The model assumes a record arrives with the claim. For the evaluation scenarios it does, because the scenarios supply them. For a tool it does not, and the instantiation section records this as an open problem of the artefact rather than of the code. This section addresses it, by asking of each field what a plant can actually supply.
The question is answerable now, and was not before, because a record no longer has to be complete to be useful. A field that cannot be supplied leaves an axis undetermined rather than defeating the comparison, so the task is not to manufacture every field but to establish which come free, which need a convention, and which are genuinely absent.
What a source already carries
Two fields are recoverable from the system that produced a value, with no new instrumentation.
Acquisition is usually implicit in the source itself. A value read from a sensor address is a measurement; a value written by an operator through a human-machine interface is a report; a value produced by an estimator or a model is an inference or a generation. The mapping from source to acquisition kind is a configuration a plant makes once, and it is exactly as reliable as that configuration: an estimated value published on a tag indistinguishable from a measured one will be constructed as a measurement, and the discipline will be wrong about it. That is a real failure mode and it is a failure of the plant's tagging rather than of the model, which is worth saying because the remedy is available and cheap.
Establishment time is carried by most industrial data already. Historians timestamp, OPC UA carries a source timestamp distinct from the server timestamp, and controllers stamp on acquisition. The distinction between when a value was established and when it was received is one those systems already draw, and the record wants the former.
What needs a convention
Two fields exist in a plant's knowledge but not in its data, and require someone to state them once.
Rate of change is a property of the measured quantity rather than of any reading of it. A tank level moves over hours, a pressure transient over milliseconds, and nothing in the data says which. It is configuration, attached to a tag or a class of tags, and it is the kind of thing a process engineer knows and has never had to write down for a machine. The cost is real but bounded, and it need not be precise: freshness is compared against an act's tolerance, so an order of magnitude is usually enough to decide.
Authority is likewise convention. Who stands behind a value is known in a plant, in the sense that people know which instruments are calibrated, which loops are maintained, and which contractor's readings are trusted. It is almost never a recorded property of the data. Attaching it is a mapping from source to responsible party, and the validity status the SPKI reading added has the same character: a calibration certificate has an expiry, and whether it still holds is a fact the plant has and the data does not.
What has no counterpart
Established scope is sometimes recoverable and often not. An instrument's placement implies the scope of what it establishes, and that placement is documented in a piping and instrumentation diagram rather than in the data stream. Where the diagram is machine-readable the mapping is available; where it is not, scope is a convention like authority, and where the claim is derived rather than measured the scope of the derivation is not documented anywhere.
Origin identity is the genuine gap. The record's independence test rests on identifying the typed event a claim descends from, and industrial systems do not identify readings as events. A historian stores a value at a timestamp on a tag; it does not issue an identifier for the act of measuring that a second claim could later be compared against. So two claims descending from the same reading cannot be recognised as sharing an origin from the data alone.
Two things follow, and they are different in kind. Where a claim is established directly, an origin identifier can be minted at construction, from the tag and the source timestamp, which is stable and reproducible and costs nothing. That covers the common case. Where a claim arrives already derived, having passed through a calculation or a person before reaching the boundary, its ancestry is not recoverable and no identifier can be minted that means anything. Those claims carry an empty origin set and are undetermined on any demand that turns on independence, which is the correct outcome and not a workaround: the model cannot tell whether they corroborate, and it says so.
Two provenances, and why the record must carry both
Building the first adapter established something the model above states too weakly. This entry already observes that a configured mapping is exactly as reliable as that configuration, and treats a plant publishing an estimate on a tag indistinguishable from a measured one as a failure of tagging. That is true and it is not the whole problem. The record as specified above cannot express the difference at all, so the receiver cannot apply its own judgement to it.
A basis record contains claims about a claim's basis, and those claims have origins of their own. Saying that a value's acquisition was a measurement is itself an assertion, made by somebody, on some basis. The model tracks where the claim came from and, until now, said nothing about where the assertions describing it came from.
So two provenances have to be named separately, because they answer different questions and can diverge.
