Provenance
Provenance records which pipeline run and stage wrote each version of a fact, and from which artifact.
Evidence answers why is this true? Provenance answers how did it get into the ledger?
EKOS does not simply say:
"The customer service uses PostgreSQL."
It says that, and can show the evidence (for instance a connection string in config/db.yaml, line 14) and the write history (which run, which stage — build, commit, commit:rollup — from which source artifact).
ekos ledger audit <object-id> # write history with per-write provenance
The same is available to agents as the ekos_audit MCP tool. In the fact-engine ledger, provenance is stored in a provenance.jsonl sidecar; in SQLite it is columns on each entry.
Entries written before provenance was introduced (RFC 0135) simply have none; the tool reports that rather than inventing it.