Decision Provenance Standard™

Badge maker

Show that you use the Standard

Write your declaration, with your own AI if you like, and get one piece of code: the badge, with your declaration inside it.

What the badge is, and is not

Nothing you type leaves this page. It has no server, stores nothing and counts nothing.

1What are you declaring?

2Write your declaration

With your own AI

Copy this prompt into the AI assistant you already use. It asks you about your Charters one question at a time, works out your Level with you, and ends with a block of data. Paste that block below. Your AI helps you judge; the claim stays yours.

Read the prompt

Its source, with the criteria it is built from: the declaration kit on GitHub.

Using a coding agent? The same check comes as an agent skill that reads your actual records and writes the declaration from the evidence.

Or fill it in yourself

What each Level means, and what it looks at. Each Level includes everything in the Levels below it.
Level 1: Charter-Conformant (§7.2)

Your rulebook for one area of decisions, which the Standard calls a Charter, is written down in full, the records kept under it can be found in one place, and each record carries the fields the Standard asks for at its stage. It suits an organization that has set up a Charter and is starting to keep decision records under it.

What it looks at:

  • A complete Charter: every field the Standard lists is actually filled in, not just labeled complete. A few fields are needed only in some cases, for example when records are about staff below executive level. L1-01
    Exact check

    Is there a written Charter for this area of decisions, with every field the Standard requires filled in, so that it has reached the "fields-completed" state?

    How to judge: Check the fields themselves. A "fields-completed" label on the Charter is not evidence on its own: "A Charter that omits any required field at the field's required-at-state has not reached that state" (§3.2). A field counts when it is present and meets its definition in §3.2: for example, accountable_owner must name one person, not a role. (Which record types the schedule lists is judged under L1-03, not here.) Every Charter at "fields-completed" has these filled in (§3.2, §3.3): charter_id, charter_name, decision_class, accountable_owner, created_at, inside_decisions, outside_decisions, mode_declaration, cadence, record_location, re_decision_triggers, escalation_rule, schedule_of_records and conformance_level_declared. It also needs disclosure_metadata_pointer when mode_declaration is mode-2 or mode-1-with-embedded-mode-2-summary (§3.2). Two more are needed only in some cases (§3.1): use_case_scope_limit_declaration, when any record would describe a person below executive level; and works_council_consultation_record, when the Charter works in an EU or UK country with a works council (such as Germany, France or the Netherlands) and covers records at function-leader level or below. Recommended, not required (§3.1): for Charters whose records describe people at function-leader level or below, the employment counsel of record (named_employment_counsel_of_record). Missing it does not fail this criterion; list it as a suggestion. The use_case_scope_limit_declaration must be one of the scopes §3.1 lists (audit-readiness; internal-optimization; team-level-measurement, at team-leader level and above; or individual-development-coaching with its three sub-fields affirmer_consent.coaching_consent_record_pointer, excluded_downstream_uses and hr_of_record_charter_scope_confirmation): "free-text or hybrid scopes are not conformant" (§3.1). In the works_council_consultation_record, the consultation completion date must be on or before the Charter's "fields-completed" date (§3.1). A record's level is its altitude field (§6.2.3): executive, function-leader, team-leader or individual-professional; if the records carry no such field, ask which levels they are at. A field may use another name if it means the same thing (§3.2). One missing or wrong field can fail two criteria: for example, a role named as owner fails L1-01 and L1-05, and a missing escalation rule fails L1-01 and L1-07. That is intended: record it under both.

  • A declared drafting method, one of three: a person drafts; an AI system drafts and a named person reviews; or a person drafts with an AI-drafted summary inside. L1-02
    Exact check

    Does the Charter declare how its decisions are drafted, using exactly one of these three values: "mode-1" (a person drafts), "mode-2" (an AI system drafts and a named person reviews and signs off), or "mode-1-with-embedded-mode-2-summary" (a person drafts, with an AI-drafted summary inside)?

  • A schedule of records: the Charter's list of the kinds of records it will keep. At least decisions, reopened decisions, escalations and changes to the Charter, plus reviews of the labels on AI-drafted content where AI drafts. L1-03
    Exact check

    Does the Charter commit to a list of the records it will keep, at least by type: decision records, re-decision records, escalation records and Charter-amendment records, plus disclosure-review records when the Charter needs them?

