≠ training; default deny protected
0013Runtime vs publicationMission events ≠ publication proofs; Git is publication-only
0014Mission event storeHybrid PostgreSQL; branch-scoped chains; no dedicated graph DB
0015Event criticalityInformational async; authorization and integrity fail closed
0016Mission and HCPMissions are org-scoped; optional host_cell_id; provenance ≠ finance

Full text: docs/adr/ in the SOVEREIGN\PROVENANCE repository.


A.6 Reference Documentation

DocumentLocationContents
Protocol Positioning/protocolPublic thesis: landscape, restraint, passport fields
Protocol Overviewdocs/protocol/overview.mdComponent details, data flow
Protocol Specification/protocol/specificationEngines, Accords, commercial offerings
API Reference/docs/developer/apiEndpoints, authentication, examples
SDK Documentation/docsJavaScript, Python, Go integrations
Product Catalog/docs/protocol/product-catalogCommercial offerings by persona
Narrative Alignmentdocs/business/narrative-alignment.mdProtocol vs category (decision accounting)
Investor Memo/investors/docs/investor-memoTAM/SAM/SOM, GTM, risks
HCP Architecturedocs/hcp/architecture-foundation.mdVentureCell, domain chain, surfaces
HCP Domain Glossarydocs/hcp/domain-glossary.mdFull HCP vocabulary
Mission Provenancedocs/mission-provenance/Runtime/publication stack, protocol spec
Policy Packsdocs/governance/product/Readiness evaluation; not certification
Repository Stewardshipdocs/repository-stewardship/Capsules, claims, evidence, authority
Preservation-to-Discoverydocs/preservation-to-discovery/Atlas, Network, Journey, evidence
Provenance Bardocs/developer/provenance-bar.mdAmbient sealing at creation
Economic Parameters Charterdocs/governance/economic-parameters-charter.mdTVE governance
Sovereign Zonesdocs/governance/sovereign-zones.mdJurisdiction and residency
Obligation Passportsdocs/obligation-passports/Schema and lifecycle
SP Market Architecturedocs/sp-market-architecture.mdClearinghouse domain model

Version History

Version 2.2 (2026-09-17) — Lineage protocol thesis

  • Re-anchored category as interoperable lineage protocol; Genesis Era retained as historical condition
  • Added protocol landscape, restraint architecture, nine Passport lineage fields, object biography, and standard test
  • Distinguished adapters/anchors (Identity, Ledger, Guardian) from the lineage layer the protocol owns
  • Placed Decision Accounting once under the institutional layer; market material remains in the investor memo
  • Stated economic restraint before TVE formalism: markets determine value; the protocol does not assign shares
  • Updated invariants, A.1 Passport schema, A.3 lineage relation types, glossary, and A.6 (/protocol is positioning, not the overview spec)

Version 2.1 (2026-09-05) — Ontology refresh

  • Named Mission Provenance in the protocol layer: runtime, critical, publication, and public proof
  • Distinguished Accord (rights) from Policy Packs (readiness evaluation)
  • Indexed Repository Stewardship, Preservation-to-Discovery, and Provenance Bar
  • Extended ADR appendix through 0016; refreshed A.6
  • Clarified architectural versus operational language for Fractal, Mirror Watch, and Guardian proposal review

Version 2.0 (2026-08-03) — Structural rewrite

  • Consolidated six-layer ontology (material → protocol → experience → participation → institutional → economic)
  • Single canonical architecture; eliminated redundant sections (duplicate math, overlapping product/use-case narratives)
  • IP boundary discipline: artifact formats and crypto in appendices; API/SDK/types moved to reference docs
  • Unified glossary (A.4); ADR summary (A.5); reference index (A.6)
  • ~50% reduction in body length; thesis-driven structure (Parts I–VIII)

Version 1.4 (2026-08-03)

  • Human-Centered Provenance, system ethos, Sovereign Zones, TVE/HCP distinction, ADR appendix

Version 1.2 (2026-02-21)

  • Trace Valuation Engine, Economic Telemetry, Economic Parameters Charter

Version 1.1 (2026-02-21)

  • Sovereign Stack, Obligation Passports, commercial offerings expansion

Version 1.0 (2025-01-15)

  • Initial publication
ProvenanceAnchored
First registered9/17/2026
Last updated9/17/2026

SOVEREIGN\PROVENANCE Whitepaper Version 2.2 — Interoperable lineage protocol constitution and IP-defining foundation

Public proof link: View proof