ProvenanceGuard is a post-generation checker designed to catch a subtle agent error: a statement may be supported somewhere in the available evidence but attributed to the wrong source. That matters when an answer confuses a patient record with general medical literature or an account record with a policy document.
The system reads captured Model Context Protocol tool traces without retraining the original agent. It splits an answer into claims, identifies the most relevant source for each, checks support and compares that source with the one the answer names or implies. It can then allow, block or attempt to repair the response while retaining source identity throughout.
Researchers tested a local-model configuration on 281 real traces from a medical agent. They used separate models for source routing, textual entailment and claim decomposition, with strict checks for numbers, dates and identifiers. Those components are not mandatory, but any replacement needs new calibration. ProvenanceGuard addresses attribution after generation; it does not guarantee that the underlying tools or records are correct.