    How to judge: Disclosure-review records must be listed when the Charter's mode_declaration is mode-2 or mode-1-with-embedded-mode-2-summary (§7.2.1). They should be listed when a mode-1 Charter's records embed AI-drafted content that carries a disclosure block (§4.7): that is a recommendation, so leaving them out does not fail this criterion, but put it on the list of fixes. They are not needed for a mode-1 Charter whose records carry no AI-generated content. Nor are they needed for AI-drafted outputs outside the Standard's disclosure requirement (§4.6): outputs made outside the EU that, as the organization has checked, will not reach, and are not reasonably foreseeable to reach, people in the EU, which the Charter declares outside it (§4.6.1; a Charter written before v1.1 of the Standard may rely on this without the declaration). Such outputs carry no disclosure block, so they need no disclosure-review record. A Charter written before v1.1 whose schedule met revision 8's requirement remains valid without adding disclosure-review records (§7.2.1). Ask about this only for a mode-2 or mode-1-with-embedded-mode-2-summary Charter that does not list disclosure-review records.

  • One lasting place where the records live, searchable at least by type of record and by date, with each record opening from its own link. A simple list giving each record's type and date is enough for the search. L1-04
    Exact check

    Does the Charter point to one lasting place (an index) where its records live, can that index be searched at least by record type and by date range, and does each record listed there open from its own location?

    How to judge: A table or list that gives each record's type and date counts as searchable by record type and by date range. Each record must also open from its own record_location: "A schedule whose Charter index resolves but whose individual records do not ... is a Level-1 conformance failure even if the schedule-enumeration field is populated" (§6.3.2).

  • An owner: one named person accountable for the Charter, not a role, a team or a department. L1-05
    Exact check

    Does the Charter name exactly one person as its accountable owner (a person, not a role, a team or a department)?

  • At least two triggers that reopen a decision: one based on how the decision is working out, and one based on a change outside the organization. L1-06
    Exact check

    Does the Charter set at least two triggers that reopen a decision: at least one based on outcome evidence (how the decision is working out) and at least one based on market evidence (a change outside the organization)?

  • An escalation rule: a stated, exact condition that moves a decision out of its usual forum, not "when it feels stuck". L1-07
    Exact check

    Does the Charter set an escalation rule with a named, exact trigger: a stated condition that moves a decision out of its usual forum (not "when it feels stuck")?

    How to judge: What counts is a named, exact trigger (§3.2). The rule must move the decision out of the Charter's standing forum (§3.2, §7.2.1); where a Charter has no higher forum, the text does not say what counts, so grade it "not sure" and say why.

  • Complete records: every record kept under the Charter carries every field the Standard requires at the stage it has reached, under the Standard's own field names. L1-08
    Exact check

    Does every record carry every field the Standard requires at the state it is in?

    How to judge: "A field that is required at a lifecycle state but absent at that state is a Charter conformance failure at Level 1" (§6.2.4, pointed to from §7.1). Section 6 lists each record field with the state at which it becomes required: §6.2.1 when the decision opens (for example decision_id, charter_id, accountable_owner, dispatch_mode and dispatched_at), §6.2.2 when it is drafted, and §6.2.3 when it is closed, with the rows that name their own state (for example altitude from draft onward, review_log from reviewed, and affirmation_record, seal_hash and seal_algorithm at affirmed, §5.1(3)). Some fields are required only in some cases: for example drafting_authority when an AI system drafts, consent_posture below executive level, and the redaction fields on a redaction-event record. A field that becomes required only at a later state is not missing before that state. Record fields use the Standard's names (see the rule on record field names). One missing field can fail this criterion and a Level 2 criterion too, for example a missing seal_hash on an affirmed record (L2-06): that is intended; record it under both. A closed (affirmed) record has passed through reviewed (§5.1), so review_log is required on it. A field missing from an affirmed record cannot be added later, because affirmed records are never edited (§5.1(3)), and superseding the record keeps the original in full, so the gap stays; record it honestly. If the Charter has no records yet, there is nothing to check, and this criterion is met.

Level 2: Mode-Disambiguated (§7.3)

On top of Level 1, every decision record says whether a person or an AI system drafted it, content drafted by AI carries a label (unless the Charter places it outside the Standard's disclosure requirement), and a named person signs off each decision. It suits an organization already keeping records under its Charter, especially one that uses AI to draft them.

