Fragmented identity
One agent typically holds three or four identities at once. Auditors stitch traces by timestamp.
Agentic Governance™ with Authority Finality™
Was the action allowed? Can you prove what happened? Did it close cleanly? The KYE™ Authority API answers all three on every consequential action (allow, deny or require approval) and returns a signed receipt your auditor can verify offline, years later.
Know Your Entity™ at t=0: identity asks who; KYE™ proves whether it was allowed, the instant the action forms.
Authority Finality™: KYE Protocol™ enforces authority while the action is forming: it refuses out-of-scope AI-agent action before the side effect commits, and every refusal and approval is signed, replayable and verifiable offline.
Built for the people who must answer who authorised the agent
Why it exists
Observability, a trace, a permit, an identity, an API key, a guardrail: each proves something real (that an agent exists, that it behaved, that a rule was checked). None proves the institution empowered it to cause the effect.
One agent typically holds three or four identities at once. Auditors stitch traces by timestamp.
OAuth scopes describe state at issuance, not state now. Revocations don't propagate; a compromised agent keeps acting until the next review.
Audit logs are vendor-specific. The decision, the inputs, the obligations and the cascade are not portable.
Responsibility split across IT, data science, business lines and control functions, without a clear accountability framework.
Protocol, not product
KYE Protocol™ sits above your agents, beneath your execution, and across every model, sector and jurisdiction: model-agnostic, vendor-agnostic, framework-agnostic. One engine; your packs, agents and surfaces are projections of it. Every action runs in one of three modes:
Three questions you can't answer today
Stop an unauthorised AI action before it commits, not after the regulator asks. Authority is traced across the whole chain and is jurisdiction-aware.
Each decision is sealed into a signed record anyone can verify offline, from published keys alone. Nothing is asserted that isn't proven.
High-stakes actions can require a second approver, or be held from becoming final until authority is re-anchored. Contestable later, never deniable.
Revoke a parent and the cascade reaches every child grant before the response to the originating request returns.
One URN names every actor (human, business, service, AI agent, model, tool, workflow) and binds it to a public key.
The pack carries the version of your estate the decision was judged against, so a rename years later cannot rewrite what the record means.
Where this applies to you
Choose your role.
For CISOs
Runtime authority checks on every consequential agent action, Shadow Mode™ before you enforce, and a Rules Gateway™ in front of your stack.
For CISOsFor CFOs
Value-based pricing: start free, prove it with an Audit Pilot™, then scale. The evidence that turns exam questions from days into one pack.
For CFOsFor General Counsel
Authority Finality™: a replayable proof layer for accountability, dispute resolution and legally defensible audit trails. KYE™ does not replace legal agreements or signatures.
For counselFor auditors and GRC
Evidence Packs™ you verify offline from published keys, with the control behind each claim mapped to the frameworks you test against.
Auditor firm onboardingFor regulators
Decisions sealed at t=0 that a supervisor can replay, with the estate as it was, not as it is now.
For regulatorsFor builders
One API call per action, SDKs in TypeScript, Python and Go, the CLI and the KYE™ MCP Server™.
Developer portalFor DPOs
Purpose Permission™: every action is bound to the purpose it was granted for, and an action outside it is refused at the boundary.
For DPOsFor partners
KYE™ Inside: sell authority to your own customers without building a governance engine; multi-tenant and under your brand.
Partner programOne authority hub
Select a module to see its lifecycle.
The mechanism
It enters the rail before anything irreversible happens.
ExampleCredit decisioning agent: approve a £4,200 credit line (demo)
Rego, Cedar, or custom policy evaluates the request against your rules: deny, allow, or escalate.
ExampleRetail credit policy, GB and IE only
Identity, data classification, and jurisdiction are verified at the edge before authority is granted.
Examplejurisdiction GB · data class personal · entity active
HSM-ready signing binds the decision to its proof; the Evidence Pack™ is an offline-replayable, tamper-evident archive.
