
Provenance tells you where it came from. Performance tells you how it did. Reputation tells you what people think. None of them tell you what it actually did.
English has a hole in it, right where the most important question lives.
Four Words, and a Gap Where the Fifth Should Be
We have precise nouns for almost every question you can ask about a participant in a system.
Provenance -- where did this come from?
Attendance -- was it present?
Performance -- how well did it do?
Reputation -- what do others think of it?
And then there is the question every authorization decision actually turns on, the one with no noun at all: what has this participant actually done?
You can ask it. You just cannot ask it in one word. You have to reach for "behavioral history" or "participation record" or "track record" or "audit trail," and every one of those is either borrowed from somewhere else or vague enough to mean four things at once. An audit trail is a compliance artifact you produce for someone else. A track record is a sports metaphor. Behavioral history sounds like a psychiatric intake form. None of them name the thing.
A missing noun is not a cosmetic problem. When there is no word for something, you cannot put it on a roadmap, you cannot line-item it in a budget, and you cannot ask a vendor whether they have one. The thing stays a paragraph, and paragraphs do not get funded.
The Word
gestance /ˈdʒɛs.təns/ n.
The accumulated, tamper-evident record of a participant's attributable deeds over time -- held by neither the actor nor the operator, so it stands as evidence rather than claim.
From the Latin gesta, "things done," from gerere, to carry on or to perform. Plus -ance, a state or an accumulated result. Morphologically it is ordinary English, built on the same frame as provenance, performance, attendance, observance. It looks like a word because it is shaped like one.
The root is older than software and it is already load-bearing in law. Res gestae -- literally "the things done" -- is a live evidentiary doctrine covering acts and statements made contemporaneously with an event, admitted precisely because they were generated as the thing happened rather than assembled afterward by someone with a stake in the telling.
That is not a flourish I am borrowing for color. It is the same idea. A record generated as a participant acts is worth something that a summary composed later is not, and the law has known this for a very long time.
Reputation Is What They Think. Gestance Is What They Did.
This is the distinction the word exists to carry, and it is worth being blunt about it.
Reputation is an opinion held by other people. It can be bought, farmed, brigaded, inherited, or simply be wrong. It compresses a participant into a number and then hides the compression, so that by the time you see the score you can no longer see what produced it.
Gestance does not compress. It does not average, rank, judge, or predict. It is the deeds, kept -- what was done, when, and by whom, left in a form you can still read.
The practical version fits on one line:
Authentication tells you who. Gestance tells you whether what they are doing fits what that participant has actually done.
The Part That Makes It Evidence and Not Just a Log
Every system already keeps some log of what its own participants did. That log is not a gestance, and the reason is sitting in the definition: held by neither the actor nor the operator.
A record of deeds that an actor keeps about itself is a claim. A record of deeds that an operator keeps about the participants it also profits from is a claim with a conflict of interest attached. Neither one is evidence, and calling them evidence is how organizations end up surprised.
Evidence is a record that survives the interests of the parties to it. Held independently. Tamper-evident. Checkable by someone with no stake in the answer.
That is the whole difference between a log and a gestance, and it is why the word has to carry the independence inside its own definition. Take that clause out and you are just describing a database.
The Family
A noun on its own is not much use. These came with it.
gest n. -- a single recorded deed. Revived: archaic English for a deed or exploit, and the root beneath "jest."
gesting n., v. -- the act of recording deeds into a gestance. Revived Middle English.
gestance n. -- the accumulated record itself.
gestive adj. -- evidentiary of deeds.
gested adj. -- recorded as a deed.
gestless adj. -- having no gestance yet.
gestor n. -- the participant whose deeds a gestance records.
I expect gestless to earn its keep fastest, because it fixes a mistake that is being made constantly right now.
A brand-new AI agent. A service account provisioned this morning. A contractor on day one. None of them are suspicious. They are gestless -- they have no recorded deeds yet. That is a completely different fact from "risky," and the absence of a word for it is a large part of why so many systems collapse the two into the same bucket and treat a newcomer like a threat.
Absence of history is not evidence of risk. It is absence of history. Having a word for that condition makes it much harder to quietly pretend otherwise.
I Coined It, and I Am Not Trademarking It
I coined gestance on 13 September 2026, while trying to write a single clean sentence about what participation history actually is and running, again, into the gap where the noun should have been.
A coined word is close to the strongest trademark class there is, and the obvious business move is to register it. I am not going to.
A word that is owned cannot become the word for a category. Provenance, observability, zero trust -- nobody owns them, and that is exactly why the industry says them. If gestance is going to be worth anything, it has to be sayable by people who owe me nothing, including people who compete with me. Registering it would keep it a product name forever, and a product name is a much smaller thing than a word.
So take it. Use it in architecture docs, in RFPs, in threat models, in arguments with your vendors. Use it about systems that have nothing to do with mine.
What I did do is establish that I said it first, in the only way consistent with what the word means. The canonical definition lives in a plain text file, and that file's SHA-256 hash is anchored in the Bitcoin blockchain through OpenTimestamps. No trusted third party, no platform, nothing anyone has to take my word for. Anyone can check it, including someone who would very much prefer it were not true.
To be precise about what that does and does not do: the anchor establishes authorship of the coinage. It is not a trademark filing and it does not stand in for one. I know the difference, and I am choosing the smaller claim on purpose.
It seemed like the only decent way to do it. A word that means "independently held, tamper-evident evidence of what was done" ought to be able to prove its own origin the same way it asks everything else to.
Why This Matters More Every Month
The question gestance names is not new. What is new is how many participants are now asking systems to answer it, and how few of them are people.
An organization running AI agents and service accounts alongside its employees and contractors is making authorization decisions all day about participants whose deeds nobody is independently keeping. Identity tells you the agent is the agent. Policy tells you what that agent is permitted to do. Neither one tells you what that agent has actually done since it was provisioned, and neither one notices when that stops matching.
That gap is what MIR exists to fill -- a record of what participants actually did, kept where neither the participant nor the platform can quietly revise it. It is the thing I have been building for the better part of a year, and for most of that time I have described it in paragraphs because there was no noun.
Now there is one.
The canonical definition, the etymology, the full word family, and the timestamp proof are at gestance.com.