What it looks at:

  • A drafting label on every decision record: whether a person or an AI system drafted it, set when the record is opened and never changed on that record; a change of mode is recorded as a new record. L2-01
    Exact check

    Does every decision record under the Charter carry its dispatch_mode field (who drafted it: a person or an AI system), set when the record was opened and never silently changed?

    How to judge: Met when every decision record carries dispatch_mode and no record's dispatch_mode was changed on the record itself: the mode "cannot be silently mutated thereafter (mutation is a re-dispatch event with its own decision record)" (§6.2.1). A change of mode appears as a new, re-dispatched record; for a demotion from AI-drafted to person-drafted, the new record carries prior_state_archive pointing to the earlier one (§4.5). A Charter amendment does not change the mode of records already made: they "remain bound to the pre-amendment Mode" (§4.5). A history of past values is not required: a record's current value is its dispatched value (§7.3.1).

  • A disclosure block on every AI-drafted record, unless the Charter places it outside the Standard's disclosure requirement: the label that gives five facts, namely who stands behind it (a person, the organization, or both), which AI system drafted it, for which countries, what kind of content it is, and when it was made. Only where an AI system drafts records. L2-02
    Exact check

    Does every AI-drafted (mode-2) record that the Standard's disclosure requirement covers carry a complete disclosure block with all five required fields: declaring authority, AI system identity, jurisdictions it applies to, content type, and generation timestamp?

    Applies only if: The Charter has any records drafted by an AI system (mode-2), other than outputs outside the Standard's disclosure requirement: those the Charter declares outside it, or, for a Charter written before v1.1, outputs that already met the §4.6.1 test (§4.6.1; see L1-03).

    How to judge: The declaring authority may name the person who prepares the disclosure, the organization they act for, or both: any of the three counts, though the Standard asks new records to name both (§4.6.2). It is never the AI system's vendor.

  • A disclosure block at the exact spot where AI-drafted content sits inside a record a person drafted, unless the Charter places that content outside the Standard's disclosure requirement. Only where person-drafted records contain AI-drafted content. L2-03
    Exact check

    Does every person-drafted record whose AI-drafted content the Standard's disclosure requirement covers carry a disclosure block at the point where that content sits?

    Applies only if: The Charter has any person-drafted records with AI-drafted content inside them (records flagged mode_1_edge_case_flag), other than embedded content outside the Standard's disclosure requirement: content the Charter places outside it, or, for a Charter written before v1.1, content that already met the §4.6.1 test (§4.6.1, §4.7; see L1-03). Until the Charter has such a record, there is nothing to check and this criterion does not apply (§7.3.2, "When there is nothing yet to check").

  • A regular drift check: person-drafted records are sampled at the rates the Standard sets, a named peer reviewer confirms any the sample flags, and the latest run found none that should have been marked as AI-drafted. Only where there are person-drafted records. L2-04
    Exact check

    Has the sample audit run at the rate the Standard sets (15% rolling; every one of a Charter's first 100 records; 30% for Charters declaring the embedded-summary mode), with a designated peer reviewer confirming the records it flagged, and did the most recent run end with no peer-confirmed findings of records that should have been marked as AI-drafted?

    Applies only if: The Charter has person-drafted records to sample (mode-1 records, including those with AI-drafted content inside). Until it has, there is nothing to audit and this criterion does not apply (§7.3.1; §7.3.2, "When there is nothing yet to check").

  • A recorded sign-off on every affirmed record. An affirmation is a person actively signing off a decision; its record shows when, by whom (the accountable owner or a named delegate) and how. Closed records count as affirmed; drafts do not. L2-05
    Exact check

    Does every affirmed record carry an affirmation record saying when, by whom (the accountable owner or a named delegate) and how a person affirmed it?

    Applies only if: The Charter has any affirmed records: records that are closed, or marked affirmed. Drafts and records still awaiting sign-off are not affirmed records. Until the Charter has one, there is nothing to check and this criterion does not apply (§7.3.2, "When there is nothing yet to check").

    How to judge: Met only when each affirmed record says all three: when, by whom and how. L2-05 and L2-07 both turn on how each affirmation was made, so ask about it once and use the answer for both. The person who affirmed must be the accountable owner or a named delegate (§6.2.3). A closed record counts as affirmed here, because the Standard expects every closed decision record to have been affirmed by a person, with that affirmation recorded (§7.1): a closed record with no affirmation recorded fails this criterion. If the person does not know how the affirmations were made, record "not sure"; if they say it is not recorded, "not met".

