For a decade, the security question about enterprise software was simple: who can see this? Access control lists, role hierarchies, and identity providers all exist to answer it. But AI systems have quietly broken the question. When an agent acts on a fact, the risk isn't only who saw the data — it's whether the fact was ever true, and whether anyone can prove where it came from.
At AntFabric, we think the next primitive isn't tighter access control. It's provenance: every fact carrying its own origin, author, and confidence, attached at the moment of capture and travelling with it forever.
Beyond access control
Access control asks who can see a thing. Provenance asks whether the thing was ever true. The two are complementary — but only one of them survives contact with an autonomous agent acting on your behalf.
Why "the model saw it" is no longer enough
When a decision surfaces in a recap — "we agreed on tiered pricing" — the useful question isn't whether the model had access to the meeting. It's which meeting, spoken by whom, at what timestamp, and how sure the system is that it heard correctly. Without that, you have a plausible sentence and no way to defend it.
A fact without provenance is a rumor with good formatting.
Regulators in financial services have started asking for exactly this. It's no longer enough to show that a control existed; you have to show the lineage of the information a decision was based on.
How AntFabric attaches provenance
Every capture that enters Core is wrapped as an event, not a blob. That event carries four things by default:
- Source — which device heard it, in which room, on which network.
- Author — the authenticated identity of the speaker, not a guess.
- Timestamp — a signed, ordered position in the organizational record.
- Confidence — how sure the system is, surfaced rather than hidden.
Because provenance is attached at capture, it can't be reconstructed after the fact or quietly dropped in a summarization step. When a digital employee later acts on that fact, the lineage comes along for the ride — all the way to the action item on someone's board.
What this changes for audits
An audit stops being an archaeology project. Instead of reconstructing what happened from logs and memory, you replay the event with its provenance intact. Every claim points back to a governed, authenticated origin — and the gap between "what the system said" and "what actually happened" closes.
Where this goes next
Provenance turns organizational memory into something you can stand behind in a room with regulators. It's the difference between an AI that's convenient and an AI you can deploy where the constraints are real. If you want to see it running on one governed use case, request a walkthrough — we'll bring one Sentry and one decision, end to end.


