The Chain Is Signed, the Handoff Is Prose: Measuring Provenance Loss at the Model Layer
Abstract
Capability-based delegation already solves provenance. UCAN describes its delegation chain as "by definition a provenance log"; RFC 8693 encodes an ordered actor chain in nested act claims; ZCAP-LD, and the 2026 agent-specific proposals built on them, extend this to multi-hop agent delegation. None of that is in dispute. The gap is elsewhere: the signed chain lives in a token envelope the language model never reads, and the handoff the model actually writes is prose. We measure what that prose carries. Across 480 delegation chains and 1,440 generation hops on four model families, a principal's identity survives to the end of an unprompted chain in 35.8% of cases. One explicit instruction to carry identity forward raises this to 99.6%. Three results are more useful than the headline. First, loss is not gradual: 52.5% of depth-5 chains have already lost full provenance after the first handoff, and only 15 further points are lost over the four hops that follow. Second, model family dominates depth: unprompted preservation ranges from 5.0% to 90.0% across families, an 85-point spread that the instruction collapses to under 2. Third, the instruction is the only arm that fabricates. Zero of 240 control chains invent an identity; 2 clause chains invent a delegating persona, because an instruction to preserve received attributions gives a model no way to distinguish a true attribution from one an earlier hop hallucinated. A signed chain rejects an unsigned link; prose has no such check. We therefore read the clause not as a fix but as a measured floor, and its residual failures as the argument for the cryptographic layer.