Inspect the lineage behind a time record
Time record lineage shows the governed relationships among an original source event, any derived classification, the policy version used, later corrections, human approvals, exports, and downstream acknowledgments. It helps explain how a record reached its current state.
Lineage does not by itself prove that every source, policy interpretation, decision, or downstream system is correct or legally conclusive.
.png)
The minimum understandable chain
Eight stages, each with its own visible context and its own relationship label. Read the relationship labels - they carry the direction, and direction is what makes a chain explainable rather than decorative.
| Stage | Node | Visible context | Relationship label |
|---|---|---|---|
| 1 | Original source event | Source type, source reference, captured and received time, time zone, source status | Captured from / received from |
| 2 | Derived record | Derived value, method and rule version, inputs, transform, created time | Derived from |
| 3 | Historical policy context | Policy reference where permitted, version, effective period, scope, jurisdiction context | Evaluated against / governed by |
| 4 | Correction / later version | Before and after fields, reason, actor and role, submitted and approved time, evidence reference | Corrects / supersedes |
| 5 | Human approval | Approver role, authority scope, decision, rationale where required, effective time | Approved by / reviewed by |
| 6 | Export / handoff | Export version, purpose, manifest reference, generated and sent time, target | Exported as / sent to |
| 7 | Target acknowledgment | Acknowledgment reference, returned version and status, received time | Acknowledged by |
| 8 | Reconciliation | Expected versus returned object and status, mismatch if any, reconciliation time and owner | Reconciled with |
Source type, source reference, captured and received time, time zone, source status
Captured from / received from
Derived value, method and rule version, inputs, transform, created time
Derived from
Policy reference where permitted, version, effective period, scope, jurisdiction context
Evaluated against / governed by
Before and after fields, reason, actor and role, submitted and approved time, evidence reference
Corrects / supersedes
Approver role, authority scope, decision, rationale where required, effective time
Approved by / reviewed by
Export version, purpose, manifest reference, generated and sent time, target
Exported as / sent to
Acknowledgment reference, returned version and status, received time
Acknowledged by
Expected versus returned object and status, mismatch if any, reconciliation time and owner
Reconciled with
Lineage Explorer
A synthetic record with its first-degree relationships. Every relationship is labelled in text - the visual connector is decorative, and the chain below remains fully understandable as an ordered list without it.
Source reference SRC-4471 - captured 04 Aug 06:58 CEST - received 04 Aug 06:58 - source status: authoritative for this scope
Rule version CLS-v12 - inputs: check-in, check-out, break record - produced 04 Aug 19:04 - deterministic, not AI
Policy FN-v3 applied at derivation. The v2 record that covered 28-31 Jul was not retained. Current policy is not inferred backwards - this record remains review-limited for that window.
COR-0912 - changed field: project reference - reason: missing at capture - submitted by worker 06 Aug 08:14 - prior version preserved
DEC-2288 - role: unit reviewer - authority scope: Field Services North - outcome: approved with reason - separation of duties: satisfied - effective 07 Aug 09:30
EXP-5510 v1 - purpose: payroll input - manifest MF-5510 - generated and sent 08 Aug 02:10 - destination: configured payroll target
ACK-5510-1 - returned status: accepted - returned version v1 - received 08 Aug 02:14 - acceptance is not proof of correct processing
Expected v3, observed v1 at target. The export carried v1 before the correction landed. Owner: payroll operations - reconciliation open, not resolved.
- Decision
- Approved with recorded reason
- Actor role
- Unit reviewer - role shown, identity not exposed publicly
- Authority scope
- Field Services North, period records only
- Separation of duties
- Satisfied - approver was not the correction submitter
- Effective
- 07 Aug 2026 09:30 CEST
- Limitations
- Approval does not guarantee payroll, billing, legal, or downstream completion. It records that an authorized person decided, within a stated scope, at a stated time.
- Permitted actions
- Open review history - compare versions - view policy context
Policy history for 28-31 Jul was not retained, so the chain is partially available rather than complete. A downstream reconciliation mismatch is open. This graph shows relationships that exist in the governed record chain - it does not assert that the underlying facts, interpretations, or target systems were correct.
What each relationship means - and does not
Direction is part of the meaning. Sent to and acknowledged by point opposite ways and prove different things.
Compare versions without overwriting anything
The prior version is not a deleted draft. It remains a first-class object with its own attribution, and the comparison shows exactly which fields moved.
One field changed. Duration did not - which matters, because a correction that adds missing context is a different thing from a correction that changes hours, and the comparison makes that visible rather than requiring trust.