Evidential ancestry is what the claim rests on: the origin set, the typed events it descends from, and the elisions recorded against it. This is what the derivation rules govern.
Construction provenance is how each field of the basis record came to be populated: observed from the source response, supplied by a named configuration profile, or derived by the constructor. This is what the adapter knows and what nothing previously carried.
They can diverge, and the divergence is the point. A historian reading may have entirely sound evidential ancestry, descending from a genuine measurement event with an identifier minted at construction, while its asserted scope comes from a spreadsheet nobody has maintained for three years. The claim about the world is well founded; a claim about the claim is not. An act may reasonably accept the first and refuse to rely on the second.
What this changes in the record
Three things travel that did not before. The constructor's identity, so a receiver knows what built the record. The source profile's identity and version, so a receiver knows which configuration supplied the fields the source did not. And the provenance of each populated field, so a receiver can tell an observation from an assertion.
The requirement is stated per field and inside the demand, not globally. An act names the provenances it will accept for each axis it constrains: an advisory display may accept configured scope, a valve movement may require scope to have been observed at the source. A field whose provenance is missing cannot satisfy a requirement that asks for one, so the comparison is unknown rather than failed, because nothing has established how the field was populated and that is a gap rather than a finding against it. A field the act does not ask about is unaffected.
Making this a property of the demand rather than a rule of the model matters. A global requirement that every record carry provenance would be a universal demand imposed outside the demand model, and it would refuse records for reasons no act stated. The discipline is action-relative or it is nothing.
What observed does not mean
The narrow reading is load-bearing. Observed means the constructor took this metadata directly from the identified source response, and nothing more. It does not mean the source observed the physical process, that the source metadata is correct, that a value was physically measured, that an instrument is calibrated, or that a tag-to-asset mapping is valid. A historian's own timestamp is observed and may still be wrong.
Allowing the word to drift would rebuild the failure this work is named for one level up, with a metadata assertion acquiring authority its basis does not warrant.
Where the recursion stops
The obvious objection is that a source profile is a claim, so it needs a basis, which is a claim, and so on. The regress is real and the model does not attempt to close it. The adapter, its configuration, the profile's author and version, and the process governing changes to that profile are declared as a trust boundary. Facts inside it are asserted, attributed and versioned; they are not independently established.
What the discipline contributes is that the boundary is visible at the point of adjudication rather than invisible or purely local. Attestable records and attributes the constructor's assertions. Whether that constructor should be trusted is a question for external assurance, and a receiver can now apply a policy to it because the attribution travels with the record instead of sitting in an adapter log the receiver never sees.
What the construction method is
Construction is therefore a mapping, not an inference. For each source a plant configures its acquisition kind, its rate of change, its authority and validity, and its scope where known. At construction time the value's timestamp becomes establishment time, the configured properties are attached, and an origin identifier is minted from the source and timestamp where the claim is established directly. Fields with no configuration and no source are left absent.
The method deliberately does not infer. It does not guess an acquisition kind from a value's behaviour, or a scope from a tag's name, because a wrong field is worse than an absent one: an absent field produces undetermined, which is visible, and a wrongly inferred field produces a confident verdict that is wrong, which is the failure this whole work is about.
What this costs a plant, and what it returns
The configuration burden is one mapping per source, covering four properties, of which two are already known to the process engineers and none requires new instrumentation, plus one named configuration profile per plant, identified and versioned, whose fields the mapping populates and against which each populated field records whether it was observed, configured or derived. The per-source cost is the four properties; the profile is named once and carried, not repeated per source. That is not free and it is the honest price of the discipline, and it is bounded by the acts a plant wants adjudicated rather than by the size of its tag space: a plant configures the sources feeding the acts it cares about and leaves the rest undetermined.
What it returns is the reason the third verdict matters. A plant that configures nothing can still run the discipline and will learn which of its acts are undecidable and on which axis. That map is the argument for what to configure next, expressed in acts rather than in principle, and it is available on the day the library is installed rather than after a programme of instrumentation.