Content type: Glossary term
190 pages. Search every page with Ctrl K, or open the menu.
Resources 190 pages
- Action ApprovalAction Approval: Pre-action human review of an agent’s proposed action.
- ActorActor: The entity actually performing an action.
- Admissibility decision valuesAdmissibility decision values: Six values. admit , reject , require_clarification , require_human_review , quarantine , route_to_authority_check .
- Adoption Evidence Pack™Adoption Evidence Pack™: Signed bundle composing intake + readiness + authority record + gates + commit boundaries + review paths + training + sample runtime…
- Agency Continuity™Agency Continuity™: The protocol-level property that an actor's interpreted goal at decision time matches its declared intent.
- Agent-as-Contracting-PartyAgent-as-Contracting-Party: The legal posture in which an AI agent's authority — the delegation it acts under, the purpose-permission it is scoped to, the…
- AI System Compliance Card™AI System Compliance Card™: The public-key-verifiable nutrition label for any AI system.
- Annex III high-risk system (EU AI Act Art 6)Annex III high-risk system (EU AI Act Art 6): (EU AI Act Art 6)
- Approval modesApproval modes: Locked set (§36 §6): none , single_approver , two_person , two_person_with_legal , delegated , auto (forbidden at high+ risk).
- Approval QueueApproval Queue: Multi-reviewer queue with pending / high-risk / escalations / second-approval-pending / SLA-breached / evidence-gap views.
- Assurance lifecycle stagesAssurance lifecycle stages: Eight stages. design , pilot , deploy , monitor , incident_review , scope_change_review , retention_review , decommission .
- AttenuationAttenuation: The rule that a child authority's scope must be a subset (⊇) of its parent's.
- Audit chainAudit chain: The append-only, hash-linked sequence of audit events the runtime emits.
- AuthorityAuthority: The protocol's noun for "what an entity is allowed to cause to happen." Authority binds a capability + scope + state to an actor + principal pair.
- Authority Continuity™Authority Continuity™: The protocol-level property that an actor's authority at decision time matches the authority granted by its delegation chain — no scope…
- Authority Drift DetectorAuthority Drift Detector: Live drift events from the kye-drift-detector Worker (ten dimensions: intent, scope, state, payload, timing, frequency, target…
- Authority Finality™ (Glossary)Authority Finality™: The protocol-level *property* that a request's KYE™ Chain of Authority™ is provably terminal — verified end-to-end with public keys alone…
- Authority Finality™ DiagnosticAuthority Finality™ Diagnostic: The free 24-question / 6-lens self-assessment that scores an organisation's agentic AI authority posture on a 0–100 scale…
- Authority Graph™Authority Graph™: The protocol's view of entities + delegations + authorities + capabilities + scopes as a typed graph.
- Authority ScopeAuthority Scope: Three-way can / cannot / needs-approval breakdown for any entity.
- BCBS 239 §6BCBS 239 §6 — Maker-checker / dual control: — Maker-checker / dual control
- Blast Radius Map™Blast Radius Map™: The view of which downstream authorities and active sessions a single revocation or quarantine signal will reach.
- CanonicalisationCanonicalisation: JCS (RFC 8785) canonical JSON form, used for hashing and signing.
- CapabilityCapability: The named verb in the action vocabulary — e.g., payment.initiate , data.read .
- CascadeCascade: The propagation pattern applied when an upstream authority is revoked or quarantined.
- Cohesion Cascade™Cohesion Cascade™: The discipline that keeps the system one coherent state.
- Conformance packConformance pack: The 133 black-box fixtures any implementation runs to demonstrate spec compliance.
- Continuity Decision Map™Continuity Decision Map™: The signed, replayable artefact bound to a single continuity decision.
- Continuity decision valuesContinuity decision values: The standard set includes continuity_preserved , continuity_degraded and continuity_broken .