  • A seal on every affirmed record, made at the moment of sign-off. A seal is a digital fingerprint of the record that shows whether it was changed afterwards; a seal added later does not count. L2-06
    Exact check

    Does every affirmed record carry a seal (the seal_hash field) stored when it was affirmed?

    Applies only if: The Charter has any affirmed records (closed, or marked affirmed; see L2-05). Until the Charter has one, there is nothing to check and this criterion does not apply (§7.3.2, "When there is nothing yet to check").

    How to judge: The seal is computed and stored at the moment the record is affirmed (§5.1(3)). A seal added later does not count, so a record affirmed before sealing began cannot meet this criterion. Seal every record at the moment it is affirmed from now on: that stops the gap growing, but it does not close it for records already affirmed without a seal.

  • Real sign-offs: in the organization's own recorded sample of affirmed records, every affirmation was an active act by a person, never time passing, silence or a default approval. L2-07
    Exact check

    In the organization's own recorded sample of affirmed records, was every affirmation an active act by a person, never time passing, silence, or a default approval?

    Applies only if: The Charter has any affirmed records (closed, or marked affirmed; see L2-05). Until the Charter has one, there is nothing to check and this criterion does not apply (§7.3.2, "When there is nothing yet to check").

    How to judge: The sample is one the organization took and recorded itself (for example in a review log). Do not pick a sample yourself. This turns on the same fact as L2-05 (how each affirmation was made): use the answer already given. If no sample has been taken and recorded, record "not met"; if the person does not know whether one exists, "not sure".

  • The drafting authority on every affirmed record that an AI system drafted, in whole or as a summary inside it: a pointer to the role under which your organization lets that system draft (its name and version are optional). This is separate from the person who signed off. L2-08
    Exact check

    Does every affirmed record that is AI-drafted, or carries an AI-drafted summary, record its drafting authority: a pointer to the role under which your organization lets the AI system draft (the system's name and version are optional)?

    Applies only if: The Charter has any affirmed records (closed, or marked affirmed; see L2-05) that are AI-drafted (mode-2) or carry an AI-drafted summary (mode-1-with-embedded-mode-2-summary). Until the Charter has one, there is nothing to check and this criterion does not apply (§7.3.2, "When there is nothing yet to check").

    How to judge: The drafting authority is the record's drafting_authority field (§6.2.3). Its deployer_role_pointer points to the role under which your organization authorizes the AI system to draft (for example "pricing team drafting assistant under Charter pricing-decision"); the system's name and version are optional. It is not the person who affirmed the record (affirmed_by or affirmation_record), and not the disclosure block's declaring authority: those name people or the organization, not the AI system. It must use the Standard's field name, drafting_authority (see the rule on record field names).

  • Protection for records about people: records of one person's own work are written only where the Charter allows that level for their use, point to that person's active consent, stop when consent is withdrawn, and are readable only by the person who signed them off and those the Charter names; sign-offs on records about function or team leaders check that the Charter allows that level. Only where there are such records. L2-09
    Exact check

    For records about one person's own work (individual-professional level): was each written only where the Charter's use-case scope allows that level for the use the record serves, does each carry a pointer to that person's active consent record, are no records added or affirmed after consent was withdrawn, and can only the person who affirmed the record and the readers named in the Charter's use-case scope read them? And for records at function-leader or team-leader level: does each sign-off check that the Charter's use-case scope allows that level before the record is sealed?

    Applies only if: The Charter has any records at function-leader, team-leader or individual-professional level (see L1-01). Until the Charter has one, there is nothing to check and this criterion does not apply (§7.3.2, "When there is nothing yet to check").

    How to judge: §6.2.3.1 sets these checks for the system that controls access to the records, and applies them to AI systems too: an AI system drafting at these levels must act under a role the Charter's use-case scope allows. An organization whose access control does not perform them "SHALL NOT self-declare Conformance Level 2 or above" (§6.2.3.1). Recommended, not required (the text recommends documenting it before declaring Level 2; missing it does not fail this criterion): for records at team-leader level or below, a minimum group size for team-level records, set by the organization (for example through a data protection impact assessment), written down (in the Charter's works_council_consultation_record, or in your data protection impact assessment where no works council applies) and enforced when records are written. This comes from Appendix G §G.11.3, which no core section repeats, so it reads as a recommendation; if it is missing, list it as a suggestion.

