---
title: "KYE Protocol™ — Action Admissibility · before authority, before commit"
description: "KYE™ Action Admissibility Profile™ — checks whether a proposed action is admissible into the authority pipeline before any authority, formal-rule or…"
url: https://kyeprotocol.com/action-admissibility/
lang: en
source: "KYE Protocol"
---

> KYE™ Action Admissibility Profile™ — checks whether a proposed action is admissible into the authority pipeline before any authority, formal-rule or…

KYE™ Action Admissibility™ · v1.0

# Catch a bad action before authority checks it.

Attribution proves who acted. Authority proves they were allowed. KYE™ adds a step before both: an admission gate that you run on the proposed action, signed and replayable. The verdict alphabet and inadmissibility taxonomy are bounded and canonical; the specific enumeration is proprietary and is not disclosed in this repository.

1 · Why a new layer

## Attribution alone is late.

If an AI agent forms a harmful or out-of-scope action, you may still carry risk even if KYE™ later denies it. The EU AI Act (Artificial Intelligence Act) Art. 14 and NIST AI RMF Govern-1.4 both want you to show that proposal was inadmissible — not just that the commit was blocked.

- Why was this action even allowed to form?
- Which signal, prompt, tool, or incentive shaped it?
- Was the proposal admissible before authority ran?
- What evidence shows you stopped it upstream?

2 · The full pipeline

## Signal → proposal → admit → authority → commit → evidence.

Admission decides if the action may enter. Authority decides if it may proceed. Commit decides if it becomes real. Each step is signed, hash-chained, and replayable under DORA (Digital Operational Resilience Act) Art. 6.

01

**Signal** User / system / agent input.

02

**Intent** Declared goal + constraints.

03

**Interpretation** Agent reading of the goal (Continuity Module™).

04

**Proposed Action** `KYEProposedAction` — origin, capability, target, preconditions, risk flags.

05

**KYE™ Admission Gate™** This profile. Signed admit / reject / clarify / review / quarantine.

06

**Authority Gate™** Decision Engine runs only if admitted.

07

**Rules & obligations** Permissions, obligations, stop-conditions.

08

**Commit Boundary™** Provisional becomes binding.

09

**Execution** The action runs.

10

**Evidence** Decision Map™ + Evidence Pack™; replayable.

3 · Six admissibility verdicts

## Admit. Reject. Clarify. Review. Quarantine. Route.

Each verdict is a signed JSON record on the audit chain. You can replay it with the same inputs and the same rule bundle and get the same output, bit-for-bit.

### `admit`

Admissible. Route to the Authority Gate™.

### `reject`

Invalid or prohibited. Block at the gate.

### `require_clarification`

Intent ambiguous. Ask the principal to clarify.

### `require_human_review`

Admit only after a human reviewer signs off.

### `quarantine`

Pattern matches a watched class. Freeze and escalate.

### `route_to_authority_check`

Explicit routing instruction. Same as admit.

4 · Fifteen inadmissibility classes

## What the gate actively detects.

Each class maps to a reason code in the public dictionary. The mappings land in ISO 42001 Annex B and NIST AI RMF Manage-2.2 for your audit packs.

- **invalid\_intent** — declared intent structurally invalid
- **ambiguous\_intent** — intent / interpretation drift over threshold
- **out\_of\_scope\_proposal** — outside the authority grant scope
- **prohibited\_action\_class** — matches a banned class for this actor
- **disallowed\_data\_source** — source banned by policy
- **inadmissible\_evidence** — required evidence missing or untrusted
- **unsafe\_tool\_path** — tool path matches an unsafe pattern
- **coercion\_signal** — pressure signal detected upstream
- **incentive\_conflict** — agent incentive clashes with intent
- **continuity\_break** — meaning drift detected upstream
- **policy\_ineligible\_action** — ineligible under the active policy set
- **missing\_authority\_context** — no authority context resolves
- **missing\_principal** — no principal entity resolves
- **missing\_accountable\_owner** — no accountable owner resolves
- **unsupported\_jurisdiction** — no jurisdiction binding

5 · Schemas

## Five normative JSON objects. Validated by ajv in CI.

Each schema is JSON Schema 2020-12 with a stable `$id`. The payload, webhook, and OpenAPI contracts all share these five objects.

- `action-admissibility-profile.json` — profile manifest
- `proposed-action.json` — the candidate action you submit
- `admission-gate.json` — pre-admission gate; upstream of the Authority Gate™
- `admissibility-decision.json` — signed verdict + next step
- `admissibility-evidence.json` — hash-chained inputs + signals

6 · Open / paid boundary

## Contracts are open. The Admissibility Engine™ is paid.

Apache 2.0 schemas, dictionaries, and fixtures ship in public. The paid engine adds detection, scoring, and sector packs for banking, healthcare, and public sector buyers.

Open source

### Open

- Action Admissibility™ schema
- 4 object schemas (proposed action, gate, decision, evidence)
- 6 decision values
- 15 inadmissibility class names
- 20 reason codes
- Signal Bus event names
- Sample proposed actions + decisions
- Conformance fixtures + validator SDK

Commercial track

### Paid

- KYE™ Admissibility Engine™
- KYE™ Admission Gate™ runtime
- Inadmissible-action detection
- Pre-action risk scoring
- Banned-class detection
- Intent-ambiguity detection
- Source / data admissibility checks
- Quarantine flow
- Sector packs (banking, health, public, defence)

Where to go next

## Adjacent reading.

If admission says admit, the Rules Engine runs next. If admission says clarify or review, the principal or owner handles it.

[Formal Rules](https://kyeprotocol.com/formal-rules/) [Continuity Module™](https://kyeprotocol.com/continuity/) [Operating Model™](https://kyeprotocol.com/operating-model/)

## Ready to see your AI agents flagged?

Start in shadow mode. We’ll deliver your first Evidence Pack™ in 4–8 weeks.

[Apply for pilot →](https://kyeprotocol.com/pilot-apply/) [Try the sandbox →](https://kyeprotocol.com/sandbox/demos/)

Canonical KYE™ surfaces referenced on this page: [Evidence Pack™](https://kyeprotocol.com/evidence-pack/) · [KYE Protocol™](https://kyeprotocol.com/).
