KYE Authority Risk Register™ · the board-facing GRC surface KYE™ produces

Every open authority gap — evidence-bound, board-readable, quarter-end-printable.

AI governance tools tell you where risk may exist. KYE™ tells you, per action, whether the action was authorised at the moment it happened. The Authority Risk Register™ is the aggregation surface that turns that per-action verdict into a board-tier inventory: one row per (subject, gap_class) tuple, each row carrying a list of evidence_refs[] pointing at the signed envelopes that prove the gap exists. Counsel can replay any row offline from public keys alone.

The schema · kye.risk.authority_register.v1

Fourteen gap classes — each one a signed envelope behind it.

The register's gap taxonomy is the canonical list of ways a privileged AI-agent action can fall outside its declared envelope. Each open row carries the evidence-event refs that prove the gap was detected, so the auditor can navigate from a register row to the underlying signed envelope in two clicks.

  • Authority · authority-unverified / authority-expired / authority-revoked. The delegation chain back to a named human principal is missing, timed out, or pulled. Each row references the relevant kye.purpose.grant.revoked.v1 or kye.purpose.admissibility.v1 envelope.
  • Scope · scope-exceeded. The agent acted outside its declared Purpose Permission™ envelope — supplier off whitelist, amount over cap, jurisdiction off list, instrument off list. Bound to a refusal-mode admissibility envelope.
  • Delegation · delegation-invalid / delegation-missing. A cryptographic link in the principal → delegate → sub-delegate chain doesn't resolve under the published JWKS, or no chain exists at all. Bound to the delegation_chain_valid field of kye.purpose.grant.v1.
  • Policy · policy-blocked. The PDP couldn't return a deterministic verdict — rule pack missing, dictionary stale, fail-safe denied. Bound to the relevant kye.evidence.decision_map.v1 with pdp_verdict = blocked.
  • Evidence · evidence-missing / approval-required-unmet. A required evidence envelope wasn't produced (rare, fail-safe), or a human-approval step was bypassed. Bound to a synthesised missing-evidence envelope signed by the supervisor.
  • Post-facto · post-facto-decision. An action was logged after the fact rather than admitted before execution. Banking-grade is a refusal — counsel filters for this class as a structural failure.
  • Capability envelope · capability-envelope-violation. The model acted outside its declared kye.model.capability_profile.v1 — used a prohibited tool family, hit a prohibited task class, exceeded its declared risk class. v1.1 surface.
  • Influence envelope · influence-envelope-drift. The kye.model.influence_envelope.v1 snapshot at decision time disagrees with the prior envelope — system prompt changed, RAG corpus rotated, tool manifest changed, adapter swapped. v1.1 surface.
  • Federation · cross-org-chain-broken. A kye.federation.cross_org_delegation.v1 chain failed verification — hop signature invalid, JWKS snapshot pin failed, attenuation invariant violated. v1.1 surface.
  • Trace replay · trace-replay-unsatisfied. The action's evidence pack only carries a decision-replayable-only claim, not trace-replayable. Counsel filters for this when preparing a litigation-ready exhibit. v1.1 surface.
Who pins it

CFO · GC · CISO · DPO · Audit Committee — same register, role-tuned filters.

  • CFO. Default filter: gap_class in (scope-exceeded, capability-envelope-violation, cross-org-chain-broken) · subject_class = agent OR action. The financial-exposure cross-section. Refused-wires-prevented becomes a board-reportable KPI.
  • General Counsel. Default filter: gap_class in (scope-exceeded, delegation-invalid, post-facto-decision) · status = open OR mitigating. Every row is a pre-litigation exhibit; the Register surfaces them as a queue.
  • CISO. Default filter: gap_class in (policy-blocked, delegation-invalid, authority-unverified). Structural failures surface first; lateral-movement attempts read as scope-exceeded.
  • DPO. Default filter: gap_class in (capability-envelope-violation, influence-envelope-drift, approval-required-unmet) · subject_class = model OR action. GDPR Art 22 + EU AI Act Art 14 board-reportable counts.
  • Audit Committee. Default filter: all open rows · board_visible = true. Quarter-end snapshot exports as a signed kye.risk.authority_register.v1 envelope.
Where rows come from

Derived from the audit chain — zero new authority surface.

  • Source: the canonical kye.evidence.decision_map.v1 + kye.purpose.admissibility.v1 + kye.purpose.grant.revoked.v1 + v1.1 surfaces (kye.model.capability_profile.v1, kye.model.influence_envelope.v1, kye.federation.cross_org_delegation.v1, kye.evidence.trace_replay_spec.v1) already emitted by every privileged action. The Register is a derived projection — no writes, no new authority.
  • Tenant-scoped: the Register binds to your tenant_id; the read JWKS is your published JWKS. The Register operator does not get a new privilege; they get a window into existing decisions.
  • Signed snapshot: each Register envelope is signed by the tenant's risk-engine key. The snapshot's summary object carries deterministic counts by severity, by gap_class, and by owner — board pages embed these counts.
  • Evidence-bound: every row's evidence_refs[] list carries the schema_id + envelope_id + sha256 envelope hash. Counsel clicks any row to pull the original signed envelope for verification.
  • IP-safe: the schema describes structure (fields, enums, refs). Algorithm internals — scoring weights, prioritisation logic, remediation suggestions — are proprietary and are not disclosed in the public spec.

Turn per-action verdicts into a board-tier inventory.

The Register pilot ships with sandbox events from day 1, real events when you flip on enforcement, and a quarter-end signed envelope your audit committee can verify offline.