A correct answer can still be unauthorised. Authority Finality™ settles it.
Authority Finality™ is the category KYE Protocol™ defines and leads: proving every consequential action was authorised, purpose-bound, evidenced, replayable and final before it changed the world. When an AI agent moves money, releases a clinical result, or files a return, KYE™ proves who authorised it — turning an auditor's days of exam-prep into minutes.
The doctrine: no authority, no finality
If you are a CISO or a regulator, every word below is a control you can test. Each rung rules out a thing the market keeps mistaking for authority.
- Output is not authority. A model producing an answer is not permission to act on it.
- Evidence is not authority. A tamper-evident log proves what happened, not that it was allowed.
- Identity is not authority. Knowing who the agent is does not establish what it may do.
- Access is not authority. Holding a credential is not the same as being authorised for this act.
- Capability is not authority. A benchmark pass proves competence, not mandate.
- No authority, no finality. An action becomes final only once KYE™ proves it was authorised.
The lifecycle KYE™ owns — entity to finality
Adjacent tools each answer one fragment of the question. KYE Protocol™ owns the whole chain a consequential action travels, end to end — eleven stages, each resolving to a control you can audit.
- Entity — who or what exists and can act. Who/what is this?
- Principal — the agent as a first-class governed principal, not an anonymous script. Is the actor accountable?
- Delegated authority — who authorised whom, for what scope. On whose mandate?
- Purpose Permission™ — authority bound to a purpose, so yesterday's grant cannot authorise today's different act. For what purpose?
- Allowed data, tool, model — only the inputs this actor is permitted to use. With what?
- Approval — required human sign-off captured for high-stakes or irreversible acts. Who approved it?
- Decision Map™ — the inputs, policy, evidence and actor that produced the verdict. How was it decided?
- Evidence Pack™ — a signed, action-level proof bundle. What is the proof?
- Replay-Proof™ — any auditor verifies the seal offline from published keys alone, without trusting KYE™. Can you prove it independently?
- Finality Gate — the action becomes final only when authority is proven; draft, advisory and executed are distinct states. May it be relied upon?
- Drift & revocation — authority that expires, drifts or is revoked is caught and itself evidenced. What happens when a control fails?
Everyone else is a point on this map
The category is forming, and serious players are converging on it. That validates Authority Finality™ — and it is why KYE Protocol™ draws the map rather than sitting on someone else's. Each adjacency answers a fragment; KYE™ owns the chain that makes an action final.
| Adjacent player | What it owns | Where it sits on KYE™'s map |
|---|---|---|
| Output-to-action boundary tools | the regulated checkpoint where AI output becomes action | a single gate inside KYE™'s chain — KYE™ proves the whole authority that earns the right to reach it |
| Runtime integrity controls | the transition between possibility and consequence at the point of execution | that transition is the Finality Gate; KYE™ governs the ten stages that precede it |
| Decision-evidence integrity tools | tamper-evident records of what an AI decided | an input layer feeding KYE™'s Evidence Pack™ — KYE™ adds whether the act was authorised |
| Capability benchmarks | whether an agent can do the work | an input layer: a benchmark result scopes authority, but capability is not authority |
KYE Protocol™ does not compete with these layers and does not run agents. It consumes their signals — the way it already consumes inference-gateway telemetry and capability evaluations — and turns them into authority decisions and replay-verifiable evidence. Govern the action; integrate the input.
What this means for you
For a board, a CISO, or a regulator, Authority Finality™ converts an unanswerable question — "was this AI action allowed?" — into a signed record you can replay on demand.
- Regulators and auditors: every consequential action arrives with its authority basis attached, so a review that took days of reconstruction becomes a minutes-long replay.
- CISOs and risk owners: authority can be revoked mid-flight and the revocation is itself evidenced — you control the blast radius of an agent that drifts.
- Builders: bring any runtime, policy engine or model; KYE Protocol™ owns the authority lifecycle above it and makes each action regulator-provable across the EU AI Act, NIST AI RMF and ISO/IEC 42001.