KYE Authority Risk Signal · the signal, not the quantification

KYE Authority Risk Signal — a signed feed of authority-failure events for boards, insurers & risk platforms.

Every governed action emits an evidence event when authority fails. The KYE Authority Risk Signal is a signed feed over those events. It counts seven authority-failure classes — denials, escalations, unauthorised attempts, authority drift, evidence gaps, finality suspensions, and revocations. It is a projection: counts and signed references, never dollar values. KYE Protocol emits the signal; your board, insurer, or risk platform prices the exposure. It is not financial-risk quantification or advice.

The wedge

Boards and insurers need a credible authority-risk input — and the only honest one is the proven event, not a guessed number.

Risk committees, cyber insurers, and risk-quant platforms all want to price the exposure created when AI-agent and delegated authority fails. The credible input is not another vendor risk score — it is the signed, tenant-scoped record of which authority events actually occurred. Four facts converge:

  • The consequential moment is the authority failure — and it is already evidenced. A denial, an escalation, an attempt to act outside scope, declared-vs-deployed authority drift, an evidence gap, a finality suspension, a revocation: each already emits an evidence event on the audit chain. The signal is a projection over those events, not a new measurement.
  • Counts are defensible; estimates are contestable. A count of authority-failure events in a window is a fact the consumer can independently verify against the referenced audit rows. KYE Protocol ships the counts and the references — never a likelihood, a loss, or an exposure range it would have to defend.
  • Replay-verifiable from public keys alone. Every feed record is Ed25519-signed; the board, insurer, or platform recomputes the canonical hash and verifies the signature against the published trust keys, with no KYE Protocol secret required. The signal is trustworthy without trusting the sender.
  • This is a signal, not a model. KYE Protocol does not compete with the insurer’s underwriting models or the risk platform’s quantification engine. It supplies the proven authority-failure signal those models lack — and leaves the pricing to them.
Why a board, insurer, or risk platform consumes this

Counts you can verify, references you can pull, a signature you can check — the proven authority-failure signal, ready for your model.

  • Seven event-class counts per window. Denials, escalations, unauthorised attempts, authority drift, evidence gaps, finality suspensions, revocations — each a tally of governed events derived from a real evidence-event family on the audit chain, never a dollar value.
  • Severity mix, classified at the event. The feed classifies the window’s events by operational severity (low / medium / high / critical) — a classification of the events, not a financial-risk score or loss estimate.
  • Signed references to the real evidence. Every material event carries a reference back to its audit row, so your team pulls the underlying evidence and verifies the signal independently — the feed asserts no new truth.
  • Tenant-isolated by construction. Each feed is scoped to exactly one trust domain; cross-tenant aggregation never happens. Your signal is yours.
  • Channels into the Insurance pack and external risk platforms. The same signed feed feeds the KYE Protocol Insurance pack and machine-consumable exports for external risk-quant platforms — they price the exposure; KYE Protocol proves the events.
How it works

A derived, signed projection — computed deterministically over the evidence you already produce.

One deterministic projector reads the audit-chain events for a tenant and a window, counts the seven authority-failure classes, classifies severity, references the most material events, and seals the record with an Ed25519 signature. Nothing is invented; the record is a projection.

  1. 1 — Authority fails, evidence is emitted. A denial, escalation, unauthorised attempt, drift, evidence gap, finality suspension, or revocation emits its evidence event on the audit chain at the moment it occurs.
  2. 2 — The projector aggregates the window. For one trust domain and one time window, the projector counts each event class, builds the severity mix, and selects the most material event references — deterministically, with cross-tenant events dropped.
  3. 3 — The record is signed. The feed record is sealed with an Ed25519 signature over its canonical JSON, carrying the seven counts, the severity mix, the references, and the non-quantification boundary — replay-verifiable from the published trust keys alone.
  4. 4 — You consume and price. Your board pack, your insurer, or your risk-quant platform ingests the signed feed and prices the exposure on its own model. KYE Protocol never prices — it proves the events.

See a worked, signed sample — counts, severity mix, a recomputable SHA-256, a signature check, and a feed export — in the Authority Risk Signal app.

Honest scope

KYE Protocol emits the signal; you price the exposure.

This is not financial-risk quantification or advice. KYE Protocol proves which authority events occurred — counts and signed references over a tenant and a window. It runs no likelihood×loss model, no exposure-range mathematics, and offers no investment or risk advice. Pricing the exposure is the job of your board, your insurer, or your external risk-quant platform. This is the exact boundary the KYE Model & Risk-Data Governance Pack already drew, held end-to-end: KYE Protocol supplies the proven signal, and cedes the quantification to the consumer.

Get the feed

Boards, insurers, and risk platforms — talk to us about an Authority Risk Signal feed.

The KYE Authority Risk Signal ships in Board, Insurer, and Risk-platform tiers; commercial distribution is value-based, qualification-gated, and disclosed under NDA to qualified applicants.