- Continuity Evidence Pack™Continuity Evidence Pack™: A signed bundle composing intent + interpretation + 6-dimension state + pressure + incentive + decision + execution + drift events…
- Control mappingControl mapping: The named link from a protocol artefact to a regulatory control — e.g., evidence pack → SOC 2 CC7.2.
- Critical Point ReviewCritical Point Review: Heavy-weight review for irreversible / regulated actions.
- Critical-action catalogueCritical-action catalogue: Twenty action classes that trigger a signed, replay-proof approval flow: send_email, send_message, delete_file, export_data…
- DecisionDecision: The runtime's verdict on a single requested action.
- Decision codesDecision codes: The standard set. allow_with_constraints , require_approval , deny .
- Decision Map™Decision Map™: The signed, replayable artefact emitted with every authorise call.
- Delegated Auditability™Delegated Auditability™: Letting an auditor verify your governance without handing them access to your production systems or your customers’ data.
- DelegationDelegation: A signed grant from one entity to another.
- Discovery modesDiscovery modes: The standard set. directory_lookup , path_finder , graph_walk , risk_discovery , connector_discovery , evidence_finder .
- Discovery policyDiscovery policy: The selection rule on (role, purpose, requester-tenant, target-tenant) that determines which authority records appear in a result set and…
- DORA (Glossary)DORA: EU Digital Operational Resilience Act.
- DORA Art 28DORA Art 28 — Critical third-party: — Critical third-party
- DORA Art 6DORA Art 6 — ICT risk framework: — ICT risk framework
- Drift typesDrift types: Ten named categories.
- Ed25519Ed25519: The default signing primitive across credentials and proof bundles.
- EntityEntity: Anything the protocol can name and reason about.
- Entity Authority Record™Entity Authority Record™: Living governance record per delegated actor — owner, accountable entity, purpose, lifecycle state, risk tier, approved + prohibited…
- Entity PassportEntity Passport: At-a-glance identity for any agent / human / system / external app — verification status, authority profile, allowed capabilities, restricted…
- ePDPePDP — Edge PDP: A locally-cached, offline-capable PDP for the bank/merchant edge.
- EU AI Act (Glossary)EU AI Act: The Union's horizontal AI regulation.
- EU AI Act Art 12EU AI Act Art 12 — Record-keeping: — Record-keeping
- EU AI Act Art 13EU AI Act Art 13 — Transparency to deployer: — Transparency to deployer
- EU AI Act Art 50EU AI Act Art 50 — Interaction disclosure: — Interaction disclosure
- EU AI Act Art 9EU AI Act Art 9 — Risk management: — Risk management
- Evidence Graph™Evidence Graph™: The graph view across multiple evidence packs — how decisions, authorities.
- Evidence Pack™ (Glossary)Evidence Pack™: A signed bundle of audit-chain entries + Decision Maps™ + signatures + public-key set, replayable end-to-end with public keys alone.
- Evidence TimelineEvidence Timeline: Replay-proof chain from proposal to execute-or-block.
- FCA OpRes IBSFCA OpRes IBS — Important Business Service: — Important Business Service
- Federation trustFederation trust: The cross-trust-domain trust signal that gates whether a discovery query may traverse an edge into another tenant's authority graph.
- FINRA 4511(d)FINRA 4511(d) — Books and records: — Books and records
- GDPR Art 30GDPR Art 30 — Record of Processing Activities (RoPA): — Record of Processing Activities (RoPA)
- GDPR Art 35GDPR Art 35 — DPIA: — DPIA
- GDPR Art 44-49GDPR Art 44-49 — Cross-border transfers: — Cross-border transfers
- HAARF §4.2 verifiable-by-third-partyHAARF §4.2 verifiable-by-third-party: verifiable-by-third-party
- HAARF Risk-Reduction-per-EffortHAARF Risk-Reduction-per-Effort: HAARF v1.0 ranking heuristic for guard recommendations.
