KYE Autonomy Tiers · A0 / A1 / A2 / A3

Four KYE Autonomy Tiers. One runtime-control floor at each step.

EC-Council ADG names three autonomy tiers (HITL / HOTL / HOOTL). KYE Autonomy Tiers compresses those into a sharper four-tier ladder so the runtime-control floor at each step is unambiguous: A0 Human-only · A1 Assist · A2 Scoped delegation · A3 Autonomous with Authority Finality. Each tier names the KAC controls and the evidence schemas that MUST be operating for an action to be admissible at that tier. The canonical set lives at public/examples/autonomy-tiers/canonical-tiers.json.

The ladder

A0 → A1 → A2 → A3 — sequenced, not parallel.

Each rung declares the runtime-control floor that must be operating for an action to be admissible at that tier. Authorised actions climb; refused or de-escalated actions slide back down.

Per-tier control matrix

Which controls must be operating at which tier.

ControlA0A1A2A3
KAC-1 Entity Registryrequiredrequiredrequired
KAC-2 Delegation Enveloperequiredrequired
KAC-3 Chain of Authority Maprequired
KAC-4 Tool & MCP Authority Registerrequiredrequired
KAC-5 Action Admissibility Gaterequiredrequired
KAC-6 Runtime Policy Resolutionrequiredrequired
KAC-7 Evidence Capture at T=0requiredrequired
KAC-8 Replay Proofrequiredrequired
KAC-9 Authority Finality Recordrequired (A3 floor)
KAC-10 Revocation and Expiry Controlrequiredrequired
KAC-11 Human Oversight and Escalationrequiredrequired
KAC-12 KYE Seal — Assurance Recordrequiredrequired
ADG mapping

HITL / HOTL / HOOTL ↔ A0 / A1 / A2 / A3

  • HITL ↔ A1 / lower-A2. Human-in-the-loop on every decision. KYE optional at A1; KYE required from A2 upward.
  • HOTL ↔ upper-A2. Human-on-the-loop — approver on-call for critical-point reviews. KAC-11 is the runtime gate that lifts the right action at the right moment.
  • HOOTL ↔ A3. Human-out-of-the-loop except for declared exceptions. Authority Finality (KAC-9) is the A3 floor — the action's chain is provably terminal before the supervisor learns it happened.

Pick the tier. The control floor follows.

An agent deployment declares its tier; the runtime refuses to admit any action that requires a control the tier does not have. Honest by construction.