Skip to content

03 / The attribution graph

Six product layers, one compact graph.

The customer-facing chain spans invocation, service, code, identity, organization, and budget. The engineering graph uses five nodes and eight relations; financial allocation remains separate from ownership.

Question

How does the graph connect AI usage to an accountable owner without forcing a complete path?

Mechanism

How the mechanism works

Five engineering node types keep the graph compact. Eight governed relation types define the eligible structural paths. Budget responsibility remains organization context and a governed relationship, rather than becoming a sixth engineering node.

Invocation
The governed model-use record
Service
The runtime service or workload context
Project
The code or project ownership context
Identity
Human, service, shared, or transient identity
Organization
Event-time organization and budget context
Eight governed relations
SourceTargetExpected whenAbsence validEvidence examplesPossible output states
InvocationServiceA service context is available for the invocationYesGateway workload, runtime trace, provider metadataDeterministically resolved, Strongly inferred, Ambiguous, Unknown, Not identifiable
InvocationIdentityAn eligible human, service, shared, or transient identity is observableYesService identity, user context, credential metadataDeterministically resolved, Strongly inferred, Bounded, Ambiguous, Unknown, Not identifiable
InvocationProjectThe invocation carries eligible deployment or project contextYesDeployment identifier, job metadata, project bindingDeterministically resolved, Strongly inferred, Ambiguous, Unknown
ServiceIdentityA service identity or governed operator relationship existsYesIdentity directory, workload identity, service-account bindingDeterministically resolved, Strongly inferred, Bounded, Unknown
ServiceProjectA deployed service can be connected to a governed projectYesCI/CD metadata, deployment manifest, source-control bindingDeterministically resolved, Strongly inferred, Ambiguous, Unknown
IdentityOrganizationAn event-time organization relationship is availableYesDirectory group, effective-dated organization hierarchyDeterministically resolved, Strongly inferred, Bounded, Unknown, Not identifiable
IdentityProjectA governed identity-to-project relationship is eligibleYesRepository membership, deployment role, project access metadataDeterministically resolved, Strongly inferred, Ambiguous, Unknown
ProjectOrganizationA governed owning organization relationship existsYesCode ownership, project catalog, organization hierarchyDeterministically resolved, Strongly inferred, Bounded, Ambiguous, Unknown

Annotated visual

Inspect the path and its unresolved states

Six product layers to five engineering nodes
Product layers
  1. Model invocation
  2. Service
  3. Code or project
  4. Identity
  5. Organization
  6. Budget responsibility
Evidence and time basis resolve at the measurement point
Engineering nodes
  1. Invocation
  2. Service
  3. Project
  4. Identity
  5. Organization includes budget context

In summary: model invocation maps to Invocation, service to Service, code or project to Project, identity to Identity, and both organization and budget responsibility to Organization context. The graph contains five node types. Budget allocation remains a separate result.

Concrete example

Apply the mechanism to one synthetic workload

Illustrative synthetic example

Decision record

Graph-backed synthetic record

Mechanism . Describes how the product is designed to work.
Workload
support-routing-workload
Invocation
invocation.synthetic.0241
Service
support-router
Project or code owner
Customer Operations Platform
Identity
svc-support-router
Organization
Customer Experience Systems
Budget responsibility
CX Automation

Operational confidence

Operational confidence

0.91

Output state

Strongly inferred

At or above the 0.80 review threshold

Explanation
Service, deployment, identity, organization, and billing evidence support one leading path.
Time basis
Event-time, synthetic evaluation window
Source health
All enabled synthetic sources healthy
Action eligibility
Decision support

Evidence sources

  • Provider billing record
  • Deployment metadata
  • Service identity
  • Organization hierarchy

Alternative candidates

  • Support Experience team, retained as an alternative
  • Platform Infrastructure, runtime owner only

Truth domains

Observed . Directly present in a source record. Inferred . Derived from eligible evidence with uncertainty preserved. Event-time . The state that applied when the governed event occurred.
Output state
Strongly inferred
Time basis
Event-time, synthetic evaluation window
Source health
All enabled synthetic sources healthy
Action class
Decision support
Correction history
No correction event in this synthetic record

Evidence and implementation boundary

What the current claim supports

The schema defines which relation types may exist. The attribution engine evaluates eligible candidate relationships; it does not invent new relation types. The current governed aggregation method remains an implementation concern and is not replaced by visual arithmetic.

Edge versus path confidence: each eligible relationship can carry an edge-specific state and confidence. The final path confidence travels with output state, source health, time basis, alternatives, and intended decision. The visual does not invent a formula or imply that a downstream path can exceed a required weaker edge.

Ownership versus allocation: fractional cost allocation is a separate result. It cannot overwrite ownership attribution.

Known limitations

Unknown and unresolved states remain valid outcomes

  • 01An invocation does not need service or project context to remain a valid governed record.
  • 02A valid absent relationship is different from an unknown relationship and must remain distinguishable.
  • 03Edge confidence and path confidence are distinct and cannot be inferred from an unlabeled visual average.

Decision enabled

Determine which ownership relationships are supported, absent, ambiguous, or still unknown before an attributed decision is used.

The graph makes the attribution basis inspectable: a reviewer can see exactly which relationships support the owner path and where the chain stops.