Govern one AI workflow before its blind spots become incidents.
A golden baseline, governance policies, and a CI gate that fails the build when reasoning regresses — for one workflow where a silent change creates real risk.
Six defined deliverables
Instrumentation review
A written assessment of the workflow's trace coverage around one agreed failure risk, flagging where reasoning steps are not captured and which steps' disappearance should page someone.
Golden baseline
A validated reference run, committed to your repository, that future runs are compared against.
Governance policies
Three to five policies authored for your workflow, delivered as a ruleset with written rationale for each rule.
CI deployment gate
A GitHub Actions or GitLab CI configuration that fails a pull request when reasoning regresses against the baseline, and comments the diff explaining what changed.
Audit and provenance report
What the baseline established, which policies apply, what they would have caught, and how to present that to an auditor or a customer.
Two calls
Kickoff and handover, plus written async support throughout, answered within two business days.
What the instrumentation review examines
Workflow evidence
One representative run and one synthetic or redacted failure scenario for the selected workflow.
Trace vocabulary
Whether the current events and priorities make the important execution steps visible.
Evidence gaps
Where the trace is missing, ambiguous, or too weak to support a dependable automated gate.
Next decision
Whether to implement internally, request separately scoped help, gather better evidence, or stop.
Intake before payment
Request
Submit a synthetic or redacted description of one workflow and its failure risk.
Accept
Confirm the written scope, review emphasis, and kickoff timing.
Invoice
An invoice is issued only after both sides accept the scope and timing — 50% on signature, 50% on delivery, net 15. There is no self-serve checkout at this scope.
Kickoff
The 30-day engagement begins on the agreed kickoff date after the first invoice.
Handover
Receive the baseline, the policy ruleset, the CI gate, and the audit and provenance report.
Clear boundaries
It does not include code written or debugged in your repository, a broad application rewrite, hosted infrastructure, a managed dashboard, multiple workflows, on-call or incident support, legal advice, an SLA, indemnity, or compliance certification.
DProvenanceKit evaluates observable, instrumented execution. It does not expose hidden chain-of-thought, guarantee factual correctness, or detect every possible AI failure. Keep secrets and confidential client data out of the public intake.
Bring one workflow and one failure risk.
Submitting the intake starts a fit and scope review. It does not create a contract or payment obligation.
Use synthetic or redacted information in GitHub. Send sensitive requirements through a private channel.