A correct answer can still be unauthorised. Authority Finality™ settles it.
Authority Finality™ is the category KYE Protocol™ defines and leads: proving every consequential action was authorised, purpose-bound, evidenced, replayable and final before it changed the world. When an AI agent moves money, releases a clinical result, or files a return, KYE™ proves who authorised it — turning an auditor's days of exam-prep into minutes.
The doctrine: no authority, no finality
If you are a CISO or a regulator, every word below is a control you can test. Each rung rules out a thing the market keeps mistaking for authority.
- Output is not authority. A model producing an answer is not permission to act on it.
- Evidence is not authority. A tamper-evident log proves what happened, not that it was allowed.
- Identity is not authority. Knowing who the agent is does not establish what it may do.
- Access is not authority. Holding a credential is not the same as being authorised for this act.
- Capability is not authority. A benchmark pass proves competence, not mandate.
- Safety is not authority. A refusal to do harm is not a mandate to do this.
- Semantic alignment is not authority. Understanding the request is not permission to fulfil it.
- Policy compliance is not authority. Matching a policy is not the same as being authorised under it.
- Behavioural conformance is not authority. Acting as expected is not evidence anyone sanctioned the act.
- Permission is not mandate. Being allowed is not being instructed by someone entitled to instruct.
- Approval is not authority. A recorded yes proves someone approved, not that they could bind.
- Technical authority is not institutional authority. A system granting access cannot grant the institution's consent.
- No authority, no finality. An action becomes final only once KYE™ proves it was authorised.
- Legitimate authority at the exact moment of consequence. Not before, not after — at the instant the act becomes real.
The lifecycle KYE™ owns — entity to finality
Adjacent tools each answer one fragment of the question. KYE Protocol™ owns the whole chain a consequential action travels, end to end — eleven stages, each resolving to a control you can audit.
- Entity — who or what exists and can act. Who/what is this?
- Principal — the agent as a first-class governed principal, not an anonymous script. Is the actor accountable?
- Delegated authority — who authorised whom, for what scope. On whose mandate?
- Purpose Permission™ — authority bound to a purpose, so yesterday's grant cannot authorise today's different act. For what purpose?
- Allowed data, tool, model — only the inputs this actor is permitted to use. With what?
- Approval — required human sign-off captured for high-stakes or irreversible acts. Who approved it?
- Decision Map™ — the inputs, policy, evidence and actor that produced the verdict. How was it decided?
- Evidence Pack™ — a signed, action-level proof bundle. What is the proof?
- Replay-Proof™ — any auditor verifies the seal offline from published keys alone, without trusting KYE™. Can you prove it independently?
- Finality Gate — the action becomes final only when authority is proven; draft, advisory and executed are distinct states. May it be relied upon?
- Drift & revocation — authority that expires, drifts or is revoked is caught and itself evidenced. What happens when a control fails?
Everyone else is a point on this map
The category is forming, and serious players are converging on it. That validates Authority Finality™ — and it is why KYE Protocol™ draws the map rather than sitting on someone else's. Each adjacency answers a fragment; KYE™ owns the chain that makes an action final.
| Adjacent player | What it owns | Where it sits on KYE™'s map |
|---|---|---|
| Output-to-action boundary tools | the regulated checkpoint where AI output becomes action | a single gate inside KYE™'s chain — KYE™ proves the whole authority that earns the right to reach it |
| Runtime integrity controls | the transition between possibility and consequence at the point of execution | that transition is the Finality Gate; KYE™ governs the ten stages that precede it |
| Decision-evidence integrity tools | tamper-evident records of what an AI decided | an input layer feeding KYE™'s Evidence Pack™ — KYE™ adds whether the act was authorised |
| Capability benchmarks | whether an agent can do the work | an input layer: a benchmark result scopes authority, but capability is not authority |
KYE Protocol™ integrates these layers rather than forking them, ships its own governed agents on top of them, and consumes their signals — the way it already consumes inference-gateway telemetry and capability evaluations — and turns them into authority decisions and replay-verifiable evidence. Govern the action; integrate the input.
Three instruments, one governor. A governance is not one lever: it enables (the public goods every agent stands on: identity, vocabulary, runtime, sandboxes, the directory), it constrains (purpose scope, allowed actions, obligations, stop conditions, the verdict that makes an action final or refuses it), it promotes (certification, sector packs, the programmes that lift selected producers) and it supports (replay, auditability, rights). Authority Finality™ is the constraining core; KYE Protocol™ carries all four, and every rail declares which one it is.
What this means for you
For a board, a CISO, or a regulator, Authority Finality™ converts an unanswerable question — "was this AI action allowed?" — into a signed record you can replay on demand.
- Regulators and auditors: every consequential action arrives with its authority basis attached, so a review that took days of reconstruction becomes a minutes-long replay.
- CISOs and risk owners: authority can be revoked mid-flight and the revocation is itself evidenced — you control the blast radius of an agent that drifts.
- Builders: bring any runtime, policy engine or model; KYE Protocol™ owns the authority lifecycle above it and makes each action regulator-provable across the EU AI Act, NIST AI RMF and ISO/IEC 42001.