When records disagree, do not overwrite one with the other simply because it is newer or appears more often. Preserve both, trace how each value was created, weigh its authority and evidence for the specific context, and document the decision so another person can reconstruct it. No universal rule makes one source authoritative for every kind of record.
What provenance and an audit trail tell you
Provenance is evidence about how a record came to be: which entities and people were involved, what activities produced or changed it, and how it relates to other records. The W3C describes this information as useful for assessing a thing’s quality, reliability, or trustworthiness in its PROV-N Recommendation. Provenance helps you evaluate a value; it does not prove that the value is correct.
An audit trail is a history of relevant actions and decisions. For U.S. federal electronic records, 36 CFR § 1236.10(c) identifies audit trails as an example of an integrity control, alongside requirements addressing reliability, authenticity, usability, content, context, and structure. That regulation applies to its defined federal records context, not automatically to every organization or jurisdiction. See 36 CFR § 1236.10.
Resolve a conflict without losing evidence
- Define exactly what is in dispute. Identify the person, object, transaction, or event the records are supposed to describe. Separate disagreements about identity from disagreements about a value, date, scope, or status; two records that look similar may refer to different real-world things.
- Preserve the competing records before editing. Retain each original value, its source identifier, when it was retrieved or observed, and any transformations already applied. Do not erase a competing value while investigating. These are practical integrity measures; the cited standards do not prescribe one storage implementation.
- Trace each value’s lineage. Record the source or issuing authority, the activity that created or changed the value, relevant times, and the responsible person or process. If a value was derived, link it to its inputs and transformation. The W3C PROV model distinguishes entities, activities, and agents and represents derivation, responsibility, and time; its overview is at PROV Overview.
- Assess each source for this specific decision. Ask whether it issues the attribute, has direct access to issuing information, or can trace its data to an authoritative source. Consider when the information was valid or checked, whether independent evidence is consistent with it, and the purpose for which it was collected. NIST defines authoritative sources in this way for identity attributes; those definitions should not be treated as universal rules for other domains. See NIST SP 800-63A, Revision 4.
- Seek more evidence if the conflict matters and remains unresolved. For identity resolution, NIST guidance allows collecting additional information, evidence, and sources. More broadly, that is a useful evidence-first approach, but it is an application of identity-specific guidance rather than a rule for every record system. Log what you obtained and how it affected the assessment. See NIST SP 800-63A implementation guidance.
- Apply an explicit, governed decision rule. State which source or evidence you accepted and why. Note any precedence rule that applies to this record type, confidence limits, or uncertainty that remains. Do not use “newest wins” or “most repeated wins” as an unexamined shortcut; rules should fit the record, its purpose, and applicable requirements.
- Record the resolution in a protected history. Capture the original competing values, the selected value, evidence references, rationale, the responsible person or process, relevant times, and any follow-up or correction. Protect the history from unauthorized changes and keep enough context for a later reviewer to interpret it.
- Look for recurring causes. Repeated discrepancies can signal stale sources, transformation defects, ambiguous identifiers, or gaps in governance. NIST SP 800-53 control SR-4 describes provenance as a chronology of origin and changes and calls for maintaining and monitoring valid provenance; organizations tailor security controls to their systems and risks. See NIST SP 800-53, SR-4. UK government guidance also recommends data catalogues with metadata, lineage, quality information, and access conditions; see GovS 005: Digital.
How to compare candidate records or sources
There is no universal winning source. Weigh the factors below according to what the record represents and the decision being made.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →| Factor | Questions to ask |
|---|---|
| Authority | Does the source issue the attribute, have direct access to issuing information, or trace its data to such a source? Or is it secondary or self-asserted? |
| Traceability | Can you reconstruct the source, transformations, responsible agents, and derivation of the value? |
| Currency and consistency | When was the source’s information valid or checked? Does it agree with independent evidence? NIST names currency and consistency as criteria for credible sources in the identity context. |
| Integrity and context | Is the record complete and protected from unauthorized alteration? Can a reviewer understand how it relates to other records and the circumstances in which it was created? |
| Fit for purpose | Does this source’s authority and evidence support this particular attribute and decision? Follow the standards and governance that apply to the domain rather than extending identity guidance to unrelated records. |
Keep the trail interpretable and appropriately scoped
A useful history lets a later reviewer follow the chain from original evidence to decision without mistaking a derived or copied value for its source. The W3C PROV specifications provide a vocabulary for relationships among entities, activities, and agents, including time, derivation, responsibility, and links between entities that refer to the same thing. The cited PROV overview and notation are dated 2013; consult the W3C’s current publication index before relying on them as a statement of present standards status.
Keep requirements distinct from guidance. The federal regulation cited above is specific to U.S. federal electronic records; NIST SP 800-63A is about identity proofing and enrollment; SR-4 is a security control organizations tailor to their systems and risk; and GovS 005 is a UK government functional standard. None establishes a universal precedence ranking for all records. Apply the relevant domain, legal, and organizational rules, and preserve uncertainty where the available evidence does not settle the disagreement.
Quick Recap
Rank #3
Rank #2
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

