Provenance is the recorded origin and history of a piece of data. Where it came from, who or what produced it, when, and what has happened to it since.
It overlaps with lineage and the two get used interchangeably. The useful distinction: lineage describes the path a value took through transformation. Provenance describes the authority behind it. Lineage answers how this number was calculated. Provenance answers who is standing behind the inputs.
The originating system and its version, since a tool’s behaviour changes across releases.
The collection method and the credential or account that performed it, since access scope determines what could be seen.
The observation time, distinct from the ingestion time.
The chain of custody afterwards: normalization applied, corrections made, who approved them.
For manual entries, the person, their role, and the evidence attached.
Metrics get challenged, and the challenge is rarely about arithmetic. It is about authority.
A department head disputes their coverage figure. The question is not whether the division was performed correctly. It is whether the scanner had visibility into their subnet, whether the account it used could see everything, and whether the asset list it worked from was current.
None of those are answerable from a computed value. All of them are answerable from provenance.
The same applies to supervisory questions. An examiner asking about a figure from eighteen months ago is asking whether the organization can substantiate what it reported, which is a provenance question rather than a calculation question.
Provenance matters most where the data was entered by a person, because that is where it is weakest by default.
A quarterly figure typed into a cell has no provenance at all. The same figure recorded with the author, the date, the period it describes and the report it was drawn from is evidence.
The difference costs a few seconds at entry and decides whether the number survives its first serious challenge. See manual data entry.
From the blog