When lineage is incomplete
Twelve honest conditions. The rule underneath all of them: never synthesize a missing link, and never render stale data as current.
| Condition | What is shown | Next action |
|---|---|---|
| Missing source | "Source unavailable," "not retained," or "not provided" as appropriate - origin is never invented. | Review source issue or route the integration owner. |
| Conflicting source authority | Both authorities and the conflict scope. No last-write-wins explanation. | Review mapping and authority configuration. |
| Stale source | Last successful update and the affected scope. | Refresh if supported, or review source health. |
| Policy unavailable | Policy reference or version unavailable; record may remain review-limited. | Route the policy owner. Current policy is not inferred. |
| Migration-limited | Migration batch, coverage, transform version, and known missing history. | Review migration evidence. |
| Circular mapping | Graph expansion is blocked and a configuration error is shown. | Route the integration administrator. |
| Duplicate source | A possible-duplicate relationship, with no worker-fault language. | Reconcile sources; preserve original objects. |
| Stale target | Last acknowledgment or reconciliation, and unknown current state. | Recheck the target or its owner. |
| Downstream mismatch | Expected versus observed object, version, and status. | Open the reconciliation workflow. |
| Permission-limited | Only an allowed placeholder, where policy permits one. | Request access through a governed path if available. |
| Graph too large | A cluster or filter prompt, plus list mode. | Narrow by time, type, relationship, or depth. |
| Service error | The static explanation is preserved. No silent stale-as-current rendering. | Retry, or use the status and help routes. |
Shown: "Source unavailable," "not retained," or "not provided" as appropriate - origin is never invented.
Next: Review source issue or route the integration owner.
Shown: Both authorities and the conflict scope. No last-write-wins explanation.
Next: Review mapping and authority configuration.
Shown: Last successful update and the affected scope.
Next: Refresh if supported, or review source health.
Shown: Policy reference or version unavailable; record may remain review-limited.
Next: Route the policy owner. Current policy is not inferred.
Shown: Migration batch, coverage, transform version, and known missing history.
Next: Review migration evidence.
Shown: Graph expansion is blocked and a configuration error is shown.
Next: Route the integration administrator.
Shown: A possible-duplicate relationship, with no worker-fault language.
Next: Reconcile sources; preserve original objects.
Shown: Last acknowledgment or reconciliation, and unknown current state.
Next: Recheck the target or its owner.
Shown: Expected versus observed object, version, and status.
Next: Open the reconciliation workflow.
Shown: Only an allowed placeholder, where policy permits one.
Next: Request access through a governed path if available.
Shown: A cluster or filter prompt, plus list mode.
Next: Narrow by time, type, relationship, or depth.
Shown: The static explanation is preserved. No silent stale-as-current rendering.
Next: Retry, or use the status and help routes.
Who can see what - and the dignity rules
Lineage visibility follows role and permission. Access to your own lineage is not access to anyone else's, and it is not administrative authority.
Own source, policy context, versions, corrections, notices, review status, outcome, and permitted downstream state - in plain language.
Assigned records within authority scope, with evidence references and permitted actions.
Configuration and mapping context. Still not credentials, identities, or restricted source topology.
Hidden identities, technical credentials, restricted topology, legal-hold detail, or records they are not authorized to see.
No worker screen uses suspicious, untrustworthy, low confidence worker, productivity score, attendance score, or guilt-oriented language. A correction request is a separate proposed object - it does not rewrite the current record until authorized review completes. A rejected request preserves the request, the reason, and the escalation route where policy allows.
Privacy, security & sensitive-data boundaries
CurrentObjective: make provenance inspectable without turning a graph into an exposure surface.
Limitations: no universal retention duration or legal-hold availability is claimed. Retention class is shown where supported; specifics are contractual.
Deterministic classification & AI boundary
CurrentObjective: keep derivation explainable and separate from AI.
Limitations: deterministic does not mean infallible. It means the rule and version that produced a value can be named, inspected, and challenged.
Related evidence destinations
Lineage does not replace these. It points at them, and only where each is approved and current.
Attribution, lineage, versions, corrections, and delivery history.
The source, context, rule, result, and review trace.
Where consequential decision authority sits and stays.
The own-record view, correction, and support routes.
Governance and access
Entry point for assurance evidence.
Access, logging, and operational controls.
Purpose, minimization, retention, and rights.
Controlled evidence and current terms.
This page makes no legal-admissibility, immutability, tamper-proof, or blockchain claim, and publishes no customer names or outcome metrics. Legal effect depends on applicable law, policy, evidence, and process - not on a graph looking complete.
Lineage questions
The governed relationship chain from an original source event through policy context, derivation, correction, human approval, export, downstream acknowledgment, and reconciliation. Each stage is a distinct object with its own attribution, timing, and limitations.
.png)