Every governed enterprise system maintains two audit trails: a record of what happened, and a record of the rules that governed what was permitted to happen. The first trail is almost universally well-maintained. The second is almost universally neglected. Business rules live in configuration files, SharePoint documents, database tables, and email chains, all mutable, rarely versioned with rigour, seldom linked in an immutable fashion to the decisions they governed, and frequently inaccessible to future auditors at the granularity required. This paper identifies this structural gap as the Policy Provenance Problem and introduces the Policy Provenance Pattern (PPP) as its solution: a named, reusable architectural pattern in which business rules are treated as first-class versioned artefacts, published through a governed approval workflow, stored in a medium providing immutability guarantees proportional to the governance stakes of the domain, and linked by explicit reference to every decision they governed.
Ravi Kumar Kappagantu (Sat,) studied this question.