---
title: "KYE Protocol™ — Agent Library™ · signed reference agents for every regulated industry"
description: "KYE™ Agent Library™ — 23 versioned, signed reference agents for 12 categories spanning banking, payments, insurance, healthcare, pharma, logistics, energy…"
url: https://kyeprotocol.com/agent-library/
lang: en
source: "KYE Protocol"
---

> KYE™ Agent Library™ — 23 versioned, signed reference agents for 12 categories spanning banking, payments, insurance, healthcare, pharma, logistics, energy…

KYE™ Agent Library™ · v1

# Signed, adoptable agents for every regulated workflow.

Every regulated operation — monitoring for BSA/AML, enforcing SCA on payments, tracing DSCSA drug lots, filing DORA incident reports — is a well-specified agentic workflow. The KYE™ Agent Library™ publishes those workflows as signed, versioned, adoptable agents. Adopt one as a platform-managed subscription, or derive a tenant-tightened variant. The Agent Library™ is a companion primitive to the KYE™ State Library™.

1 · What it is

## 23 starter agents. 12 categories.

Each entry is a JSON document conforming to `kye.agent.library_entry.v1` — triggers (cron, queue, HTTP, signal), typed inputs and outputs, required Cloudflare bindings, declared capabilities, constitutional obligations, `platform_locked_capabilities` that tenants cannot remove, a `machine_seal` sha256 over canonical content, and a detached Ed25519 signature. Tenants adopt by reference and may add triggers, add inputs, add outputs, add obligations, or tighten capabilities. They cannot remove anything present in the base entry, and locked capabilities cannot be denied.

- **Integrity-locked.** machine\_seal is sha256 of canonical sorted JSON; seal is recomputed and verified at adoption time.
- **Derivation-safe.** The schema has no `removed_*` keys. Deriving agents can only add or tighten — never weaken.
- **Regulation-cited.** Each sector agent cites the specific regulation clause it enforces — 31 C.F.R. § 1020.320 (SAR), PSD2 Art 97 RTS (SCA), 45 C.F.R. § 164.528 (HIPAA), DORA Art 19(4)(a), EU AI Act Art 73, and more.
- **Companion to the State Library.** Sector agents reference the compatible State Library entries they consume, creating a coherent lifecycle + agent graph for each regulated entity class.

2 · The catalog

## Pick the category that matches your regulator.

### Platform · State · 7 agents

Core state-machine infrastructure: state transition validator enforcing guard predicates and actor-role requirements; derivation conformance checker auditing every derivation against platform\_locked\_obligations; relationship orphan sweeper; signal replayer for incident reconstruction; ClickHouse backfiller; native FTS5 search reindexer; cross-region state-event replicator.

### Platform · Library · 3 agents

Library lifecycle management: library curator validating and publishing new Agent Library entries from CI; library signer computing canonical machine\_seal and attaching Ed25519 signatures; tenant archiver producing signed NDJSON cold-storage bundles per data-retention schedules.

### Platform · Safety · 4 agents

Platform-wide security: policy compiler producing deterministic sealed bundles (rules / purpose / gates / evidence-trigger / webhook); policy binding evaluator refusing to evaluate any bundle whose seal does not resolve to a deployed Operating Model; grant cascade auditor tracing revocation propagation within 15 minutes; cron watchdog detecting missed scheduled runs within one 5-minute cycle.

### Banking · 1 agent

Banking BSA/AML Monitor enforces Bank Secrecy Act obligations under 31 U.S.C. § 5318(g) and 31 C.F.R. § 1020.320. Monitors entity state transitions and transaction events for suspicious-activity patterns, generates SAR candidates with a 30-day filing deadline, and raises CTR obligations for cash transactions ≥ $10,000 per 31 C.F.R. § 1010.311. Compatible with the banking.kyc\_check, loan\_application, and credit\_facility State Library entries.

### Payments · 1 agent

Payments SCA Enforcer evaluates transaction risk and applies Strong Customer Authentication under PSD2 Art 97, Commission Delegated Regulation 2018/389 (RTS on SCA), and UK PSRs. Manages TRA, low-value, and recurring exemptions per EBA fraud-rate thresholds. All SCA decisions are signed and retained for 5 years per PSD2 Art 248. Compatible with the payments.payment\_intent and banking.merchant\_onboarding State Library entries.

