Bring your own control matrix.
“We built our own” isn’t an objection — it’s the fit.
The most governed teams already keep a controls spreadsheet. Provenance doesn’t ask them to abandon it — it turns that spreadsheet into live, evidenced governance in three steps.
Import your matrix
Upload the Excel control register your team already maintains. Provenance parses every control and stores it as your own framework — no re-keying.
Evaluate against the estate
Each control runs a deterministic binding over observed facts — authorship, reviews, dependencies, agent configs — and returns evidenced, partial, or flagged.
Prove it, sealed
Flags, evidence, and human attestations render into one framework-mapped report — sealed, timestamped, and verifiable on any date.
Follow one control, end to end.
One row from your spreadsheet — imported as-is, evidenced against your live estate, then frozen into the sealed report.
Your row, exactly as it sits in the spreadsheet your team maintains.
22 of 25 AI-PRs to Tier-1 repos had a recorded human review — 3 did not.
Evaluated against the live estate — an observed fact, not a claim.
Frozen into the framework-mapped report — verifiable on any date.
Derived from your estate — not declared on a form.
A questionnaire records what someone said. Provenance records what actually happened. The overlay is computed per request from observed facts and never persisted as a claim — and a manual “evidenced” with no evidence behind it is rejected. Where a control needs a human, the attestation is a dated, signed decision — evidence of the sign-off, not a ticked box.
“Yes, we review AI-authored changes.” — a box ticked in a spreadsheet, unverifiable months later.
“25 AI-authored PRs merged to Tier-1 repos with a recorded human review; 3 without — here they are.” — observed from the estate, reproducible on any date.
Maps to the standards your auditor reads.
Each control in your matrix carries a crosswalk, so one recorded decision shows where it counts across frameworks — no re-work per standard.
EU AI Act and NIST AI RMF — status derived directly from your estate.
ISO 42001, NIST SSDF, OWASP, CIS — one decision, shown where it counts. “Maps to,” never “certifies.”
The questions teams ask.
What is a custom control matrix?
It's the set of controls your organization is actually measured against — often a spreadsheet your security, risk, or audit team already maintains. Instead of forcing you onto a vendor's fixed framework, Provenance lets you import that matrix as-is and treats each of your controls as a first-class governance object it can evidence against your estate.
How do I import my controls?
Upload your control register as an Excel workbook. Provenance parses each control — its id, name, description, and any framework mappings you've already recorded — and stores it as your tenant's own framework. Re-importing updates in place, so your matrix stays the source of truth as it evolves. No re-keying, no forcing your controls into someone else's taxonomy.
Does Provenance use an LLM to decide whether a control passes?
No. Each control is bound to a deterministic evaluator that reads observed facts from your estate — authorship, review records, dependency manifests, agent-config files — and returns a status (evidenced, partial, awaiting scope, flagged). This is 'evidence then report,' the opposite of a 'classify then derive' approach that asks a model to judge compliance. Deterministic bindings mean the same estate produces the same verdict every time.
Can I just mark a control as 'evidenced' myself?
Not silently — that's the honesty gate. Provenance will reject a manual 'evidenced' status that isn't backed by observed evidence; the estate overlay is computed per request and never persisted as a claim. Where a control genuinely needs human sign-off (a policy attestation, for example), that attestation is recorded as an explicit, dated human decision with a note — evidence of the sign-off, not a box someone quietly ticked.
Which frameworks does it map to — and which does it evaluate?
Provenance evaluates two frameworks built in — the EU AI Act and NIST AI RMF — meaning it derives their status from your estate directly. For other standards (ISO/IEC 42001, NIST SSDF, OWASP, CIS), each control carries a crosswalk mapping so one recorded decision shows where it counts across the standards your auditor reads. The distinction is deliberate and honest: 'evaluated' for the two packs, 'maps to' for the crosswalk — never 'certified.'
Has anyone actually run this on a real matrix?
Yes. We imported a real enterprise security-controls matrix (an Excel workbook) and evidenced it, control by control, against a live multi-repository estate — flags, evidence, and attestations rendered into a single sealed, framework-mapped report. Re-import updates the register in place; the report can be re-generated and its seal verified at any time.
Related from Provenance.
See your evidence this afternoon.
Connect your first repo in minutes — read-only, no credit card, no sales call. Your Provenance Score, your blind spots, and your first board-ready briefing, from your own estate.
