ZoikoDigital
Time Record Lineage

Inspect the lineage behind a time record

Time record lineage shows the governed relationships among an original source event, any derived classification, the policy version used, later corrections, human approvals, exports, and downstream acknowledgments. It helps explain how a record reached its current state.

Lineage does not by itself prove that every source, policy interpretation, decision, or downstream system is correct or legally conclusive.

Lineage graph preview

The minimum understandable chain

Eight stages, each with its own visible context and its own relationship label. Read the relationship labels - they carry the direction, and direction is what makes a chain explainable rather than decorative.

1Original source event

Source type, source reference, captured and received time, time zone, source status

Captured from / received from

2Derived record

Derived value, method and rule version, inputs, transform, created time

Derived from

3Historical policy context

Policy reference where permitted, version, effective period, scope, jurisdiction context

Evaluated against / governed by

4Correction / later version

Before and after fields, reason, actor and role, submitted and approved time, evidence reference

Corrects / supersedes

5Human approval

Approver role, authority scope, decision, rationale where required, effective time

Approved by / reviewed by

6Export / handoff

Export version, purpose, manifest reference, generated and sent time, target

Exported as / sent to

7Target acknowledgment

Acknowledgment reference, returned version and status, received time

Acknowledged by

8Reconciliation

Expected versus returned object and status, mismatch if any, reconciliation time and owner

Reconciled with

Lineage Explorer

A synthetic record with its first-degree relationships. Every relationship is labelled in text - the visual connector is decorative, and the chain below remains fully understandable as an ordered list without it.

Record TR-77841 - version 3
Field Services North - period 28 Jul - 03 Aug 2026 - all values synthetic
Lineage partially available
All relationshipsSourcePolicyCorrectionApprovalExportDownstreamDepth 1Depth 2
1
Captured from
Source event - terminal check-in

Source reference SRC-4471 - captured 04 Aug 06:58 CEST - received 04 Aug 06:58 - source status: authoritative for this scope

2
Derived from
Derived record - classified duration

Rule version CLS-v12 - inputs: check-in, check-out, break record - produced 04 Aug 19:04 - deterministic, not AI

3
Evaluated against
Policy context - partially unavailable

Policy FN-v3 applied at derivation. The v2 record that covered 28-31 Jul was not retained. Current policy is not inferred backwards - this record remains review-limited for that window.

4
Corrects - supersedes v2
Correction - project reference added

COR-0912 - changed field: project reference - reason: missing at capture - submitted by worker 06 Aug 08:14 - prior version preserved

5
Approved by - selected
Human approval - unit reviewer

DEC-2288 - role: unit reviewer - authority scope: Field Services North - outcome: approved with reason - separation of duties: satisfied - effective 07 Aug 09:30

6
Exported as - sent to
Export - payroll input package

EXP-5510 v1 - purpose: payroll input - manifest MF-5510 - generated and sent 08 Aug 02:10 - destination: configured payroll target

7
Acknowledged by
Target acknowledgment - accepted

ACK-5510-1 - returned status: accepted - returned version v1 - received 08 Aug 02:14 - acceptance is not proof of correct processing

8
Reconciled with
Reconciliation - mismatch open

Expected v3, observed v1 at target. The export carried v1 before the correction landed. Owner: payroll operations - reconciliation open, not resolved.

Selected node - DEC-2288 human approval
Decision
Approved with recorded reason
Actor role
Unit reviewer - role shown, identity not exposed publicly
Authority scope
Field Services North, period records only
Separation of duties
Satisfied - approver was not the correction submitter
Effective
07 Aug 2026 09:30 CEST
Limitations
Approval does not guarantee payroll, billing, legal, or downstream completion. It records that an authorized person decided, within a stated scope, at a stated time.
Permitted actions
Open review history - compare versions - view policy context
Limitations on this graph

Policy history for 28-31 Jul was not retained, so the chain is partially available rather than complete. A downstream reconciliation mismatch is open. This graph shows relationships that exist in the governed record chain - it does not assert that the underlying facts, interpretations, or target systems were correct.

Accessible relationship list is the primary representation; the connector is decorativeSynthetic record

What each relationship means - and does not

Direction is part of the meaning. Sent to and acknowledged by point opposite ways and prove different things.

Captured from
This record originates in a named source event.
Source existence does not prove accuracy, worker intent, or completeness.
Derived from
A rule version produced this value from named inputs.
Deterministic derivation is not infallible, and it is not AI.
Evaluated against
A policy version, effective at the time, governed the derivation.
Policy configuration is not legal compliance, and current policy never applies backwards.
Corrects / supersedes
A later version replaces an earlier one as current.
A correction does not mean misconduct, and the prior state has not vanished.
Approved by
An authorized person decided within a stated authority scope.
Approval does not guarantee payroll, billing, legal, or downstream completion.
Exported as / sent to
A named version was generated and transmitted for a purpose.
Sent does not mean received, accepted, or reconciled.
Acknowledged by
A target returned a reference and a status.
Acknowledgment does not mean semantic correctness or completed processing.
Reconciled with
Expected version and status were compared with what the target holds.
Reconciliation does not prove legal or financial correctness.