  • A deletion record for every removal of information: who confirmed the deletion, when, how the data was deleted, and how the deletion was checked. Only where information has been removed. L2-11
    Exact check

    Does every redaction-event record carry a deletion attestation with all four parts: who attested, when, how the data was deleted, and how the deletion was checked?

    Applies only if: The Charter has any redaction-event records (records of removing information). Until the Charter has one, there is nothing to check and this criterion does not apply (§7.3.2, "When there is nothing yet to check").

Level 3: Continuously Auditable (§7.4)

On top of Levels 1 and 2, the Charter keeps running as written: decisions are reopened and escalated when its rules say, its own checks run on schedule, and its records can be searched and exported for an audit at any time and stay findable for as long as the Charter says. It suits an organization that expects auditors, lawyers or regulators to ask for its records.

What it looks at:

  • Reopening on time: the triggers that reopen decisions have produced those records at the pace the Charter declares, with none missed. L3-01
    Exact check

    Have the Charter's re-decision triggers produced re-decision records on the cadence the Charter declares, with no missed firings?

  • Escalations on record: each time the escalation rule fired, a record gives the outcome and the escalation owner's call. L3-02
    Exact check

    Each time the escalation rule fired, was an escalation record produced, stating the outcome and the escalation owner's call?

  • Labels kept current: every disclosure block has been reviewed within the Charter's review cycle, shown by a review date on the block or by a review record that names it. Only where records carry disclosure blocks. L3-03
    Exact check

    Was every disclosure block reviewed within the review cadence the Charter declares: shown by a last_reviewed_at date on the block, or by a disclosure-review record dated within the cadence that names the record?

    Applies only if: The Charter has any records carrying a disclosure block.

    How to judge: Either counts (§7.4.1): the block's last_reviewed_at, where the implementation keeps one, or a disclosure-review record (§6.3.1) dated within the cadence that names the block's record. Where the block is stored inside an affirmed record, which is not edited after close (§6.2.3), a disclosure-review record can show its review (§7.4.1). A review that has expired does not meet this criterion.

  • Records ready for an audit: they can be searched and exported on demand by type, date, drafting method, owner and trigger, within the response time you have stated. L3-04
    Exact check

    Can the records be searched and exported on demand for lawyers and auditors, by record type, date range, drafting mode, accountable owner and re-decision trigger, within the response time your organization has stated?

  • A recent level check: your own check of which Level you reach (the Standard calls it the conformance-level reporter) has run within the Charter's reporting cycle. L3-05
    Exact check

    Has your level check (the Standard calls it the conformance-level reporter) been run within the reporting cadence the Charter declares?

  • Replaced records kept whole: when a record is replaced, the old one is kept in full and unchanged, and the new one points to it. L3-06
    Exact check

    When a record is replaced by a newer one, is the old record kept in full and unchanged, with the new record pointing to it (supersedes)?

  • Records kept findable over time: the index and every record open from their locations, record IDs never change, each record names the version of the Charter it was made under, and each kind of record is kept for a stated period, with any removal or transfer at the end recorded. L3-07
    Exact check

    Are the records findable and retained as §6.4 requires: each location resolves, identifiers are stable, each record names the Charter version it was made under, and retention follows the schedule?

    How to judge: Level 3 reads the discoverability and retention rules of §6.4 (§6.5.2, pointed to from §7.1). Findable (§6.4.1): the Charter's index and each record open from their record_location for the people the Charter's distribution rule names; decision_id and charter_id never change, including through a move to another system; and each record names the version of the Charter it was made under. Retained (§6.4.2): the Charter declares a retention period for each record type in its schedule, either as a specific duration or by naming the retention requirement it follows ("indefinite" or "as needed" is not a declared period); records stay findable for that period; and when a record is deleted, moved out of reach or transferred to a successor system at the end of it, that is itself recorded. Which period applies is for the organization to determine (§6.4.2); this criterion checks only that a period is declared and kept.

3Your badge and declaration, in one paste

One piece of code carries the badge, a small "Our declaration" fold-out that anyone can open and read, and the same declaration as data for search engines and tools.

Preview

On a light page

On a dark page

For your website
Complete step 2 first.
For a README on GitHub
Complete step 2 first.

GitHub does not run pasted scripts, so your declaration's data goes inside the badge file itself. Download it, commit it next to your README as dps-declaration-badge.svg, then paste the code above.

The declaration as data, for your own decision register
Complete step 2 first.

The Standard asks you to keep your self-declaration in your own decision register (§7.1).