### Insurance · 1 agent

Insurance Claim Orchestrator manages FNOL-to-settlement lifecycle, enforcing 24-hour acknowledgement under FCA ICOBS 8.1, best-estimate reserving per Solvency II Art 77, and mandatory fraud-indicator checks before settlement authority under the Insurance Act 2015. Emits signed reserve-calculation records and claim-action audit logs throughout the claim lifecycle.

### Healthcare · 1 agent

Healthcare HIPAA Guard enforces minimum-necessary access under 45 C.F.R. § 164.502(b), maintains 6-year disclosure accounting records per 45 C.F.R. § 164.528, and emits breach-candidate signals triggering the 60-day HHS notification window per 45 C.F.R. § 164.412. Every PHI access is evaluated in real time against healthcare entity authority grants.

### Pharma · 1 agent

Pharma DSCSA Tracer enforces Drug Supply Chain Security Act obligations under 21 U.S.C. § 360eee-1: verifying Transaction Information and Transaction Statements at each change of ownership, detecting suspect and illegitimate product within 24 hours, and retaining all transaction records for 6 years. Integrates with EPCIS serialisation data and the authorised trading-partner registry.

### Logistics · 1 agent

Logistics Customs Bridge files Automated Export System (AES) declarations per 15 C.F.R. § 30.4 before export, and bridges shipment state-machine events with customs authority gateways (AES/ACI/CHIEF). Notifies shipment owners within 2 hours of a customs hold per WCO SAFE Framework Standard 1 and EU Union Customs Code Art 55.

### Energy · 1 agent

Energy REMIT Reporter monitors wholesale market transactions and inside information under EU REMIT Regulation 1227/2011 and REMIT II (Regulation 2024/1106). Generates ACER-format transaction reports within T+1 per REMIT Art 8 and enforces immediate public disclosure of inside information per REMIT Art 4 through the registered reporting mechanism API.

### RegTech · 1 agent

RegTech DORA Incident Manager classifies ICT-related incidents per EU DORA Regulation 2022/2554 RTS thresholds and manages the full reporting timeline: initial notification within 4 hours (Art 19(4)(a)), intermediate report within 72 hours (Art 19(4)(b)), and final report within 1 month of resolution (Art 19(4)(c)). Maintains the DORA incident register and submits reports to competent authorities via the regulator gateway.

### AI Governance · 1 agent

AI Act Conformance Agent classifies AI system entities by risk tier, verifies conformity assessment completeness per EU AI Act Regulation 2024/1689 Art 43, monitors high-risk system obligations (automatic logging Art 12, human oversight Art 14), and triggers serious incident reports to the market surveillance authority within 15 days per Art 73. Compatible with the ai\_governance.ai\_inference\_run State Library entry.

Companion family

## Governed Agents™ — the bounded agents KYE Protocol™ operates.

The Agent Library™ above lists reference _workflows_ you run. The [KYE™ Governed Agents™](https://kyeprotocol.com/governed-agents/) family is different: these are the bounded agents KYE Protocol™ runs as products. Each one is a first-class principal — authority-bound, evidence-sealed, metered, and kill-switched. This list is derived from the product registry, so a new agent shows up here on its own.