- HIPAA §164.312HIPAA §164.312 — Technical safeguards: — Technical safeguards
- Human involvement typesHuman involvement types: Six types. influence , direct , limit , approve , override , review .
- Inadmissibility classesInadmissibility classes: Fifteen classes the engine actively detects.
- ISO 27001 9.1ISO 27001 9.1 — Monitoring of operational controls: — Monitoring of operational controls
- ISO 42001 Annex A.4ISO 42001 Annex A.4 — Lifecycle: — Lifecycle
- Journey stagesJourney stages: Ten ordered stages. intake , assess , classify , map_authority , place_gates , configure_runtime , execute , evidence , review , improve .
- JSON-LD contextJSON-LD context: Recommended semantic-interoperability serialisation.
- KYAKYA — Know Your Agent: The general industry term for agent attestation.
- KYEAgencyDriftEventKYEAgencyDriftEvent: One record per detected drift, signed and hash-chained into the audit ledger.
- KYE™ Academy™KYE™ Academy™: Training and certification track for KYE™ Operating Model Profile™ owners and operators.
- KYE™ Action Admissibility Profile™KYE™ Action Admissibility Profile™: The upstream pre-action layer of KYE™.
- KYE™ Admissibility DecisionKYE™ Admissibility Decision: Signed verdict for a proposed action with checked dimensions, next-step routing, obligations and reference to the…
- KYE™ Admissibility Engine™KYE™ Admissibility Engine™: Runtime engine performing the admission check across intent, source, data, policy and rule dimensions.
- KYE™ Admissibility EvidenceKYE™ Admissibility Evidence: Hash-chained record of the inputs and signals consulted at admission time.
- KYE™ Admission Gate™KYE™ Admission Gate™: Pre-admission gate placed UPSTREAM of authority gates.
- KYE™ Agency Drift Monitor™KYE™ Agency Drift Monitor™: Drift detection + alerting surface (planned commercial layer).
- KYE™ AI Worker Readiness App™KYE™ AI Worker Readiness App™: Assess whether an AI worker is ready for pilot, controlled execution or production deployment.
- KYE™ Assurance Card Builder™KYE™ Assurance Card Builder™: Generate living assurance cards from KYE™ runtime objects.
- KYE™ Assurance Card Library™KYE™ Assurance Card Library™: Discoverable library of governed AI use cases + assurance patterns.
- KYE™ Assurance Card Profile™KYE™ Assurance Card Profile™: The lifecycle assurance layer of KYE™.
- KYE™ Assurance Card™KYE™ Assurance Card™: Living lifecycle record per delegated entity — owner, accountable entity, intended use, prohibited uses, authority model, human…
- KYE™ Assurance Review Cycle™KYE™ Assurance Review Cycle™: Scheduled + event-triggered review windows.
- KYE™ Assurance Review Scheduler™KYE™ Assurance Review Scheduler™: Scheduled + event-triggered + scope-change + incident + retention + decommissioning review cycles.
- KYE™ Authority Directory™KYE™ Authority Directory™: The directory index of cryptographically-bound authority records.
- KYE™ Authority Gates™KYE™ Authority Gates™: Runtime gate placed before high-impact delegated actions.
- KYE™ Authority Path Finder™KYE™ Authority Path Finder™: The path-resolution engine over the authority graph — given (principal, actor, capability), returns one or more delegation paths…
- KYE™ Billing Meters™KYE™ Billing Meters™: Usage metering for governed activity.
- KYE™ Certified™KYE™ Certified™: L4. Third-party-audited certification by an approved firm.
- KYE™ Chain of Authority™KYE™ Chain of Authority™: The structural artefact.
- KYE™ Cloud Gateway™KYE™ Cloud Gateway™: The optional commercial layer.
- KYE™ Cloud Portal™KYE™ Cloud Portal™: Enterprise dashboard tying use-cases, agents, gates, boundaries, decisions, evidence packs, training and certification together.