Examplekye:decision:9f3ac1 · Ed25519
Start where you are
The runtime that checks authority, seals evidence and reaches finality.
Governed surfaces you can adopt today.
Prove it to your auditor.
Pilot, partner, get certified.
Try it free, right now.
Banks and regulated institutions whose supervisor is already asking who authorised the agent.
Agent actions on accounts and payments, each checked against delegated authority.
Governed AI over personal health information, with break-glass and evidence.
Dispute resolution and the agent as contracting party.
Sovereign AI profiles per region: UK, EU, US, Gulf, Canada, Australia, Singapore, New Zealand.
Underwriting and claims authority, refused before the side effect commits.
An empty sandbox is not enough
The terminal and the lab come with fictional tenants, agents, delegations and decisions, so you can see the authority engine work in the first minute.
Authority has a lifecycle
Select a stage to see what happens in it.
Shadow Mode™ first
Choose a run mode and a scenario, and watch the decision and the evidence respond.
Scenario
Use cases
Credit decisioning
Accounts payable
From API to app
Three demo consoles built on the same decision. Tap inside the phone or press play; each step shows the API call and the event it produced.
Tap any call in the list under a phone to open the same request in the API console. All data is fictional.
KYE™ Widgets™
GovernedUI™ widgets embed from widgets.kyeprotocol.com. Try a simplified preview here, then copy the embed snippet.
Notifications
Approval required, delegation expiring, action denied, Evidence Pack™ sealed: one rule per event, with a delivery receipt for each message. Choose an event type and answer it on the phone. Demo data
Governed agents
KYE Protocol™ enforces authority while the action is forming: it refuses out-of-scope AI-agent action before the side effect commits, and every refusal and approval is signed, replayable and verifiable offline. An action commits only when:
DemoAll organisations, people, agents and amounts are fictional. Identifiers are shaped like real KYE Protocol™ identifiers but do not resolve to a governed record.
Governed workflows
Each node is an agent, a tool, a person or a policy. Every run is visible step by step, and waits for a person wherever the decision is require approval.
KYE™ Cloud™
Demo data
The KYE™ terminal
Request, check, decide, approve and seal, from one place. Demo data
Identify→Delegate→Scope→Decide→Approve→Seal
DemoAll organisations, people, agents and amounts are fictional. Identifiers are shaped like real KYE Protocol™ identifiers but do not resolve to a governed record.
For developers
Schema-first, dictionary-first, profile-first, registry-first, API-first, SDK-first, evidence-first, conformance-first. The same decision reaches your backend, your scripts and your agents.
POST/api/v1/runtime/evaluate
Interactive API console
Pick an endpoint, edit the request and send it. You see the path through the six checks, the decision, the headers, the events and ready-made code in four languages. Responses here are simulated and touch no real tenant.
Architecture
Select a layer to see its role.
Select a layer.
Ecosystem
Connectors, integrations, the App Store, the Plugin Marketplace™, the State Library and the Directory: the ecosystem around one authority engine.
Counterparty governance
A buyer's agent and a seller's agent each prove their authority; both receipts land in both Evidence Packs™. Demo data
DemoAll organisations, people, agents and amounts are fictional. Identifiers are shaped like real KYE Protocol™ identifiers but do not resolve to a governed record.
Connector Hub™
A connector maps each system's own contract onto the KYE™ decision. Delegations, scopes and evidence stay the same; only the connection changes.
Systems, capabilities, versions and status, in one view (demo data).
| Connector | Capability | Environment | Status |
|---|---|---|---|
| Simulator | Decisions, delegations, evidence | Simulated | Ready |
| Identity provider (demo) | Principals, sessions | Sandbox | Connected |
| MCP gateway (demo) | Tool calls under authority | Shadow | Observing |
| SIEM export (demo) | Decision and audit events | Live | Active |
The decision path
Identity, on-behalf-of, authority, scope, state and audit, each checked before the side effect commits; every step is timestamped in the pack. Demo data
DemoAll organisations, people, agents and amounts are fictional. Identifiers are shaped like real KYE Protocol™ identifiers but do not resolve to a governed record.