Compare versions without overwriting anything

The prior version is not a deleted draft. It remains a first-class object with its own attribution, and the comparison shows exactly which fields moved.

Version 2 - prior, preserved
Duration6h 45m
Project ref- not provided
Rule versionCLS-v12
StatusNeeds input
Created bySystem, at derivation
Effective04 Aug 19:04 - 06 Aug 08:14
Version 3 - current
Duration6h 45m
Project refPRJ-Northgate-02
Rule versionCLS-v12
StatusApproved
Created byWorker correction, reviewer approved
Effective07 Aug 09:30 - current

One field changed. Duration did not - which matters, because a correction that adds missing context is a different thing from a correction that changes hours, and the comparison makes that visible rather than requiring trust.

When lineage is incomplete

Twelve honest conditions. The rule underneath all of them: never synthesize a missing link, and never render stale data as current.

Missing source

Shown: "Source unavailable," "not retained," or "not provided" as appropriate - origin is never invented.

Next: Review source issue or route the integration owner.

Conflicting source authority

Shown: Both authorities and the conflict scope. No last-write-wins explanation.

Next: Review mapping and authority configuration.

Stale source

Shown: Last successful update and the affected scope.

Next: Refresh if supported, or review source health.

Policy unavailable

Shown: Policy reference or version unavailable; record may remain review-limited.

Next: Route the policy owner. Current policy is not inferred.

Migration-limited

Shown: Migration batch, coverage, transform version, and known missing history.

Next: Review migration evidence.

Circular mapping

Shown: Graph expansion is blocked and a configuration error is shown.

Next: Route the integration administrator.

Duplicate source

Shown: A possible-duplicate relationship, with no worker-fault language.

Next: Reconcile sources; preserve original objects.

Stale target

Shown: Last acknowledgment or reconciliation, and unknown current state.

Next: Recheck the target or its owner.

Downstream mismatch

Shown: Expected versus observed object, version, and status.

Next: Open the reconciliation workflow.

Permission-limited

Shown: Only an allowed placeholder, where policy permits one.

Next: Request access through a governed path if available.

Graph too large

Shown: A cluster or filter prompt, plus list mode.

Next: Narrow by time, type, relationship, or depth.

Service error

Shown: The static explanation is preserved. No silent stale-as-current rendering.

Next: Retry, or use the status and help routes.

Who can see what - and the dignity rules

Lineage visibility follows role and permission. Access to your own lineage is not access to anyone else's, and it is not administrative authority.

Worker

Own source, policy context, versions, corrections, notices, review status, outcome, and permitted downstream state - in plain language.

Reviewer

Assigned records within authority scope, with evidence references and permitted actions.

Administrator

Configuration and mapping context. Still not credentials, identities, or restricted source topology.

Nobody

Hidden identities, technical credentials, restricted topology, legal-hold detail, or records they are not authorized to see.

Worker dignity rules

No worker screen uses suspicious, untrustworthy, low confidence worker, productivity score, attendance score, or guilt-oriented language. A correction request is a separate proposed object - it does not rewrite the current record until authorized review completes. A rejected request preserves the request, the reason, and the escalation route where policy allows.

Privacy, security & sensitive-data boundaries

Current

Objective: make provenance inspectable without turning a graph into an exposure surface.

Never rendered
Technical credentials, secrets, internal topology, hidden identities, legal-hold detail
Roles not names
Actor role and authority scope are shown; public views do not expose personal identity
No sensitive IDs in URLs
Record identifiers are never placed in public analytics or marketing URLs
Retention honesty
A not-retained node says so rather than appearing as an absent link

Limitations: no universal retention duration or legal-hold availability is claimed. Retention class is shown where supported; specifics are contractual.

Deterministic classification & AI boundary

Current

Objective: keep derivation explainable and separate from AI.

Derivation
Deterministic, versioned, rule-referenced - and never branded as AI
Approved AI scope
May assist only within separately governed limits; it decides nothing here
No scores
No confidence percentage, risk score, or opaque ranking appears in any node

Limitations: deterministic does not mean infallible. It means the rule and version that produced a value can be named, inspected, and challenged.

Related evidence destinations

Lineage does not replace these. It points at them, and only where each is approved and current.

Evidence Ledger

Attribution, lineage, versions, corrections, and delivery history.

Deterministic Classification

The source, context, rule, result, and review trace.

Human-in-Command

Where consequential decision authority sits and stays.

Worker Experience

The own-record view, correction, and support routes.

Governance and access

Trust Center

Entry point for assurance evidence.

Security

Access, logging, and operational controls.

Privacy

Purpose, minimization, retention, and rights.

Procurement & Legal

Controlled evidence and current terms.

No evidentiary claim

This page makes no legal-admissibility, immutability, tamper-proof, or blockchain claim, and publishes no customer names or outcome metrics. Legal effect depends on applicable law, policy, evidence, and process - not on a graph looking complete.

Follow the evidence

Trace a record without being asked to trust a badge

See how source, derivation, policy version, correction, approval, export, acknowledgment, and reconciliation stay separate - with limitations visible at every step.

Product preview

Lineage questions

The governed relationship chain from an original source event through policy context, derivation, correction, human approval, export, downstream acknowledgment, and reconciliation. Each stage is a distinct object with its own attribution, timing, and limitations.