KYE Authority Studio · give · bind · prove an agent's authority

Give your agent authority you can prove.

KYE Authority Studio is the control surface where you take an agent — yours or off-the-shelf — and give it, bind it, and prove its authority. Register the agent as a first-class principal, attach an authority manifest, set an approval policy, wire a policy enforcement point into it, then watch every consequential action turn into a replayable Evidence Pack. It governs agents; it does not build them — so a regulated buyer's security review drops from weeks to days.

Two lanes, one control surface

Bring an agent, or scaffold a governed one.

KYE Authority Studio meets you where your agent already lives. Most teams arrive with an agent in production and need to govern it; some are starting fresh. Either way you leave with authority plus a verifiable receipt — never a black-box agent KYE built and now owns.

hub Lane 1 — govern your existing agent Point KYE Authority Studio at an agent you run on LangChain, CrewAI, the OpenAI Agents SDK, or the Claude Agent SDK. The Studio generates a drop-in policy enforcement point, an authority manifest, and an approval policy — the agent keeps running on your framework, now governed at the action boundary.
construction Lane 2 — scaffold a governed agent Starting from zero? Use the KYE Agent Dev Kit templates (hello / kyc / payment), each self-governing by default. KYE supplies the scaffold and the governance, not a runtime you have to adopt — you still own and run the agent.

The differentiator: this is a studio that governs agents, not one that builds or runs them. The non-competition line with LangChain, CrewAI, the OpenAI Agents SDK and the Claude Agent SDK is deliberate — KYE governs the authority, you keep the agent.

What the Studio does

Register → bind → policy → wire → prove → revoke.

KYE Authority Studio is a composition surface over KYE Protocol rails you already trust — the GovernedUI approval modules, the §52 authority bindings, and the §13 evidence and Authority Finality receipts. You move an agent through six honest steps, and each step is itself a governed, evidenced action.

  • 1. Register the agent as a principal. The agent gets a canonical KYE identity and becomes discoverable in the directory — a first-class principal with the same governance weight as any human or system actor.
  • 2. Bind its authority. Attach a §52 authority manifest, a Model Context Protocol allow-list, and a Purpose Permission scope — declaring exactly which actions, value bands, and data the agent may touch.
  • 3. Set the approval policy. Choose an approval mode per action class — none, single approver, two-person, two-person-with-legal, delegated, or auto — reusing the GovernedUI Action Approval module, not a parallel model.
  • 4. Wire the policy enforcement point. Generate a drop-in PEP adapter for your framework so the agent asks “is this action authorised?” the moment it acts — before money moves or a record changes.
  • 5. Watch decision → evidence → finality. Every governed action emits the §0.3 evidence family and seals an Evidence Pack you can replay from public keys alone — Replay-Proof, no access to your database required.
  • 6. Revoke in one click. Pull an agent's authority the instant it drifts — the revocation is itself an evidenced, banking-grade act with dual-channel sign-off on irreversibles.
Worked example

An AML agent closes an alert — and proves who let it.

Picture an AML triage agent your team already runs. When it closes a suspicious-activity alert or files a report, KYE Authority Studio decides whether that agent was authorised for that customer, that risk band, and that action — and seals the proof before the close lands.

  • The action is checked at the boundary. The alert-close is sent to the decision point as a proposed action; Purpose Permission admissibility returns ALLOW only if the agent's bound authority covers it — otherwise it routes to a two-person review.
  • The proof is sealed, not asserted. The verdict and its inputs are hash-sealed into an Evidence Pack in a write-once audit trail, re-derivable by your examiner via Replay-Proof against KYE Protocol's published keys.
  • The value is faster exams. Because every agent action ships with mapped controls under EU AI Act Article 14, NIST AI RMF, and ISO/IEC 42001, exam-prep for a governed agent fleet drops from days of screenshots to minutes of replay.
Built on rails you already have

A composition surface, not another silo.

KYE Authority Studio adds no parallel agent registry, no second approval model, and no build-your-agent runtime. It composes the canonical KYE Protocol rails — so what you govern in the Studio is the same authority your auditors, your directory, and your evidence trail already understand.

  • Approvals reuse GovernedUI. The Studio's approval policy is the existing Action Approval module — one canonical human-control surface, six approval modes, four channels.
  • Authority reuses §52 bindings. Every agent's authority manifest and Model Context Protocol allow-list are the same §52 artefacts the platform governs everywhere else — no forked authority model.
  • Evidence reuses §13 receipts. Decisions become Evidence Packs and Authority Finality receipts — the same replay-verifiable proof KYE Protocol emits for any governed action.

Honest scope: KYE Authority Studio governs whether an action was authorised and proves it. It is not an agent framework and never runs your agent — the output is authority plus a verifiable receipt, and nothing more.

Bring the agent. KYE makes its authority provable.

Start a proof of concept: register an agent, bind its authority, wire the enforcement point, and get back a sealed Evidence Pack for its first governed action — in days, not a quarter.