Authorline
A repository-linked provenance ledger separating captured tool events, human edits, attribution assertions, integrity receipts, reviewer findings and approved evidence exports.
Teams using several coding agents may be unable to reconstruct which system proposed a change, which human altered it and what review occurred before release. The supplied research reports emerging audit and oversight obligations, a mature public transparency-log capability, and no reviewed direct product producing per-hunk multi-agent provenance exports. The cited legal regimes have specific scopes and do not automatically require this product or make its records compliant. Applicability must be determined from current primary authority and qualified counsel.
Authorline would preserve repository, revision, parent revision, file and hunk locator, captured agent identity assertion, model identity assertion, model-version assertion, session reference, prompt reference or redacted digest, generated patch, human edit, merge event, reviewer identity, review finding, exception, signing key identity, signature, timestamp source, transparency-log receipt, verification result, export request, approved export, recipient acknowledgment, correction, revocation and retention state as distinct records.
A tool-provided identity can be wrong or absent. A hunk may combine model output, generated code, copied material and human edits. Rebases and conflict resolution break simple lineage. A valid signature supports integrity and signer attribution only; it does not prove who authored a line, that a prompt was lawful to retain, that review was meaningful, that code is safe or that a legal obligation was satisfied. Raw prompts may contain secrets, personal data and licensed material, so the default evidence should be minimized and access-controlled.
The pilot should use synthetic repositories and simulated agent events, key rotation, history rewrites and disputed attribution. The likely buyer is an engineering-governance, security or compliance-operations owner in an organization with material agent-assisted development, but applicable obligations, repository count, evidence expectations, privacy constraints, integration feasibility, budget and demand beyond the bounded search remain unverified.
An engineering-governance, security or compliance-operations owner responsible for reviewable evidence about agent-assisted software changes.
Engineering-governance and compliance owners are identifiable, while applicable scope, repository volume and budget need validation.
Repository integrations and a common event schema can support repeated evidence exports after setup.
Agent adoption creates a new evidence gap, but the input establishes the product gap more clearly than a durable barrier.
The input combines a concrete commit-time mechanism, available signed-log infrastructure and current interest in AI oversight and traceability.
Legal applicability is uncertain, per-hunk authorship is intrinsically ambiguous, prompt capture creates privacy risk, and existing provenance or developer-platform vendors can extend into this area.
Discussion
No comments yet — be the first to weigh in.
