Provenance is usually a scramble. The delivery is due, someone asks which shots touched a generative model, and the answer lives in a producer's memory and a Slack thread. The honest fix is to stop treating provenance as paperwork you assemble at the end. When you generate or process media, the record should be written at the same moment the pixels are, not reconstructed weeks later.
That is what we mean by provenance by default. In Asset Foundry, the moment an asset comes out of Forge, it comes out marked. Forge writes a visible watermark onto video, image and document outputs, and it attaches a C2PA Content Credential to image outputs carrying an AI-source assertion. You do not run a second pass to add it. You do not remember to add it. It is part of the same job that produced the file.
Provenance breaks down for a boring reason: it is nobody's step. A conform gets exported, a still gets upressed, a plate gets a generative cleanup, and each of those tools cares about the output, not the paper trail behind it. So the trail is added afterward, by hand, by whoever remembers. The result is exactly what you would expect. Some assets are marked, some are not, and the ones that matter most in a review are usually the ones nobody labelled.
AI provenance media makes the gap sharper. When a portion of your image work involves generative models, "which of these was touched by AI" stops being a curiosity and becomes a question legal, marketing and security all ask independently. If the answer depends on human recall, you do not have provenance. You have anecdotes.
Forge runs 13 media job types across video, image, 3D, audio and documents, and it reaches 60+ generative models behind one governed API. Watermarking and Content Credentials are not a bolt-on beside that. They are applied to the output of the same job. The split matters, so here it is plainly:
To be exact about scope: Content Credentials attach to images, not to every output. Visible watermarking is the mark that spans video, image and document. Keeping those two things separate is the difference between a claim you can stand behind and one you cannot.
A mark on a file is only half the value. The other half is being able to ask about it across everything you hold. That is where the rest of Asset Foundry earns its place. Fabric joins ShotGrid, FileMaker and Airtable natively, plus 300+ more sources through the connector catalog, into one governed knowledge graph, modelled on MovieLabs OMC with 340 fields across 14 entity types. Once an asset and its lineage live in that graph, "show me every image that carries an AI-source assertion on this show" is a query, not a hunt.
Fabric also opens the graph to agents through 23 entity MCP tools. MCP is the open agent-connector standard, so an agent platform can walk your provenance the same way a person would, under the same permissions. Embeddings for that retrieval are computed inside the deployment environment, with no external AI calls, which matters when the thing you are indexing is unreleased work.
And when you need to prove a marked asset is the marked asset, Gateway returns files with checksums and metadata across every store, including LTO tape, read-only, with an audit row on every question. Nexus then verifies checksums on intake and routes deliveries to ShotGrid so the provenance you wrote at generation is the provenance that ships.
Run one of the 13 job types across 60+ models. The output is the deliverable, not a draft you have to finish by hand.
Visible watermark on video, image and document outputs. A C2PA Content Credential with an AI-source assertion on image outputs. Same job, no second pass.
Fabric holds the asset and its relationships, so provenance becomes a query anyone with the right permissions can run.
Nexus verifies checksums on intake and routes to ShotGrid. Gateway can prove, read-only, that the marked asset is the one that shipped.
Any tool can watermark a file if you remember to ask it to. The failure mode is not capability, it is discipline at 2am before a delivery. Making provenance the default takes it off the checklist and out of human memory. The asset that skipped the mark is the one that hurts you in a review, and the only reliable way to never have that asset is to never make marking optional.
This is also why we are careful about what we claim. Content Credentials are on images, not on every output. Watermarking is visible and human-readable, not hidden analysis. Being specific about that is not modesty. It is what lets a security team actually rely on the record instead of discovering its edges during an audit.
Note: Asset Foundry runs on a SOC 2 Type II aligned engineering posture and is designed for MPA content-security best practices. In production deployments content stays in your environment, so the provenance you generate stays inside your walls too.
If you run a post or VFX pipeline, provenance by default means the generative cleanups and upresses ship marked without adding a step to an already tight I/O schedule. If you sit in enterprise brand or compliance, it means "which assets were AI-touched" has a queryable answer instead of a meeting. And if you own security and IT at a studio, it means the label is written inside your walls, on your terms, and provable after the fact.
The best way to see it on your own material is the same way we test everything else: on a slice of your real work. The four-week pilot runs on data you choose and hands back findings in your own numbers. If you want the wider picture first, tape is a feature, not a graveyard covers how the same estate becomes visible in the first place.