Elora Engine 0.2.8

Governance Provenance

A session-level evidence journey that reconstructs how governed interaction moved from preparation to proposal, policy and guardrail evaluation, commit outcome, and consequence.

From Records to a Governed Journey

Replay remains an important inspection view, but Governance Provenance is the wider reconstruction layer. It connects retained evidence without pretending every source has the same meaning or authority.

Session and Turn Structure

Observer preparation is represented separately from actor turns. Governed and comparison lanes remain distinct, and internal re-evaluation is not mislabelled as another actor prompt.

Lifecycle Evidence

Accepted, queued, held, actioning, completed, cancelled, and failed states can be read as one ordered journey while preserving their source records.

Stage Replay

Turn-scoped stages provide focused inspection of timing, token, policy, guardrail, and commit evidence. Replay is a lens into provenance rather than a replacement for it.

Separate Authorities

Observation, interpretation, recommendation, policy evaluation, guardrail outcome, and commit authority remain separately labelled. Correlation does not transfer authority.

Continuous TOCTOU Evidence

Elora studies time-of-check to time-of-use state across ordinary retained transitions, not only after a Threat Case is opened.

Check and State

Available evidence can show what was evaluated and which relevant state was retained at that moment.

Use and Consequence

Later evidence can show the state used at authorization and the resulting outcome, including when continuation was denied or held.

Careful Claims

A state change or collision is evidence for investigation. It is not automatically proof of vulnerability, exploitation, causation, or impact.

Runtime Intelligence

Measured provider time, recorded event spans, intentional waits, and pressure-related intervals are classified separately so elapsed time is not assigned to the wrong cause.

Governed Interaction

Testing Edge

A conversation-shaped research surface presents submitted work, retained responses, run progress, provider/model context, token evidence, and governance outcomes while keeping the complete forensic record elsewhere.

AI Behaviour Provenance

Selected Behaviour packs and effective run profiles are visible as evidence. They can influence a proposal but cannot grant themselves policy or commit authority.

Memory Governance

Session work has declared runtime ownership and terminal release evidence. Durable findings and reports remain distinct from disposable working state.

Completion Integrity

Provider transport success is not treated as a complete answer. Incomplete output remains labelled evidence and is not promoted into an approved commit candidate.

Public-Safe Reporting

Elora can prepare readable Schematic provenance reports and an optional JSON companion from the same bounded projection.

The public boundary can include execution lanes, lifecycle evidence, commit and guardrail outcomes, semantic runtime classes, and TOCTOU evidence states. It excludes prompts, responses, private identities, internal event identifiers, protected infrastructure, detector details, and operational thresholds.