Everyone owns a layer. KYE™ owns the centre.
The Unowned Centre™ is the convergence KYE Protocol™ names: observability, identity, access, evidence and model-governance are each owned by someone — but the centre they circle, whether a consequential action was legitimately authorised the moment it acts, was an unclaimed category. KYE™ owns it — the plane that defines, leads and proves authority to finality — governing the authority that still belongs to the institution, and turning an auditor's days of reconstruction into a minutes-long replay.
Every layer is an upstream input; they funnel into the centre. KYE Protocol™ owns the centre — the Authority Finality™ category and its governance. The authority itself belongs to the institution; KYE™ proves it held.
The centre every layer stops short of
If you buy AI-governance tools, you have noticed the pattern: every product owns a layer, and every layer stops short of the same question. That question is the centre — and until KYE Protocol™, it was an unclaimed category, because owning a layer is not owning the centre.
- Observability owns the layer that sees agents and measures behaviour — but seeing is not authorising. Visibility never silently creates permission; a discovered agent can be registered but unauthorised.
- Identity and access own who may reach a system — but reachability and RBAC/ABAC are not the external mandate to move money, reject a claim, file a SAR or terminate an employee.
- Evidence and telemetry own the record of what happened — but a trace proves what occurred, not that it was allowed.
- Model-governance and evaluation own how good or safe the model is — but a correct, safe, compliant output can still be unauthorised.
Each incumbent's centre of gravity is its own layer; none is built to answer the authority-to-finality question portably across all of them. That was The Unowned Centre™ — and KYE Protocol™ owns it, defines it and leads it as Authority Finality™.
The doctrine: no authority, no finality
KYE™ owns the centre by ruling out, one by one, the things the market keeps mistaking for authority — and each of those things is a layer someone already owns. A CISO or regulator can test every rung.
- Output is not authority. A model producing an answer is not permission to act on it.
- Evidence is not authority. A tamper-evident log proves what happened, not that it was allowed.
- Identity is not authority. Knowing who the agent is does not establish what it may do.
- Access is not authority. Holding a credential is not the same as being authorised for this act.
- Capability is not authority. A benchmark pass proves competence, not mandate.
- Observability is not authority. Discovering and measuring an agent does not empower it to cause a consequence.
- Permission is not mandate. A system granting an operation is not an institution delegating the power to cause its effect.
- Technical authority is not institutional authority. That an agent can act does not settle whether the institution will own the act as its own.
- No authority, no finality. An action becomes final only once KYE™ proves it was authorised.
Every layer is owned; KYE™ owns the centre
The category is forming, and serious players are converging on it from every edge. That validates the centre — and it is why Authority Finality™ draws the map rather than sitting on someone else's. KYE Protocol™ consumes each layer as an input and adds the one state the layers structurally lack.
| Owned layer | What it legitimately owns | Where it sits on KYE™'s map |
|---|---|---|
| AI-observability platforms | agent discovery, behaviour measurement, operational guardrails | an input layer — KYE™ consumes its discovery and drift signals and adds registered-but-unauthorised |
| Identity & access platforms | who may authenticate and reach a system | an input layer — reachability scopes access, but access is not the external mandate to act |
| Evidence & telemetry stores | tamper-evident records of what happened | an input layer feeding KYE™'s Evidence Pack™ — KYE™ adds whether the act was authorised |
| Model-governance & policy tools | model quality, safety and configured rules | an input layer — a policy owner is not the source of authority; the mandate comes from the institution |
KYE Protocol™ does not compete with these layers and does not run agents. It consumes their signals and turns them into authority decisions and Replay-Proof™ evidence. KYE™ owns the centre — the category and its governance; the authority itself belongs to the institution. Govern the action; integrate the input.
Two layers, and only one of them commoditises
The centre has a shape, and naming it matters more each quarter. Agent authority splits cleanly in two, and the split decides which questions a vendor can answer at all.
| Technical authority | Institutional authority | |
|---|---|---|
| The question | Can this agent perform this operation? Is it authenticated, does it hold the scope, is the delegation chain intact, is the capability unexpired? | Will the institution that bears the consequence own this action as its own act — was the power to cause this effect delegated by a principal who held it, exercised inside the mandate, at the moment of consequence? |
| Who owns it | Platform vendors. It belongs where the workloads and the directory already sit, and enterprise directories are now issuing first-class agent identities. | Unclaimed before KYE™. Every incumbent owns a layer, and a layer cannot answer a question about mandate. |
| Where it is heading | Commoditising. Agent identity, scoped delegation and capability attenuation are becoming platform primitives shipped with the directory and distributed by default. | Does not commoditise. The answer depends on the institution's own delegations, mandates, regulatory perimeter and liability — facts no vendor holds and none can infer from a user store. |
| On KYE™'s map | An input layer. KYE™ consumes the credential as evidence and never re-issues it. The state a directory has no name for is authenticated-but-unauthorised. | The root. This is Authority Finality™, stated as a layer rather than as an outcome. |
Provisioning an identity must never silently create the entitlement to cause a consequence. A technically valid credential is a necessary input to the authority decision, and never a sufficient one.
The Adoption Boundary™
Between the two layers sits a crossing: the point at which an institution adopts an agent's action as its own act — where the account stops reading "the AI did it" and starts reading "we did it", and liability, regulatory exposure and counterparty reliance transfer with it.
Finality is the runtime fact that an action became irreversible. The Adoption Boundary™ is what finality means institutionally. An action can be technically committed and institutionally disowned, and that is precisely the position no regulated institution can afford to discover after the fact. KYE™ proves the boundary was crossed deliberately — by an authorised principal, inside a mandate, with the evidence sealed the moment it happened rather than reconstructed months later.
Scope, stated plainly: KYE™ proves the crossing was authorised and seals the proof. It does not adjudicate the institution's liability, and no evidence pack substitutes for a court, a regulator or a contract. The claim is authority provenance, never legal outcome.
What this means for you
For a board, a CISO or a regulator, The Unowned Centre™ turns a question no layer could answer — "was this AI action authorised, and can we prove it?" — into a signed record you can replay on demand.
- Regulators and auditors: every consequential action arrives with its authority basis attached, so a review that took days of reconstruction becomes a minutes-long replay.
- CISOs and risk owners: you keep your observability, identity and evidence tools; KYE™ owns the centre beneath them and proves the authority they cannot, so nothing is ripped out and replaced.
- Builders: bring any runtime, policy engine or model; Know Your Entity™ and Purpose Permission™ own the authority lifecycle above them and make each action provable across the EU AI Act™, NIST AI RMF and ISO/IEC 42001.