> ## Documentation Index
> Fetch the complete documentation index at: https://docs.seynlabs.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get the provenance chain for a rule

> The full four-hop audit chain from a rule back to source records.

Returns the complete chain of custody: rule → the inference log (the exact LLM call that produced it) → the normalized events the model observed → the raw records ingested from source systems. This is what makes every claim auditable. See [Provenance](/platform/provenance) for the full picture.

Responses can be large; a well-evidenced rule may carry dozens of events and records. If you only need to gauge evidence strength, count the arrays rather than rendering them.


## OpenAPI

````yaml openapi.yaml GET /v1/rules/{id}/provenance
openapi: 3.1.0
info:
  title: Seyn API
  version: 1.0.0
  description: >
    Programmatic access to Seyn for your organization.


    - **Ingest** data from any source with the Ingestion endpoints (requires a
    key with the `ingest` scope).

    - **Read** extracted process knowledge: search, rules, libraries,
    provenance, and metrics.


    Authenticate with a bearer API key (`sk_live_*`); each key is scoped to a
    single organization.
  contact:
    name: Seyn Support
    email: support@seynlabs.com
    url: https://seynlabs.com
servers:
  - url: https://api.seynlabs.com
    description: Production
  - url: https://api-dev.seynlabs.com
    description: Staging
security:
  - bearerAuth: []
tags:
  - name: Ingestion
    description: >-
      Push data into Seyn from any source: register a custom source and stream
      records to it
  - name: Knowledge
    description: Natural-language search over extracted knowledge
  - name: Rules
    description: Process rules, the atomic knowledge units extracted by the pipeline
  - name: Libraries
    description: Versioned snapshots of extracted knowledge for your organization
  - name: Patterns
    description: Aggregate pipeline analytics
paths:
  /v1/rules/{id}/provenance:
    get:
      tags:
        - Rules
      summary: Get the provenance chain for a rule
      description: >
        Returns the full audit chain: rule → inference log (the LLM call that
        produced the rule)

        → normalized events the LLM observed → raw records ingested from source
        systems.
      operationId: rulesProvenance
      parameters:
        - name: id
          in: path
          required: true
          schema:
            type: string
            format: uuid
      responses:
        '200':
          description: Provenance chain.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SuccessEnvelope_Provenance'
        '400':
          $ref: '#/components/responses/ValidationError'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        '429':
          $ref: '#/components/responses/RateLimited'
components:
  schemas:
    SuccessEnvelope_Provenance:
      type: object
      properties:
        success:
          type: boolean
          enum:
            - true
        data:
          $ref: '#/components/schemas/Provenance'
        meta:
          $ref: '#/components/schemas/Meta'
      required:
        - success
        - data
        - meta
    Provenance:
      type: object
      properties:
        rule:
          $ref: '#/components/schemas/ProvenanceRuleRef'
        inferenceLog:
          oneOf:
            - $ref: '#/components/schemas/ProvenanceInferenceLog'
            - type: 'null'
        sourceEvents:
          type: array
          items:
            $ref: '#/components/schemas/ProvenanceEvent'
        rawRecords:
          type: array
          items:
            $ref: '#/components/schemas/ProvenanceRawRecord'
      required:
        - rule
        - inferenceLog
        - sourceEvents
        - rawRecords
    Meta:
      type: object
      properties:
        requestId:
          type: string
          description: Per-request UUID; quote in support tickets.
      additionalProperties: true
      required:
        - requestId
    ErrorBody:
      type: object
      properties:
        success:
          type: boolean
          enum:
            - false
        error:
          type: object
          properties:
            code:
              type: string
              enum:
                - MISSING_AUTH_HEADER
                - INVALID_API_KEY
                - KEY_REVOKED
                - RATE_LIMITED
                - NOT_FOUND
                - LIBRARY_NOT_FOUND
                - SOURCE_NOT_FOUND
                - VALIDATION_ERROR
                - INSUFFICIENT_SCOPE
                - PAYLOAD_TOO_LARGE
                - INTERNAL_ERROR
            message:
              type: string
          required:
            - code
            - message
      required:
        - success
        - error
    ProvenanceRuleRef:
      type: object
      properties:
        id:
          type: string
          format: uuid
        description:
          type: string
        processId:
          type:
            - string
            - 'null'
      required:
        - id
        - description
        - processId
    ProvenanceInferenceLog:
      type: object
      properties:
        id:
          type: string
          format: uuid
        model:
          type: string
        promptHash:
          type: string
        tokenCount:
          $ref: '#/components/schemas/TokenUsage'
        latencyMs:
          type: integer
        createdAt:
          type:
            - string
            - 'null'
          format: date-time
    ProvenanceEvent:
      type: object
      properties:
        id:
          type: string
          format: uuid
        action:
          type: string
        entityType:
          type: string
        timestamp:
          type:
            - string
            - 'null'
          format: date-time
    ProvenanceRawRecord:
      type: object
      properties:
        id:
          type: string
          format: uuid
        connectorType:
          type: string
        ingestedAt:
          type:
            - string
            - 'null'
          format: date-time
    TokenUsage:
      type: object
      description: Token counts for a single LLM call.
      properties:
        input:
          type: integer
          minimum: 0
        output:
          type: integer
          minimum: 0
        total:
          type: integer
          minimum: 0
      required:
        - input
        - output
        - total
  responses:
    ValidationError:
      description: Request parameters failed validation.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorBody'
          examples:
            validationError:
              value:
                success: false
                error:
                  code: VALIDATION_ERROR
                  message: Query parameter 'q' is required
    Unauthorized:
      description: Missing or invalid API key.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorBody'
          examples:
            missing:
              summary: No Authorization header
              value:
                success: false
                error:
                  code: MISSING_AUTH_HEADER
                  message: 'Authorization: Bearer <api-key> header is required'
            invalid:
              summary: Unrecognized key
              value:
                success: false
                error:
                  code: INVALID_API_KEY
                  message: API key is invalid or unrecognized
    Forbidden:
      description: API key was revoked.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorBody'
          examples:
            revoked:
              value:
                success: false
                error:
                  code: KEY_REVOKED
                  message: API key has been revoked
    NotFound:
      description: Resource not found in this organization.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorBody'
          examples:
            notFound:
              value:
                success: false
                error:
                  code: NOT_FOUND
                  message: Process rule not found
    RateLimited:
      description: Per-key rate limit exceeded (default 60 req/min/key).
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorBody'
          examples:
            rateLimited:
              value:
                success: false
                error:
                  code: RATE_LIMITED
                  message: Rate limit exceeded for this API key
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: sk_live_*
      description: |
        Bearer token from `app.seynlabs.com` → Settings → API Keys.
        Send as `Authorization: Bearer sk_live_...`.

````