Content provenance
Where did this artefact come from? Was it AI-generated? Authenticates files: images, video, documents. The C2PA and watermarking conversation.
Provenance is the oldest trust technology we have. It is how a painting proves it is not a forgery and how a dataset proves where it came from. AI agents now take actions inside your business. Those actions need the same thing.
AI provenance is the verifiable record of an AI action's origin and journey: who requested it, which agent and model produced it, what data it touched, who approved it, and what it changed.
The word comes from the art world, where provenance is the documented chain of custody that makes an object trustworthy. Data teams borrowed it for lineage. Now agents force the question onto behaviour itself: not where did this file come from, but what did our AI do, and on whose authority.
Most of the 2026 provenance conversation is about media: C2PA credentials, watermarking, proving whether AI made an image. That work matters, and it answers a different question.
Where did this artefact come from? Was it AI-generated? Authenticates files: images, video, documents. The C2PA and watermarking conversation.
What did the AI do? It queried the CRM, drafted the email, updated the record. On whose request, with which model, under whose approval. Accounts for behaviour, not files. This is where Renly works.
A chatbot produces text a human then acts on, so the human is the author of record. An agent acts directly. Once AI takes the action itself, provenance stops being optional metadata and becomes the difference between a system you can defend and one you cannot.
Renly treats every agent action as one continuous thread. Each stage is recorded and correlated to the same action, so the whole journey can be read back later as a single account.
Each recorded action in Renly carries the fields an auditor actually asks for, correlated into one chain with timestamps.
This is why provenance is not logging. Logs are fragments: one system's view, in its own format, in its own place. Provenance is the same action traced end to end. You can grep logs. You answer to an auditor with provenance.
AI provenance is the verifiable record of an AI action's origin and journey: who requested it, which agent and model produced it, what data it touched, who approved it, and what it changed. The term borrows from art and data lineage, where provenance is the documented chain of custody that makes an object trustworthy.
Content provenance, the C2PA and watermarking conversation, tells you where a piece of media came from and whether AI made it. Action provenance tells you what an AI agent actually did inside your business: the request, the model, the approval, and the outcome. Content provenance authenticates artefacts. Action provenance accounts for behaviour.
A chatbot produces text a human then acts on. An agent acts directly: it writes to your CRM, sends the email, updates the record. Once AI takes the action itself, the question shifts from "is this output good" to "can we account for what happened". Agents without provenance are actions without an author.
The requesting user, the agent, the model that produced the proposal, the inputs, the approval decision where a gate applied, the outputs, and the response from the target system, correlated into one chain with timestamps.
No. Logs are fragments: one system's view, in one place, in its own format. Provenance is a chain: the same action traced end to end, from request to outcome, with each step correlated to the others.
Renly is the governed runtime for AI agents. The agents run the work. Every action carries its provenance.
See how the runtime works Read: AI accountability