- KYE™ Commit Boundary™KYE™ Commit Boundary™: Separates recommendation from committed action.
- KYE™ Comms Engine™KYE™ Comms Engine™: The one engine every outbound message from every KYE Protocol™ surface passes through.
- KYE™ Compliance Mapping Rail™KYE™ Compliance Mapping Rail™: The runtime channel through which evidence becomes per-framework projection.
- KYE™ Conformant™KYE™ Conformant™: L3. Program-reviewed conformance report + badge + registry listing.
- KYE™ Connector Discovery Hub™KYE™ Connector Discovery Hub™: The discovery surface for Connector Profile™ implementations and their conformance state.
- KYE™ Continuity Gateway™KYE™ Continuity Gateway™: Runtime extension to the reference Gateway adding the continuity decision surface + drift-event endpoints.
- KYE™ Continuity Profile™KYE™ Continuity Profile™: The runtime profile that binds interpreted intent vs declared intent, multi-dimension authority state, pressure context, incentive…
- KYE™ Contract-to-Authority Mapper™KYE™ Contract-to-Authority Mapper™: Phase-2 — extracts permissions, obligations, prohibitions and powers from contracts, policies and mandates into KYE™ formal…
- KYE™ Control Compiler™KYE™ Control Compiler™: Compiles formal KYE™ rules into runtime PDP/PEP policies, authority gates, commit boundaries, signal events and evidence requirements.
- KYE™ Data Mapping Agent™KYE™ Data Mapping Agent™: Sub-engine of the Directory Engine.
- KYE™ Decommissioning PlanKYE™ Decommissioning Plan: Retention windows, off-boarding step sequence, cascade-revocation scope, evidence-archival policy, post-execution verification.
- KYE™ Discoverability Profile™KYE™ Discoverability Profile™: The runtime profile that turns a cryptographically-bound authority graph into a queryable surface, with role-and-purpose…
- KYE™ Discovery Console™KYE™ Discovery Console™: The operator surface over the directory + path finder + risk discovery.
- KYE™ Edge Governance™KYE™ Edge Governance™: Governance that still reaches a verdict when the network does not.
- KYE™ Evidence Finder™KYE™ Evidence Finder™: The resolver over audit-event and evidence-pack indexes.
- KYE™ ExceptionKYE™ Exception: A rule that displaces or modifies another rule under enumerated exceptional conditions (incident response, business continuity, regulatory…
- KYE™ Formal Rules Profile™KYE™ Formal Rules Profile™: The rights, obligations and governance layer of KYE™.
- KYE™ Governance RuleKYE™ Governance Rule: Meta-rule on who may override which rules, under what conditions, with what evidence.
- KYE™ Governed Entity Catalog™ entryKYE™ Governed Entity Catalog™ entry: Discovery entry per governed entity — agent, model, tool, service, connector, app, plugin, profile or certified…
- KYE™ Governed Use Case Library™KYE™ Governed Use Case Library™: Sector-curated library of governed AI use cases linking authority records, gates, commit boundaries, decisions, evidence packs…
- KYE™ GovernedUI™ (Glossary)KYE™ GovernedUI™: The human-facing control layer.
- KYE™ Human Involvement Planner™KYE™ Human Involvement Planner™: Define where authorised humans must review, approve, limit or override AI-enabled actions across the lifecycle.
- KYE™ Human Involvement Plan™KYE™ Human Involvement Plan™: Schema-bound record of points where authorised humans must influence, direct, limit, approve, override or review an AI-enabled…
- KYE™ Memory Engine™KYE™ Memory Engine™: Sub-engine of the Decision Engine.
- KYE™ Native Search Engine™KYE™ Native Search Engine™: Sub-engine of the Directory Engine.
- KYE™ ObligationKYE™ Obligation: Lifecycle object — actor MUST perform a required action by a deadline.
