For a CISO
— when an agent does something it should not have, you replay the Authority Timeline™ and see the exact failed control, not a guess. Authority Finality™ lets you revoke mid-flight, and the revocation is itself an event.
Most systems store authority as current state — a row you can overwrite and never explain. Authority Sourcing™ stores it the way ledgers store money: as an append-only log of events. Every grant, delegation, revocation and decision is a sealed event, so an entity's authority at any instant is a fold over that log — and you can replay the exact decision on an Authority Timeline™ and walk the Authority Graph™ behind it.
If you have built an event-sourced system, you already understand Authority Sourcing™ — KYE Protocol™ applies the same discipline to the one piece of state a regulator asks about, and emits it as a fixed family of 7 signed JSON schemas that map to the EU AI Act™ Article 12 logging duty, NIST AI RMF and ISO/IEC 42001™.
This is not a new engine. Authority Sourcing™ is the name for what KYE Protocol™ already does — the Evidence Pack™ chain, write-once audit retention, and replay verification — framed as the event-sourcing pattern teams already know.
When an action is questioned, you do not reconstruct intent from logs and memory — you open the action's timeline and read the sealed events in order. Worked example: a treasury agent proposes a supplier payment.
The Authority Timeline™ is a projection of the locked Evidence Timeline contract (the operator widget defined in the KYE™ GovernedUI™ rail). The schema names are the canonical event family every consequential action emits.
A timeline answers what happened, in order. The Authority Graph™ answers on whose authority — it is the typed graph of principals, delegations, scopes and decisions that the Decision Engine™ walks to admit or block each action.
The same decision, as a graph. Authority Sourcing™ keeps the timeline and the graph in lock-step: every edge here is backed by an event on the timeline above, and every event resolves to nodes on this graph.
One log, three audiences — because event-sourced authority serves the question each of them actually asks.
— when an agent does something it should not have, you replay the Authority Timeline™ and see the exact failed control, not a guess. Authority Finality™ lets you revoke mid-flight, and the revocation is itself an event.
— the EU AI Act™ Article 12 logging duty and NIST AI RMF’s govern function bind per action; a folded, Replay-Proof™ log discharges them as evidence, mapped across frameworks including ISO/IEC 42001™. 249
— you emit the event family from your runtime and get the timeline, the graph and the proofs for free. KYE Protocol™ sits above whatever agent runtime you choose; it does not replace it.
— because authority is derived from the log, “what could this agent do last March?” is a query, not an archaeology project.
Canonical KYE™ surfaces referenced on this page: Authority Graph™ · KYE™ GovernedUI · KYE Protocol™.