Agents act. Authority decides. Evidence proves.
An agent can restart — its authority must not drift unnoticed. The KYE Agent Authority Stack™ sits above any agent runtime and adds the layer they leave out: purpose-bound authority, action admissibility, evidence verifiable from public keys alone, and suspendable finality.
The seven layers of agent authority
Whether you are a CISO or a builder, each layer answers one question a regulator will ask about your agents.
- Identity — every principal (human, service, or agent) is a first-class identity your auditors can resolve. Who acted?
- Purpose Permission™ — authority is bound to a purpose and scope, so yesterday's grant cannot authorise today's different act. On whose authority, for what?
- Action Admissibility™ — every consequential action is checked at the moment it happens: admit, block, escalate, or quarantine. Is this action allowed, now?
- Evidence Pack™ — each decision is sealed into a tamper-evident record with its cited basis. What happened, and why?
- Replay-Proof™ — any auditor verifies the seal offline from the published keys alone, without trusting KYE Protocol™. Can you prove it independently?
- Authority Finality™ — authority can be revoked mid-flight, and the revocation is itself evidenced. What happens when a control fails?
- Authority Risk Signal™ — a signed feed of authority failures boards and insurers consume to price exposure. How do you track problems?
Bring your runtime — KYE Protocol™ proves it
For a platform team, the runtime that enforces policy is increasingly a commodity; the evidence that satisfies a regulator is not.
Open-source agent toolkits and policy-as-code engines (such as Open Policy Agent) now ship policy enforcement, identity, and audit logging well — and that is good. KYE Protocol™ does not compete with the runtime or the policy engine; it sits above whatever runtime and policy stack you choose and owns the whole authority lifecycle they leave out — delegated authority, action admissibility, conformance to the framework you must answer to, signed evidence an auditor can verify without trusting any vendor (including us), and suspendable finality. Bring your policy engine; KYE™ resolves who was authorised and makes it replayable.
| A runtime toolkit gives you | The KYE Agent Authority Stack™ adds |
|---|---|
| Policy decision (allow / deny) | Purpose Permission™ — was the action within the purpose the authority was granted for? |
| Tamper-evident audit log | Replay-Proof™ — verifiable from public keys alone, not trust-the-vendor's-log |
| A handful of compliance mappings | Deep mapping to the EU AI Act, NIST AI RMF, ISO/IEC 42001 and 160-plus frameworks, each tied to the artefact that enforces it |
| A library you embed | Agents as billable, directory-discoverable principals — the commercial and research rails on top |
Boundary: KYE Protocol™ governs whether an agent may act and proves what it did; it does not replace your inference engine or your chosen runtime. It consumes their signals — the way it already consumes Weights & Biases provenance and inference-gateway telemetry — and turns them into authority decisions and replay-verifiable evidence.
Why above, not inside
Prompt-level rules are a request to a stochastic system; authority is a control. KYE™ puts the control where it cannot be argued with.
- The EU AI Act's logging and human-oversight duties bind at runtime — the stack discharges them per action, not in an annual review.
- Authority is decided once and proven forever: the same sealed evidence serves the incident responder today and the auditor next quarter.
- A runtime can change; the authority record and its public-key proof do not depend on which runtime produced them.