- KYE™ Obligation Ledger™KYE™ Obligation Ledger™: Append-only ledger tracking every obligation lifecycle, hash-chained into the audit ledger.
- KYE™ Obligation StateKYE™ Obligation State: One state-transition record on a KYEObligation .
- KYE™ Onboarding Agent™KYE™ Onboarding Agent™: The guided path from first contact to a working, governed tenant.
- KYE™ Ontology Conformance™KYE™ Ontology Conformance™: Conformance fixture suite + certification track for ontology-correct implementations.
- KYE™ ontology mappingKYE™ ontology mapping: External-system → KYE™ term mapping with mapping_type , confidence.
- KYE™ Ontology Profile™KYE™ Ontology Profile™: The semantic layer of KYE™.
- KYE™ Ontology Registry™KYE™ Ontology Registry™: Managed registry for terms, relationships, mappings and semantic assertions.
- KYE™ ontology relationshipKYE™ ontology relationship: One predicate triple (subject, predicate, object) with constraints + evidence requirements.
- KYE™ ontology termKYE™ ontology term: One canonical term in the registry.
- KYE™ Operating Model Profile™KYE™ Operating Model Profile™: The enterprise adoption layer of KYE™.
- KYE™ PermissionKYE™ Permission: Standing rule that an actor MAY perform a capability under defined scope + state.
- KYE™ PowerKYE™ Power: Authority to create, modify, revoke, waive or override a normative state.
- KYE™ Pre-Action Filter™KYE™ Pre-Action Filter™: Product-friendly synonym for the admission surface in marketing copy.
- KYE™ ProhibitionKYE™ Prohibition: Standing rule — actor MUST NOT perform the prohibited capability.
- KYE™ Proposed ActionKYE™ Proposed Action: The candidate action submitted to KYE™ Admission Gate™ for admissibility check before any authority decisioning.
- KYE™ Provenance & Supply Chain Evidence App™KYE™ Provenance & Supply Chain Evidence App™: Track datasets, models, tools, suppliers, licences and hardware lineage as runtime-bound evidence.
- KYE™ Provenance EvidenceKYE™ Provenance Evidence: Provenance + supply-chain dimension — model / dataset / tool / hardware / supplier / licence references with verification status.
- KYE™ Reconciliation Engine™KYE™ Reconciliation Engine™: The check that what you declared is what you actually deployed.
- KYE™ Reporting Engine™KYE™ Reporting Engine™: Sub-engine of the Evidence Engine.
- KYE™ Rights & Obligations Engine™KYE™ Rights & Obligations Engine™: Runtime engine that evaluates permissions, obligations, prohibitions, powers, exceptions and governance rules.
- KYE™ Rule ConflictKYE™ Rule Conflict: Detected conflict between two or more rules with the resolution strategy applied (e.g., specific overrides general, prohibition overrides…
- KYE™ Rule ProofKYE™ Rule Proof: Test result over a rule set checking enumerated consistency properties.
- KYE™ Rule Prover™KYE™ Rule Prover™: Pre-runtime consistency checker for rule sets — conflicts, unbounded obligations, missing satisfaction paths, circular delegation, override…
- KYE™ Self-Attested™KYE™ Self-Attested™: L2. Signed self-attestation (Ed25519, JWS) bundled with fixture results.
- KYE™ Self-Tested™KYE™ Self-Tested™: L1 of the conformance ladder.
- KYE™ Semantic AssertionKYE™ Semantic Assertion: A signed record bound to a runtime decision listing every term, mapping and predicate consulted.
- KYE™ Semantic Authority Mapper™KYE™ Semantic Authority Mapper™: Maps OAuth scopes, IAM roles, payment mandates, legal delegations, healthcare consents, API permissions and sector terms into…
- KYE™ Semantic Graph™KYE™ Semantic Graph™: Graph view of the ontology + live instances.
- Mapping typeMapping type: Six explicit categories.
- MCPMCP — Model Context Protocol: Tool / agent communication protocol.
- Meta-governance gateMeta-governance gate: §36 §9 (LOCKED). Self-grants ( delegate_authority or modify_own_authority where actor == grantee) are rejected at the PDP gate with…
- MHRA SaMD & AIMHRA SaMD & AI: UK Medicines and Healthcare products Regulatory Agency Software-as-a-Medical-Device regime.
- NIST 800-207NIST 800-207 — Zero Trust Architecture: — Zero Trust Architecture
- NIST AI RMF GOVERN-1.2NIST AI RMF GOVERN-1.2 — Traceability: — Traceability
- Non-goalsNon-goals: Things the protocol explicitly does NOT do — replace SCA, replace tokenisation, run fraud scoring, etc.
- Normative operatorsNormative operators: Compact operator notation.
- OAuth 2.0 / OIDCOAuth 2.0 / OIDC: Human-centric authorisation + identity federation.
- Off-boarding actionsOff-boarding actions: Eight named actions. revoke_authority , quarantine_credentials , rotate_keys , archive_evidence , notify_owner , notify_supplier…
- On-behalf-ofon-behalf-of: The relationship between actor and principal.
- Ontology domainOntology domain: One of twelve domains every KYE™ term must declare.
- OSCALOSCAL — Open Security Controls Assessment Language (NIST): (NIST)
- Payload statePayload state: The lifecycle status of a single payload.
- PCI DSS 6.4.1PCI DSS 6.4.1 — Segregated environments: — Segregated environments
- PDPPDP — Policy Decision Point: The component that evaluates the request against authorities + state + scope and returns a decision.
- PEPPEP — Policy Enforcement Point: The component that intercepts an action and asks the PDP for a decision.
- PredicatePredicate: Stable predicate dictionary.
- PrincipalPrincipal: The entity on whose behalf the actor is acting.
- ProfileProfile: One of 10 canonical conformance profiles — core , pdp , epdp , spdp , pep , runtime-authority , evidence-replay , connector , manifest , conformance .
- Proof bundleProof bundle: The transport format for an evidence pack.
- PSD3PSD3: EU revised Payment Services Directive.
- Purpose Permission™Purpose Permission™: The purpose and scope rail.
- Readiness assessmentReadiness assessment: Multi-dimension assessment plus a readiness score plus the required profiles, gates and evidence for the assessed entity.
- Reports@kyeprotocol.comreports@kyeprotocol.com: The canonical auto-delivery From-address for sealed compliance reports.
- Resilience Loop™Resilience Loop™: The evidence and replay rail.
- Review pathReview path: Multi-step human-review chain with required role, decision options, optional condition and SLA per step.
- RFCRFC: The four-stage process for landing changes.
- Risk-discovery typesRisk-discovery types: Three non-mutating traversals.
- Rule familiesRule families: Six families. permission , obligation , prohibition , power , immunity , exception .
- ScopeScope: The constraint set bounding an authority — amount cap, currency, corridor, time window, beneficiary allowlist, etc.
- SEC 17a-4(f)SEC 17a-4(f) — Records preservation: — Records preservation
- SPIFFE / SPIRESPIFFE / SPIRE: Workload identity for services.
- SR 11-7 §VSR 11-7 §V — Model risk management: — Model risk management
- SR 11-7 §VISR 11-7 §VI — Model inventory: — Model inventory
- StateState: The current lifecycle status of an entity / authority / payload — e.g., active, quarantined, suspended, revoked.
- UK NCSC CAF Principle B6UK NCSC CAF Principle B6 — Staff awareness & training: — Staff awareness & training
- Universal Engagement RailUniversal Engagement Rail: One intake surface for every external party — pilot, partner, trainer, auditor.
- URNURN: The canonical identifier format.
- Use-case intakeUse-case intake: Initial proposal for a delegated AI worker.