EC-Council ADG ↔ KYE Protocol™ crosswalk

ADG defines what controls. KYE™ proves which actions met them.

EC-Council ADG (Adopt · Defend · Govern, 2026) names three pillars, nine governance surfaces, twelve minimum controls (MC-1..MC-12), and three autonomy tiers (HITL / HOTL / HOOTL). It is an operating-model framework — it tells an organisation what controls to operate. KYE Protocol™ is the runtime authority layer beneath it — it proves a specific action was authorised, admissible, evidenced, and final. The two stacks are complementary, not competing. This page is the analyst-grade crosswalk: every ADG surface and every MC-1..MC-12 control mapped to the KYE™ Minimum Authority Control™ (KAC™) and canonical evidence schema that materially discharges it at runtime.

Positioning

Complementary stacks — distinct accountability layers.

StackLayerUnit of accountabilityBuyer-facing artefact
EC-Council ADGOperating modelControl declarationFramework adoption attestation
KYE Protocol™Runtime authorityAction admissibility + evidencePer-action Replay-Proof™ envelope

A regulator-grade deployment runs both: ADG as the operating frame, KYE™ as the per-action runtime proof. ADG without KYE™ relies on after-the-fact log scraping to prove the control held. KYE™ without ADG ships a runtime authority layer without the operating-model frame that puts it in the board pack.

The nine ADG governance surfaces

Surface → KYE™ primitive.

ADG surfaceKYE™ primitiveKAC™Canonical schema
Identity surfaceVerified EntityKAC™-1entity.json + kye.governedui.entity_passport.v1
Tools & MCP RegisterKYE Tool & MCP Authority Register™KAC™-4kye.tool_mcp_register.v1
Agentic orchestrationChain of Authority™KAC™-3kye.federation.cross_org_delegation.v1
Runtime monitoringEvidence Pack™ + drift signalKAC™-7kye.evidence.pack.v1 + kye.signal.drift.detected.v1
Incident response / forensic replayReplay Proof™KAC™-8kye.evidence.trace_replay_spec.v1
Decision rights / authorityAuthority Finality™KAC™-9kye.estate.authority_finality.v1
Lifecycle / revocationRevocation + expiry controlKAC™-10kye.purpose.grant.v1 + kye.purpose.admissibility.v1
Human oversightGovernedUI™ critical-point reviewKAC™-11kye.governedui.critical_point_review.v1
Assurance / certificationKYE Seal™KAC™-12kye.compliance.attestation.v1
ADG minimum controls MC-1..MC-12 ↔ KAC™-1..KAC™-12

Same twelve. KYE™ materially enforces them.

ADG MCTitleKAC™Coverage on KYE™
MC-1Verified entity / identity registerKAC™-1 Entity Registryenforced
MC-2Delegation envelopeKAC™-2 Delegation Envelope™enforced
MC-3Chain of authority across organisationsKAC™-3 Chain of Authority Mapenforced
MC-4Action-class declaration / scopeKAC™-2 + KAC™-5 (admissibility scope)enforced
MC-5Admissibility floorKAC™-5 Action Admissibility™ Gateenforced
MC-6Runtime policy resolutionKAC™-6 Runtime Policy Resolutionenforced
MC-7Tools & MCP registerKAC™-4 Tool & MCP Authority Registerenforced — pilot SKU live
MC-8Revocation + expiry controlKAC™-10 Revocation and Expiry Controlenforced
MC-9Evidence capture per actionKAC™-7 Evidence Capture at T=0enforced
MC-10Forensic replay capabilityKAC™-8 Replay Proofenforced
MC-11Decision rights / authority terminalityKAC™-9 Authority Finality™ Recordenforced
MC-12Human oversight + critical-point reviewKAC™-11 Human Oversight and Escalationenforced
Autonomy tiers

HITL / HOTL / HOOTL ↔ A0 / A1 / A2 / A3.

ADG names three autonomy tiers. KYE Autonomy Tiers™ compresses to four so that the runtime-controls floor is unambiguous. See /autonomy-tiers.html for the per-tier control matrix.

ADG tierKYE™ tierKYE™ requiredKAC™ floor
(n/a)A0 Human-onlynonone
HITLA1 AssistoptionalKAC™-1
HITL / HOTLA2 Scoped delegationyesKAC™-1, 2, 4, 5, 6, 7, 8, 10, 11, 12
HOOTLA3 Autonomous with Authority Finality™yesKAC™-1..KAC™-12 (all twelve)
Deep-mapping coverage

35 ADG requirements → KYE™ canonical artefacts — bijection enforced.

The full requirement-by-requirement deep mapping lives at /compliance/ec-council-adg.html, generated from internal on every build. Every cited kye.<ns>.*.v1 schema MUST resolve to a canonical declaration on disk; the framework-coverage-bijection gate fails the merge if anything drifts. Honest coverage breakdown: 22 enforced / 11 designed / 2 advisory / 0 out-of-scope (63% enforced; the runtime-authority surface where KYE™'s wheelhouse sits is enforced wall-to-wall, with deployer-side operating-model concerns honestly marked advisory).

Same twelve controls. ADG declares them. KYE™ proves them.

A regulator-grade deployment runs both stacks. The crosswalk is the analyst-grade artefact that lets a CISO, regulator, or auditor see which KYE™ primitive discharges which ADG control without translation.