---
title: "KYE™ Agentic Authority Index™ — the measurement standard for valid agent authority · KYE Protocol™"
description: "The KYE™ Agentic Authority Index™ measures whether AI agents act with valid authority, not just whether they succeed. Ten Authority Benchmark metrics, indexed across sectors, jurisdictions and agent action-classes, published and replay-verifiable via the Governed Research Rail. Approval is an event; authority is a property."
url: https://kyeprotocol.com/authority-index/
lang: en
source: "KYE Protocol"
---

> The KYE™ Agentic Authority Index™ measures whether AI agents act with valid authority, not just whether they succeed. Ten Authority Benchmark metrics, indexed across sectors, jurisdictions and agent action-classes, published and replay-verifiable via the Governed Research Rail. Approval is an event; authority is a property.

# Did it succeed is the wrong question. Did it act with valid authority is the one the KYE™ Agentic Authority Index™ answers.

The **KYE™ Agentic Authority Index™** is the reference standard from [KYE Protocol™](https://kyeprotocol.com/) that measures whether AI agents act with **valid authority**, not just whether they get an answer. It defines the category's measurement layer: ten Authority Benchmark™ metrics, indexed across sectors, jurisdictions and agent action-classes, and published under the Governed Research Rail so every figure is evidence-sealed and replay-verifiable. If you own agent risk, it turns "we think our agents behaved" into a number you can defend — and it launches with the first fully-scored entity: KYE™ itself.

[Request an authority assessment](https://kyeprotocol.com/poc/) [See the category](https://kyeprotocol.com/authority-finality/)

## The doctrine: authority is a property, not an event

If you are a CISO, a regulator, or a board member, the Index™ exists to close one gap the agent market keeps stepping over: a task can complete flawlessly and still be institutionally invalid. Each line below is a control you can test rather than a slogan.

- **Approval is an event; authority is a property.** A single click yesterday is not standing permission for a different act today.
- **An engineered outcome can still be institutionally invalid.** The transaction cleared, the letter shipped, the file was accepted — none of that proves the agent was allowed to do it.
- **"Did it succeed?" becomes "Did it possess valid authority?"** The Index™ re-asks every agent action against its mandate, its purpose and its evidence, and scores the answer.

## The ten Authority Benchmark™ metrics

You cannot manage what you cannot measure, so the Index™ decomposes "valid authority" into ten metrics an auditor can reproduce. Each is defined once here, in one honest sentence, and each maps to a control the KYE™ engine already emits.

| Metric | What it measures |
| --- | --- |
| Authority Resolution™ Time | How fast the system resolves whether an agent's action carries valid authority before that action is allowed to land. |
| Authority Accuracy | The share of actions where the authority verdict — allowed or not allowed — matches the true mandate. |
| False Authority Grant Rate | How often an action is treated as authorised when it was not; the dangerous error, because the world already changed. |
| False Authority Denial Rate | How often a legitimately-authorised action is wrongly blocked; the friction error that erodes trust in the control. |
| Delegation Drift | How far an agent's exercised authority strays from the chain of delegation that actually granted it. |
| Mandate Drift | How far an action drifts from the specific purpose the authority was granted for under Purpose Permission™. |
| Policy Drift | How far runtime enforcement diverges from the declared policy as rules, models and agents change over time. |
| Authority Replay Success | The share of actions whose authority basis can be independently re-verified from sealed evidence, without trusting KYE™. |
| Authority Finality™ Completeness | The share of consequential actions that reach a proven-final state rather than an ambiguous "probably fine" one. |
| Human Authority Correctness | The share of required human approvals that were genuinely present, valid, and correctly attributed to the right person. |

## What the Index™ indexes — three axes

A single score means nothing without knowing what it is a score of. The Index™ places every measurement on three axes drawn from existing KYE™ registries, never a new taxonomy, so a result is always "this action-class, in this sector, under this regime."

- **Sectors** — the regulated verticals KYE™ already maps as sector packs: `aml-financial-crimes`, `agentic-lending`, `biopharma-pharmacovigilance`, `consumer-reporting-adverse-action`, `canada-health` and more, so an authority score is anchored to a real market, not an average.
- **Jurisdictions** — the 249 regulatory frameworks KYE™ deep-maps, including the EU AI Act, NIST AI RMF, ISO/IEC 42001, GDPR and DORA, so an authority claim is graded against the regime that would actually judge it.
- **Agent action-classes** — the consequential acts an agent performs: moving money, releasing a clinical result, deciding credit, granting data access. Each is scored on its own risk. A chatbot reply and a wire transfer do not carry the same authority weight.

## The first fully-scored entity: KYE™ itself

An index that has scored nobody is a promise, so KYE Protocol™ published its own authority posture first — with numbers it computes on every run and can hand an auditor, not numbers it made up. Under constitutional self-run governance (§0.34), every component of the KYE™ codebase is driven through the real KYE™ Decision Engine and must produce a governed, evidenced, replay-stable verdict.

### 1044 / 1044

inventory items run through the real KYE™ Decision Engine — governed decision, hash-sealed [Evidence Pack™](https://kyeprotocol.com/evidence-pack/), and replay-stable identity. Zero ungoverned.

### 217

regulatory frameworks each actively emitting an Evidence Pack™ on every run, so jurisdiction coverage is executed, not asserted.

### 0

ungoverned components — a net-new ungoverned item hard-fails the build, so the score cannot silently rot.

Honest scope: these figures prove the KYE™ engine renders a governed, evidenced, replay-stable authority verdict for an action attributed to every item in KYE™'s own inventory — a real Replay-Proof™ posture KYE™ can defend, not a claim of enforcing any framework KYE™ has not mapped. Source: `scripts/smoke/governed-inventory.mjs`, verified by the `governed-inventory-coverage` gate; the day's full scan is recorded in `_diagnostics/functional-inventory.json`.

## How your entity gets scored — a living index

The Index™ launches with its methodology and its first entity, then populates as entities are assessed. It is a living index, published edition by edition through the Governed Research Rail. Every added score arrives evidence-sealed and independently replay-verifiable. Here is how your organisation joins it.

- **Regulators and auditors:** each Authority Benchmark™ metric is defined so you can reproduce it, and every published figure ships with the sealed evidence to replay it offline — turning weeks of authority reconstruction into a same-day check.
- **CISOs and risk owners:** an assessment scores your agents on False Authority Grant Rate and Delegation Drift against your sector and your regime. Board risk moves from anecdote to a defensible number you can trend quarter over quarter.
- **Builders:** bring any runtime, model or policy engine; the Index™ measures the authority above it, mapping each action to the EU AI Act, NIST AI RMF and ISO/IEC 42001 clauses that govern it.

[Request an authority assessment](https://kyeprotocol.com/poc/) [Map your chain of authority](https://kyeprotocol.com/authority-diagram/)

Canonical KYE™ surfaces referenced on this page: [Purpose Permission](https://kyeprotocol.com/glossary/) · [Self-Governance](https://kyeprotocol.com/self-governance/).