The protocol governs itself
The promise: KYE Protocol™ enforces authority while the action is forming: it refuses out-of-scope AI-agent action before the side effect commits, and every refusal and approval is signed, replayable and verifiable offline.
Authority Finality™: legacy IAM vs KYE™
| Approach | Strength | Limit |
|---|---|---|
| Legacy IAM | Role resolved at login; well understood | Static permissions; revocation propagates eventually; no account of why the actor was entitled |
| Observability and traces | Shows what an agent did | Proves it behaved, not that it was empowered to cause the effect |
| Guardrails | Checks a rule on the content | A rule was checked; authority was not resolved |
| KYE Protocol™ | Authority resolved at t=0 of the action: scope-bound, expiring, recursively revocable, the entitlement sealed as evidence | Needs delegations and scopes declared for each use case |
Start free. Prove it. Scale.
SDK (TypeScript, Python, Go), CLI and local adjudication, self-assessment fixtures, community support.
A scoped Evidence Pack™, a regulator-ready report, a standard mutual NDA on request and guided onboarding.
HSM-ready (BYOK) signing, dedicated support, custom sector packs and private connector profiles.
Platform fees and professional fees, anchored on the continuous value the runtime delivers.
Audit exam-prep drops from days of reconstruction to a single verifiable pack.
Continue here
List entities, read a delegation's scope, evaluate an action, replay safely, hit the scope and read the events. No sign-up.
Open the lab TerminalTen views of governed agent actions.The decision path, delegations, require approval, workflows, notifications, counterparties, failure scenarios and evidence.
Open the terminal AcademyLearn the category.Authority, evidence and finality: learning paths over KYE™ Learn™, the glossary, the library and the playbooks.
Enter the academy PartnersPartner, get certified, build on KYE™.Resellers, integrators, ISVs, connector builders, trainers and auditor firms.
Become a partnerPodcasts
KYE™ Minute explains one glossary term in about a minute, with a full transcript and an RSS feed. Episodes are published once audio is switched on; until then this section lists what is planned.
Glossary
190 terms in 16 groups, one paragraph per term, linked to its schema and its dictionary code.
Events
A practitioner-led forum for agentic governance in the runtime era: conferences, workshops, webinars, office hours and governed-research report launches, each one dated entry you can register for.
We email you when a session is scheduled or a report is published.
FAQ
The open contract that answers, for every action a human, service, AI agent, model, tool or workflow takes: who acted, on whose behalf, with what authority, under what scope, with what evidence?
No. KYE™ does not replace legal agreements, signatures, or regulatory obligations; it provides the technical control and evidence layer needed to support authority finality, accountability and legally defensible audit trails for agentic systems.
A decision (allow, require_approval or deny) with a reason code from KYE™'s vocabulary, a replay-stable decision id, a receipt you can verify, and a sealed Evidence Pack™ that can be verified offline from published keys.
Traditional IAM answers who logged in. KYE™ answers everything that comes after: who or what acted, who they acted for, what authority they had, what capability they used, what state they were in, and what evidence proves it.
Yes. The lab and the terminal run in your browser on fictional data; the free tools and the sandbox need no sign-up. An API key comes from the console.
Apache License 2.0. KYE™, KYE Protocol™ and Know Your Entity™ are trademarks of the KYE Protocol™ project; see the trademarks page.
Only to answer that request. Read the details in the and the full privacy policy.
Start free. Prove it. Scale.
Identity, on-behalf-of, authority, scope, state and audit, decided at t=0 and sealed into an Evidence Pack™ your auditor verifies offline.
Start in one line: npx @kye/cli
Reference: