Diwo
Provenance · Claude Desktop

Ask Provenance from Claude Desktop.

Your controls, your posture, your evidence — in plain language, from the tool your team already has open. Provenance runs as a read-only MCP server inside Claude Desktop.
Read-only and tenant-isolated. It answers from your live estate — board-ready and honest — and it can’t change a thing.
Claude Desktop
Is our AI-written code governed?
66 repos watched. 25 AI-authored PRs merged with 0 recorded approvals, and 1 hallucinated dependency flagged. Start by requiring review on AI merges.
via Provenance · MCP · read-only
Ask, don’t hunt

Your governance, in plain language.

No dashboard spelunking. Ask the question; get the answer, grounded in your live estate.

01

Is our AI-written code governed?

Your Provenance Score with its honest drivers — scanned vs unscanned, reviewed vs unreviewed AI merges.

02

Walk our control register.

Every control with its live status — evidenced, partial, or still grey — mapped to the frameworks you report.

03

Verify last quarter's board report.

The report's seal checked against its frozen bytes — tamper-evident, on demand, from where you work.

Safe by design

A window onto the evidence — not a control surface.

Every tool is a read, tenant-scoped through the same isolation gate the app uses, authenticated by a token you mint and can revoke. Governance decisions still happen in the app, by a human. The MCP server can look; it can’t touch.

It can read

Score · posture · red flags · estate · control register · control evidence · reports · verify seal — 12 tenant-isolated read tools.

It can’t change anything

No create, edit, attest, or delete. Read scope only, on a revocable token, scoped to your tenant.

Proof

It caught its own bug from Claude Desktop.

During live testing, asking Provenance to walk its control register from Claude Desktop surfaced a discrepancy in one of its own control checks — a QA bug we then fixed. The governance layer auditing itself, in plain language, is the strongest evidence that the answers are real.

Frequently asked

The questions teams ask.

What is the Provenance MCP server?

It's a Model Context Protocol server that exposes Provenance to AI clients like Claude Desktop. Once connected, you can ask your estate's governance in plain language — your Provenance Score, posture, red flags, control register, evidence, and report seals — and get answers grounded in your live data, without opening the Provenance app.

Is it read-only?

Yes — entirely. Every tool the server exposes is a read. It can retrieve your score, posture, findings, control register, control evidence, reports, and verify a report's seal. It cannot create, change, attest, or delete anything. Governance decisions still happen in the app, by a human; the MCP server is a window onto the evidence, not a control surface.

Is my data isolated from other tenants?

Yes. Access is authenticated with a personal access token you mint in Provenance, and every tool call is tenant-scoped through the same isolation gate the app uses — the server can only ever see your own estate. The token carries a read scope and can be revoked at any time.

How do I connect it?

In Provenance, open Settings → Access Tokens and mint a token. Add the Provenance MCP endpoint to your Claude Desktop config with that token as a bearer credential. One connection detail matters: the endpoint URL must include its trailing slash. Once connected, the Provenance tools appear in Claude Desktop and answer from your estate.

What can I actually ask?

Anything the evidence supports: 'Is our AI-written code governed?', 'Walk our control register and show what's still grey', 'Which repos have unreviewed AI merges?', 'Verify the seal on last quarter's board report'. Because the answers are grounded in real estate data — with honest coverage caps — they read the way a board-ready briefing should, not like a marketing summary.

Does it work in tools other than Claude Desktop?

The server speaks standard MCP, so it works with MCP-capable clients generally. Claude Desktop is the primary, verified experience today. Customer-facing self-serve access (OAuth, rate-limiting) is on the roadmap; the current experience is designed around your own team's tokens.

See it on your estate

See your evidence this afternoon.

Connect your first repo in minutes — read-only, no credit card, no sales call. Your Provenance Score, your blind spots, and your first board-ready briefing, from your own estate.