Back to tools

AgentProvenance

Local-first provenance and security control plane for sandboxed AI agents, correlating agent context with system telemetry into verifiable causality graphs.

Tool categories
Developer tools
Tool links

Tool overview

AgentProvenance is in an early development and public phase, with only 38 GitHub stars and no forks, and no evidence of real‑world deployments, tutorials, or third‑party evaluations. Adoption cannot be confirmed; the limited star count signals only tentative interest, not proven utility.

As a local‑first security control plane built on eBPF and Falco/Tetragon, it correlates sandboxed AI agents’ application context (e.g., task goals, action sequences) with OS‑level telemetry (processes, networking, file access) to produce signable, tamper‑evident causality graphs. This allows security teams to replay, forensically examine, and audit agent behavior in a Git‑like provenance model, supporting risk assessment and compliance.

The project is open source and deployable locally, but operational demands are high: teams need expertise in eBPF sensor management, Falco/Tetragon rule authoring, and Linux observability. No pricing or managed offering has been announced; costs depend entirely on the deploying organisation’s infrastructure. It is not a ready‑to‑use AI security product and is best suited for exploratory integration by security engineering teams.

Related social content