Governance for the AI Web.
The web is becoming a place where AI agents act on people's behalf. KYE Protocol™ governs the authority behind those actions — who authorised what, under what delegation, relying on which models and vendors — and proves it later. The category it defines is Governance for the AI Web™, and the risk it removes is Systemic Authority Risk™.
Systemic Authority Risk™ is the accountability gap of the AI web.
Systemic Authority Risk™ is the inability to reconstruct who authorised what, under what delegation, relying on which models and vendors, across a shared AI ecosystem. It is distinct from systemic financial risk and from systemic model risk: the failure is not that a model is wrong, but that accountability itself cannot be reassembled after an AI-mediated action.
KYE Protocol™ reduces it by reusing the rails it already ships — it coins no new authority machinery:
- Identity. Every actor — human, system, or agent — resolves to a canonical
kye:<class>:<trust-domain>:<subclass>:<local>ID. - Discovery. Authority records and registries are projections of KYE Directory Search™ — one directory, many views.
- Evidence. Every governed action carries a signed Evidence Pack™ under write-once retention, with Authority Finality™ guaranteeing the authority that stood at the moment of the action.
- Delegation. Agents acting on a person's behalf are bound as first-class principals through the delegated-agent contract — the accountability evidence the EU AI Act and the NIST AI RMF expect you to produce.
Secure browsing → trusted browsing → governed browsing.
Each era of the web added a layer of assurance. The padlock made browsing secure. Reputation and verification made it trusted. The agentic web needs the next layer: governance — provable authority and evidence behind every consequential action.
Secure browsing
TLS proved the channel was private and the server was who it claimed. It said nothing about authority.
Trusted browsing
Reputation, badges, and verification told a person whether a site was credible. It said nothing about who authorised an action.
Governed browsing
Governance for the AI Web™ resolves the authority behind every consequential action — human or agent — and makes it replay-provable from public evidence.
Four channels, one category.
Each member is a new public-facing product built over the existing KYE Protocol™ rails — they add no parallel authority machinery. One category, four surfaces of the same governance.
travel_explore KYE Lens™
A privacy-by-design browser extension that overlays authority and evidence onto the web a person and their agents browse. Local processing, no user-browsing exfiltration, opt-in telemetry only. Learn more.
Built on: kye: ID · KYE Directory Search™ · Evidence Pack™.
verified KYE Site Authority™
A site scan and badge that lets a publisher disclose a site's authority and evidence posture, with public lookup through the KYE Site Authority Registry™. The site UUID is the canonical kye: ID.
Built on: KYE Directory Search™ projection · Evidence Pack™ · Authority Finality™.
deployed_code KYE Build-Release Authority™
A GitHub App governing the authority, evidence, and provenance of software supply-chain changes — builds, dependency updates, and releases. The actor, human or agent, resolves to a canonical principal.
Built on: Evidence Pack™ · write-once retention · actor binding.
monitor_heart KYE Production Action Authority™
Governs the authority of SRE, incident, and production actions — including an autoheal-partner integration acting on production. Each action proves who authorised it and on what basis.
Built on: Evidence Pack™ · write-once retention · Authority Finality™.
Two non-negotiables hold across every surface.
No truth score.
KYE Protocol™ asserts only verifiable facts — that an action is evidenced, governed, disclosed, and that an authority exists for it. It never asserts that a claim, a page, or an output is "true" or "false". The honesty bar is definitional: the category proves the basis an action relied on, never the truth of the underlying content.
Privacy by design.
Processing is local by default. There is no user-browsing exfiltration. Telemetry is opt-in only. A person's web is theirs; the category governs authority over actions, not surveillance over people.
See the category in context.
Governance for the AI Web™ is the web-facing projection of the broader agentic-governance category KYE Protocol™ defines. Read the category page, or browse the directory and evidence rails the family is built on.