Provenance
git blame answers who changed a line and when. For code an agent wrote, the questions that matter are which requirement motivated it, which prompt and model produced it, what review approved it and which human decisions shaped it. hashd answers all of them because it runs the whole pipeline and records each link as the work happens.
line of code -> git commit -> micro-commit -> run -> prompt + agent call
-> workstream -> story -> requirement -> reviews + human decisions
Query lineage
hashd lineage detects the kind of target automatically:
STORY-NNNorBUG-NNN: everything produced by that story- 7 to 40 hex characters: the full chain for one commit
- anything else: a file path
hashd lineage STORY-0012
hashd lineage a1b2c3d
hashd lineage src/auth/jwt.go
hashd lineage src/auth/jwt.go --lines 42-58
Output formats: --format table (default), --format json and --format markdown. In hashd watch, press I in the diff view to trace a line interactively.
The requirement a story came from is stored verbatim, with its SHA-256 and the git revision and path it was read from.
Export attestations
hashd lineage export <sha> --format slsa
hashd lineage export <sha> --format in-toto
hashd lineage export STORY-0012 --format slsa
- SLSA writes an in-toto statement with a SLSA v1.0 provenance predicate: the story, micro-commit, requirement and origin as external parameters, and the run as the invocation.
- in-toto writes a statement with the full hashd predicate: the commit, a story summary, review decisions and confidence, human decisions, agent calls (model, tokens, duration) and the hash-chain links.
A story exports as an array of attestations, one per commit.
Verify the hash chain
Commit records are linked into a chain: each record stores the SHA-256 of the previous record's canonical JSON.
hashd lineage verify
verify reports total, verified and broken records, and exits non-zero when a link is missing, duplicated, cyclic or mismatched, that is, when a record was altered or removed after the fact.
The chain provides tamper evidence. Cryptographic signing of exports and a public transparency log are not part of hashd today.