KYE Threat Response Authority Agent™ — a bounded agent you can defend.
You keep your own systems; KYE Protocol™ governs the one consequential act around them — proving who authorised it, sealing each act as an Evidence Pack™ a regulator can re-derive. That cuts dispute and exam-prep evidence work from days to minutes.
Any agent can act. A KYE™-governed agent can be trusted by customers, counterparties, auditors and regulators.
One bounded act, governed block/revoke/isolate/disable/escalate/notify.
governs the consequential SOC / incident-response decision at the action boundary. The governed acts are blocking an IP or domain, revoking an API key or token, isolating a workload, disabling an account, escalating an incident, notifying a regulator or customer, and triggering a fraud or payment control. It records the contestable disposition with chain-of-custody. It holds the irreversible containment finality and the regulator-notification-clock release advisory until a named incident commander or CISO records two-person sign-off. The bound frameworks are DORA ICT-incident, NIS2, NIST CSF 2.0 Respond/Recover, the SEC cyber-disclosure rule, and ISO 27035. It runs the existing KYE Cyber Resilience & Incident Governance™ flow — it does not duplicate it. KYE Protocol™ proves the basis; it does not detect threats, run the SIEM or EDR, perform forensics, remediate, or replace the SOC analyst. Threat intel creates urgency; KYE Protocol™ prevents urgency from becoming unauthorised action.
The Threat Response Authority Agent™ does exactly one job under KYE Protocol™ authority, and it is metered (SKU KYE-AGENT-THREAT-RESPONSE-001) and stoppable by a kill-switch. Its jurisdiction is global. It is a first-class principal — identical in governance weight to any human or system principal.
- Authority-bound — it acts only inside its constitution §52 authority binding; an act outside that bound scope is refused and routed, never silently attempted.
- Evidence-sealed — each act packs an Evidence Pack™ and seals a Replay-Proof™, verifiable from public keys alone.
- Metered & kill-switched — every act is metered under
KYE-AGENT-THREAT-RESPONSE-001and can be stopped instantly; no act survives a revoked authority.
Every act, five governed steps.
Whatever the agent does, the act crosses the same boundary, captured as real envelopes against existing protocol schemas. No new schema was minted for this agent — it reuses Purpose Permission™ and the Evidence Pack™.
- Admit. The bounded act crosses the constitution §52 authority boundary; only the agent's allow-listed tools and inputs are admitted.
- Decide. A Purpose Permission™ verdict answers whether this bounded agent may act, as a per-check reason list.
- Act. The agent performs its single-purpose act within the admitted scope — nothing more.
- Evidence. An Evidence Pack™ binds the decision and each act-supporting signal as a signed signal.
- Finalise. A signed Replay-Proof™ seals the act so it re-runs to the same result — Authority Finality™ for the bounded act.
Metered, jurisdictioned, framework-bound.
This agent is one declared SKU with a named regulatory perimeter — reused, never re-mapped. Your team buys the governance, not raw agent capability.
- SKU —
KYE-AGENT-THREAT-RESPONSE-001, metered per governed act. - Pricing — metered per governed act; commercial terms follow the KYE Protocol™ pricing model (PoC → Pilot → Annual Licence), confirmed during scoping.
- Jurisdiction — global.
- Sector — Horizontal.
- Bound frameworks — the named regulatory perimeter the agent governs against is stated in full above; KYE Protocol™ maps each governed act to that perimeter and seals the reasonable-steps evidence.
It proves the basis — it does not execute the act.
Constitution §0.30 makes agents first-class principals; constitution §32 keeps KYE Protocol™ out of the agent-framework business. This agent lives precisely on that line.
KYE Protocol™ proves the basis for the bounded act; it does not run your screening, scoring, modelling, retrieval, or execution engines. The honest non-goals are stated in full in the agent description above. An act outside the agent's bounded scope is refused and routed, never silently attempted — the refusal is itself evidenced. Read the governing clause on the agents-as-first-class-principals page.
Provable from public keys alone.
Every signed envelope this Governed Agent™ emits verifies against the published key set at trust/self-audit-jwks.json — the same Ed25519 verification surface KYE Protocol™ uses to audit itself. No credentials, no vendor portal: parse the JSON, canonicalise the payload, and check the signature. The self-audit page walks the verifier step by step — turning each governed act into evidence a regulator can re-derive, cutting exam-prep from days to minutes.
Three steps to a governed agent in production.
You do not rip out your stack. A KYE Protocol™ engagement governs this one act in stages — each with a signed deliverable you keep.
- Pilot. A paid, fixed-scope Proof-of-Concept delivers a signed Evidence Pack™ for this agent's act on one real workflow — replayable offline by your auditor. 100% of the fee credits against a Pilot or Annual Licence signed within 60 days.
- Onboard. Bind the agent to your stack (SSO, data store, API gateway) and set its constitution §52 authority scope. Commercial terms follow the KYE Protocol™ pricing model; create your workspace at account setup.
- Live. The agent runs as a metered, kill-switched first-class principal under SKU
KYE-AGENT-THREAT-RESPONSE-001— every act sealed and verifiable from public keys alone. Operate and approve from GovernedUI™.