KYE Oversight Envelope

Human over the loop, not just in the loop.

You set the authority envelope — the scope, the hard limits, and the drift thresholds your AI agent may act within — once. KYE Protocol then binds the agent to it and emits a signed record of every breach, so you monitor instead of approving each action. The agent runs inside the envelope; you are alerted only when a limit is crossed or behaviour drifts. Set the envelope, watch for breach.

In the loop versus over the loop.

Two governance postures: an approver who signs off each action, or an overseer who sets the boundary and supervises within it.

Human-in-the-loop means a person approves each proposed action before it commits — the killer wedge of KYE GovernedUI™ Action Approval. Human-over-the-loop means a person sets the boundary once and supervises the autonomous agent within it. Both are governance postures; over-the-loop is the one regulated buyers ask for when per-action approval would throttle a high-volume agent. KYE Oversight Envelope ships the over-the-loop posture as a first-class GovernedUI module, admissible only at the higher KYE Autonomy Tiers (supervisor and exception-only).

How the envelope is set — scope, limits, drift.

You declare three things once; the protocol enforces all three and emits an alert the moment any one is crossed.

  • Scope — which action classes and purposes the agent may act within without per-action approval.
  • Hard limits — ceilings (actions per window, spend, records touched, blast radius, geography). Crossing one is an immediate breach: the agent's authority is suspended.
  • Drift thresholds — soft thresholds wired to the protocol's drift detector (the authority lifecycle evidence rail). Crossing one raises an alert to the overseer; the human decides — no auto-suspend.

The envelope is one signed artefact. Once it is active, the agent acts; the overseer monitors a breach feed instead of an approval queue.

The oversight itself is governed — oversight of the oversight.

Setting an envelope is an authority act: it is decided at the policy point, it cannot be self-set, and it emits a signed Evidence Pack™.

The hard question regulated buyers ask is not only whether a human is over the loop, but how the oversight itself is governed, evidenced, and audited. Setting or revising an envelope is an authority act, not a configuration change. It is decided at the policy point, it cannot be self-set (an overseer may not write their own subject agent's envelope), and it emits a signed Evidence Pack™. Every envelope moment — set, breach, drift alert, revised, revoked — lands on the WORM audit chain, replay-derivable from the published keys alone.

Mapped to the oversight regulators ask about.

The envelope maps to EU AI Act Article 14 and to the APRA CPS 230 and CPS 234 oversight expectations Australian buyers apply.

KYE Oversight Envelope maps to EU AI Act Article 14 (human oversight of high-risk AI), and to APRA CPS 230 operational-risk and CPS 234 information-security oversight expectations that Australian financial-services and government buyers apply to autonomous systems. The supervisor and exception-only oversight roles encode the over-the-loop posture those frameworks describe.

Set the envelope. Monitor for breach.

Give your agent a bounded mandate and watch one breach feed instead of an approval queue.

KYE Oversight Envelope is a governance projection of KYE Protocol™, surfaced through KYE GovernedUI™. Every overseer act emits a signed Evidence Pack™.