- [**KYE™ Chargeback Evidence Agent™**](https://kyeprotocol.com/governed-agents/chargeback-evidence-agent/) — governed card-dispute evidence.
- [**KYE™ Companies House Lookup Agent™**](https://kyeprotocol.com/governed-agents/companies-house-lookup-agent/) — governed UK company verification.
- [**KYE™ KYC-Refresh Agent™**](https://kyeprotocol.com/governed-agents/kyc-refresh-agent/) — governed KYC refresh.
- [**KYE™ Clinical Action Authority Agent™**](https://kyeprotocol.com/governed-agents/clinical-action-authority-agent/) — governed release/flag-triage/recommend/escalate/share.
- [**KYE™ Clinical Trial Conduct Authority Agent™**](https://kyeprotocol.com/governed-agents/clinical-trial-conduct-authority-agent/) — governed enroll/randomize/unblind/deviation/data-lock/IRB-submission.
- [**KYE™ Credit Card Action Authority Agent™**](https://kyeprotocol.com/governed-agents/credit-card-action-authority-agent/) — govern limit/APR/issuance.
- [**KYE™ Drug Discovery Research Authority Agent™**](https://kyeprotocol.com/governed-agents/drug-discovery-research-authority-agent/) — governed advance/release-claim/use-dataset/register-finding.
- [**KYE™ Insurance Action Authority Agent™**](https://kyeprotocol.com/governed-agents/insurance-action-authority-agent/) — govern accept/decline/pay.
- [**KYE™ Legal Action Authority Agent™**](https://kyeprotocol.com/governed-agents/legal-action-authority-agent/) — govern execute/sign/release decisions.
- [**KYE™ Mortgage Lending Action Authority Agent™**](https://kyeprotocol.com/governed-agents/mortgage-lending-action-authority-agent/) — govern approve/decline/terms.
- [**KYE™ Payment Authorization Authority Agent™**](https://kyeprotocol.com/governed-agents/payment-authorization-authority-agent/) — governed authorize/hold/step-up/decline.
- [**KYE™ Pharmacovigilance Action Authority Agent™**](https://kyeprotocol.com/governed-agents/pharmacovigilance-action-authority-agent/) — governed ICSR filing, signal disposition, PSUR release, recall notification.
- [**KYE™ PII Action Authority Agent™**](https://kyeprotocol.com/governed-agents/pii-action-authority-agent/) — governed use/disclose/transfer/retain/profile/delete.
- [**KYE™ RAG Output Authority Agent™**](https://kyeprotocol.com/governed-agents/rag-output-authority-agent/) — governed release/act-on/feed of a RAG answer.
- [**KYE™ Sanctions & AML Authority Agent™**](https://kyeprotocol.com/governed-agents/sanctions-aml-authority-agent/) — governed block/release/escalate/file-SAR.
- [**KYE™ Threat Response Authority Agent™**](https://kyeprotocol.com/governed-agents/threat-response-authority-agent/) — governed block/revoke/isolate/disable/escalate/notify.
- [**KYE™ Governed Grants Agent™**](https://kyeprotocol.com/governed-agents/grants-authority-agent/) — governed award and disbursement decisions.
- [**KYE™ Settlement Finality Authority Agent™**](https://kyeprotocol.com/governed-agents/settlement-finality-authority-agent/) — governed, final settlement decisions.
- [**KYE™ Account-Opening CDD Authority Agent™**](https://kyeprotocol.com/governed-agents/account-opening-cdd-authority-agent/) — governed open/decline/refer-EDD/conditionally-open.
- [**KYE™ Billing & Dunning Authority Agent™**](https://kyeprotocol.com/governed-agents/billing-dunning-authority-agent/) — governed fee/late-fee/dunning/suspend/collections/write-off.
- [**KYE™ Fraud Decision Authority Agent™**](https://kyeprotocol.com/governed-agents/fraud-decision-authority-agent/) — governed block/hold/release/step-up.
- [**KYE™ Genetic Sequencing Authority Agent™**](https://kyeprotocol.com/governed-agents/genetic-sequencing-authority-agent/) — synthesis-order/screening-disposition/data-release/clinical-result.
- [**KYE™ Pension Liquidity Authority Agent™**](https://kyeprotocol.com/governed-agents/pension-liquidity-authority-agent/) — governed LDI collateral call / forced sale / redemption gate / buy-in-out trigger.
- [**KYE™ Treasury Authority Agent™**](https://kyeprotocol.com/governed-agents/treasury-authority-agent/) — governed corporate-treasury decisions within mandate/limit.
- [**KYE™ Governed Control & Policy Authority Agent™**](https://kyeprotocol.com/governed-agents/control-policy-authority-agent/) — governed recommend-controls / draft-policy.
- [**KYE™ Claims Decision Authority Agent™**](https://kyeprotocol.com/governed-agents/claims-decision-authority-agent/) — govern triage, reserves, settle/deny, payment release, referrals.
- [**KYE™ Policy Lifecycle Authority Agent™**](https://kyeprotocol.com/governed-agents/policy-lifecycle-authority-agent/) — govern issue/endorse/renew/cancel/non-renew/reinstate.
- [**KYE™ Quote & Bind Authority Agent™**](https://kyeprotocol.com/governed-agents/quote-bind-authority-agent/) — govern overrides, discounts, and the bind finality gate.
- [**KYE™ Underwriting & Risk-Acceptance Authority Agent™**](https://kyeprotocol.com/governed-agents/underwriting-authority-agent/) — govern accept/decline/refer within delegated limits.
- [**KYE™ Islamic Embedded Finance Authority Agent™**](https://kyeprotocol.com/governed-agents/islamic-embedded-finance-authority-agent/) — govern releasing or holding a Shariah-compliant embedded-finance offer.
- [**KYE™ Islamic Microfinance Authority Agent™**](https://kyeprotocol.com/governed-agents/islamic-microfinance-authority-agent/) — govern a qard hasan or micro-murabaha disbursement and its late-payment treatment.
- [**KYE™ Islamic Mortgage Authority Agent™**](https://kyeprotocol.com/governed-agents/islamic-mortgage-authority-agent/) — govern home-finance acts under diminishing-musharaka or ijarah muntahia bittamleek.
- [**KYE™ Islamic Trade Finance Authority Agent™**](https://kyeprotocol.com/governed-agents/islamic-trade-finance-authority-agent/) — govern the Shariah-governed trade-finance acts.
- [**KYE™ Istisna Authority Agent™**](https://kyeprotocol.com/governed-agents/istisna-authority-agent/) — govern the istisna' construction-finance acts.
- [**KYE™ Murabaha Authority Agent™**](https://kyeprotocol.com/governed-agents/murabaha-authority-agent/) — govern each step of the murabaha sequence in order.
- [**KYE™ Muzaraa Authority Agent™**](https://kyeprotocol.com/governed-agents/muzaraa-authority-agent/) — govern the muzara'a agricultural-partnership acts.
- [**KYE™ Salam Authority Agent™**](https://kyeprotocol.com/governed-agents/salam-authority-agent/) — govern the salam acts.
- [**KYE™ Shariah Operations Authority Agent™**](https://kyeprotocol.com/governed-agents/shariah-operations-authority-agent/) — govern recording and escalating a Shariah non-compliance (SNC) event.
- [**KYE™ Shariah Screening Authority Agent™**](https://kyeprotocol.com/governed-agents/shariah-screening-authority-agent/) — govern a screening verdict on an instrument, counterparty, or portfolio line.
- [**KYE™ Shariah Structuring Authority Agent™**](https://kyeprotocol.com/governed-agents/shariah-structuring-authority-agent/) — govern a product structure into the Shariah Supervisory Board approval queue.
- [**KYE™ Sukuk Authority Agent™**](https://kyeprotocol.com/governed-agents/sukuk-authority-agent/) — govern the sukuk lifecycle acts (issuance, servicing, redemption).
- [**KYE™ Takaful Authority Agent™**](https://kyeprotocol.com/governed-agents/takaful-authority-agent/) — govern operator-side acts on a takaful risk fund.
- [**KYE™ Wakala Authority Agent™**](https://kyeprotocol.com/governed-agents/wakala-authority-agent/) — govern an act under a wakala mandate only within its recorded scope.

