Authority for agentic access
KYE Open Access Authority™ answers the one question that decides whether an autonomous agent should be let through the door: may this agent legitimately access, rely upon, invoke, cite, or transact with this resource — under its rights, and the jurisdiction that applies?
As agents operate across APIs, MCP (Model Context Protocol) servers, datasets, services and marketplaces — across borders — the hard problem stops being discovery or routing. The missing layer is governed admissibility: deciding whether the access should be allowed, and proving it afterwards.
The five access verbs
Every agent-to-resource interaction reduces to exactly one of five access actions. Whether you are a CISO, a regulator, or a developer wiring an agent, the question is the same: Open Access Authority™ adjudicates each one against the requesting principal's rights and the applicable jurisdiction.
Access
Reach or read the resource at all — an API, dataset, knowledge base, or service endpoint.
Rely upon
Depend on the resource's output as an authority for a downstream consequential action.
Invoke
Call the resource as a tool that performs work — an MCP server, an action endpoint, a paid API.
Cite
Reproduce, quote, or attribute the resource's content in the agent's own output — licence-sensitive by nature.
Transact
Exchange value — purchase, subscribe, or settle against a marketplace or service. The most jurisdiction-sensitive verb.
Not a router. An adjudicator.
Open Access Authority™ does not discover content, route connections, or proxy bytes. It is a projection of KYE™'s governed admissibility decision onto the agent-to-resource access question — the same governed decision, scoped to an access action. Think of it as OAuth for agentic admissibility: a standard checkpoint a system calls to ask "is this access authorised?" — and one that frequently, and legitimately, answers no.
- Identify the principal. Resolve the requesting agent to exactly one principal in one tenant — agents are first-class principals with their own identity and authority bindings.
- Resolve the rights. What delegation does the principal hold over this class of resource? What contractual or licensing regime governs it?
- Resolve the jurisdiction. Which jurisdiction applies to this principal-and-resource pair, and what happens when the request crosses a border?
- Evaluate admissibility. The decision returns a verdict — allow, deny, or allow only with notice, consent, or minimisation â through KYE™'s existing decision engine, not a parallel one.
- Evidence it. Every decision emits an Evidence Pack™ that is Replay-Proof™ — independently verifiable from public keys alone, so a regulator or counterparty can re-derive the verdict without trusting you.
Boundary: KYE™ governs whether an agent may access a resource. It does not run the agent, build the agent, or route its traffic — that is the job of agent frameworks and networks. Open Access Authority™ is the authority layer they call, not a competitor to them. It is part of the KYE Protocol™ platform.
Why this matters across borders
The moment agentic access expands beyond convenience into regulated services — financial products, telemedicine, legal advice, education, pharmaceutical access, insurance, government services — cross-border execution turns into a jurisdiction-conflict and authority problem. The EU AI Act, GDPR, and your sector's regulators each attach obligations to who may act, where. An agent that can reach a service in another country is not the same as an agent that is authorised to use it there. Open Access Authority™ is where that distinction is enforced, and evidenced, at the action boundary — not discovered after the fact. For your auditor or regulator, that evidence is the difference between a claim and a proof.
- The EU AI Act, GDPR, DORA and NIST AI RMF each bind who may act, not just what is stored.
- Every access decision emits a signed Evidence Pack™ in JSON, replay-verifiable from public keys alone.
- Exactly one jurisdiction resolves per request; cross-border handoffs are evidenced, never silent.
The Resource Authority Badge™
A resource earns an authority state as it becomes governable for agentic access:
"Authority evidenced" is the full state: access decisions against the resource emit Evidence Packs™ and are Replay-Proof™ from public keys alone. A change of rights or jurisdiction, or an upstream revocation, moves a resource to "suspended" pending re-assessment.
Tiers
Start free with a Resource Authority Badge™, or talk to us about a governed pilot — whether you are a security team, a regulator, or a developer, the free tier gives you the access-verb matrix in minutes.
Resource Authority Badge™
Free- Declare a resource's access terms
- Access-verb × resource-class matrix
- Jurisdiction applicability summary
- Badge in "authority-asserted" state
Standard
Annual · by application- Per-action admissibility across all five verbs
- Jurisdiction-aware decisioning
- Evidence Pack™ per decision
- Badge in "authority-evidenced" state
Enterprise
Annual · by application- Multi-tenant, multi-region, cross-border
- Contestability + revocation on access authority
- Regulator-grade replay export
- SLA + named authority owner
Pricing for the paid tiers is shared with qualified applicants on request, in line with KYE™'s closed-registration policy. Start with the free Resource Authority Badge™, or talk to us about a governed pilot.