[See the Governed Agents™ family](https://kyeprotocol.com/governed-agents/)

3 · Adopt + derive

## Two adoption modes. One integrity model.

The KYE™ Agent Library™ adoption flow has two modes, both enforced by the platform through the same seal-verification step.

1. **Subscription.** The tenant adopts the platform-managed agent instance as-is. The platform runs the agent; the tenant configures bindings. Zero derivation overhead. Seal verified at adoption time and re-verified at each scheduled execution.
2. **Derivation.** The tenant records a `kye.agent.derivation.v1` document listing additions only: extra triggers, extra inputs, extra outputs, extra obligations, tightened capabilities. The platform merges the derivation on top of the base entry at runtime. The base-entry seal is always re-verified first. Forbidden derivation keys (`removed_triggers`, `removed_inputs`, `removed_outputs`, `removed_obligations`, `removed_capabilities`) are rejected at write time by the adoption API — the schema does not define them.

In both modes, `platform_locked_capabilities` cannot be removed or denied. The Policy Decision Point verifies this at every evaluation cycle.

4 · Open source

## The catalog is open.

The 23 starter Agent Library entries are published under Apache-2.0 in the [KYE Protocol™](https://github.com/KYE-Protocol) GitHub organisation. The schemas (`kye.agent.library_entry.v1`, `kye.agent.derivation.v1`) are published under MIT. The adoption API, seal-verification logic, and Policy Decision Point integration are part of the KYE Protocol™ platform.

[View on GitHub](https://github.com/KYE-Protocol)

5 · Get started

## Join the KYE Protocol™ pilot.

Early access to the KYE™ Agent Library™, KYE™ State Library™, and the full KYE Protocol™ platform is available to regulated financial institutions, healthcare providers, logistics operators, and energy market participants under the pilot program.

[Apply for pilot access](https://kyeprotocol.com/pilot-apply/)

Canonical KYE™ surfaces referenced on this page: [KYE Protocol™](https://kyeprotocol.com/).
