Interactive examples Every widget here is built from KYE™'s own scenarios and contracts: the decision feed with its chain of authority, delegation chains and Purpose Permission. Demo data: fictional organisations, people and amounts.
All Security and identity teams Risk, compliance and audit Agent and platform builders
No widget for this audience yet.
Decision feed Every agent action, decided with its chain of authority
Every agent action, decided with its chain of authority Fictional organisations, people, agents and amounts. The records follow KYE™'s published contract shapes; hashes are recomputed in your browser, signatures are not real.
For: Security and identity teams Risk, compliance and audit Agent and platform builders
Decision centre: chain of authority, admissibility, finality Computed
You learn: Who decided what, along which chain, why a request was held or denied, and that the record is final and verifiable. You can: Watch decisions arrive; approve as the delegate (the initiator cannot), verify a seal, revoke a delegation.
Replay
Approver's phone 1 Approver console 2 CISO dashboard 2 agent-decisions 1
Approver's phone Dara Quinn, head of procurement
! KYE™ policy decision point now
Procurement agent orders above its approval threshold
approval_threshold_breach
Procurement Needs approval
Details Chain of authority
Orrin Logistics (demo) Principal Dara Quinn, head of procurement kye:authority:orrin.example:procurement-head-2026 Procurement agent kye:authority:orrin.example:proc-04-2026q4
Approve Dara Quinn, head of procurement Procurement agent tries to self-approve
Approver console Dara Quinn, head of procurement
✓ KYE™ policy decision point now
Drafting agent prepares a disclosure letter, with redaction
permission_granted
Legal Allowed
Details Decision record sealed
Decision allow_with_constraints Obligations kye:obligation:redaction ff8305bc6290ca7ef2d60b6290c4c2712c62b1280faf28be46d896685fdea90e✓
✕ KYE™ policy decision point now
Credit agent acts outside its jurisdiction
jurisdiction_unsupported
Financial services Denied
Details Decision
not_revoked grant in force within_time_window 2026-10-14T09:09:20Z before 2027-01-12T00:00:00Z action_in_scope credit.line.approve in [credit.line.approve] purpose_matches lending.adjudicate = lending.adjudicate within_jurisdiction US in [GB, IE] within_constraints GBP 4,200.00 ≤ GBP 25,000.00
agent-decisions Agent platform team (demo)
✓ KYE™ policy decision point now
Accounts-payable agent pays a supplier invoice
permission_granted
Agent payments Allowed
Details Chain of authority
Brightmoor Retail (demo) Principal Ana Ruiz, finance lead kye:authority:brightmoor.example:finance-lead-2026 Accounts-payable agent kye:authority:brightmoor.example:ap-11-2026q4
CISO dashboard CISO (demo)
✕ KYE™ policy decision point now
Clinical summarisation agent asks to read records for marketing
permission_missing
Healthcare data access Denied
Details Decision
not_revoked grant in force within_time_window 2026-10-14T09:05:31Z before 2027-01-01T00:00:00Z action_in_scope record.read in [record.read, record.summarise] purpose_matches marketing.outreach ≠ clinical.summarise data_class_in_scope [health.record] in [health.record] within_jurisdiction GB in [GB]
✕ KYE™ policy decision point now
HR operations agent acts on a revoked delegation
delegation_revoked
HR Denied
Details Signal
Regional treasurer, EU Revoked Treasury agent (fx-router) Revoked by cascade
Revoke the treasurer's grant CISO (demo)
How this widget is built
Demonstrates Decision feed and approvals
Components Policy decision point (evaluate, kye_decide) Chain of authority Admissibility checks Decision records and evidence packs Revocation cascade
Flow Each decision lands on the device of whoever must know or act: approvals on the approver's phone, denials on the CISO dashboard, allows in the team channel. Tapping one opens its chain, checks, seal or cascade. Architecture diagram
Used on /examples/ : On the examples page; it plays when scrolled into view (Play/Pause)./ : The home page, right after its opening./terminal/ : The terminal: the decision centre on its devices.
Every agent action, decided with its chain of authority Fictional organisations, people, agents and amounts. The records follow KYE™'s published contract shapes; hashes are recomputed in your browser, signatures are not real.
For: Security and identity teams Risk, compliance and audit Agent and platform builders
Recent decisions Demo data
You learn: What KYE™ decides for each agent action, why (reason code), and who must act. You can: Replay the feed; approve or decline the held decision.
Replay
✓
KYE™ policy decision point → Accounts-payable agentpayments.transferAllowed
Accounts-payable agent pays a supplier invoice
permission_granted
Pay €412.90 to Paperhouse Supplies (demo), invoice INV-2026-0917
In-app Webhook
accounts_payable.settle kye_decide
!
KYE™ policy decision point → Procurement agentpurchase_order.createNeeds approval
Procurement agent orders above its approval threshold
approval_threshold_breach
Order 40 pallets of packaging film from Kilnworks Supplies (demo), £18,400
App push In-app Webhook
procurement.replenish kye_decide
✕
KYE™ policy decision point → Clinical summarisation agentrecord.readDenied
Clinical summarisation agent asks to read records for marketing
permission_missing
Read 1,200 patient records to build a marketing list (demo)
In-app Webhook
marketing.outreach kye_purpose_admit
✕
KYE™ policy decision point → HR operations agenthr.record.updateDenied
HR operations agent acts on a revoked delegation
delegation_revoked
Change a staff member's contracted hours (demo)
In-app Webhook
hr.contract.administer kye_authority_check
✓
KYE™ policy decision point → Research and drafting agentdocument.draftAllowed
Drafting agent prepares a disclosure letter, with redaction
permission_granted
Draft a disclosure letter for matter M-2207 (demo)
In-app Webhook
legal.matter_support kye_decide
✕
KYE™ policy decision point → Credit decisioning agentcredit.line.approveDenied
Credit agent acts outside its jurisdiction
jurisdiction_unsupported
Approve a £4,200 credit line for an applicant in the US (demo)
In-app Webhook
lending.adjudicate kye_decide
How this widget is built
Demonstrates Decision feed
Components Policy decision point (kye_decide) Decision records (kye.decision.record.v1) Approval routing (dual control) Evidence packs
Flow Each agent action is decided against its chain of authority; approvals go to the delegate who holds the threshold; every outcome is sealed. Architecture diagram
Used on /examples/ : On the examples page, with the rest of its scenario./developers/ : The developer portal: what every call returns./governed-ui/ : GovernedUI™: the decisions it shows./mcp/ : The MCP server: the decisions behind its tools./platform/ : The platform: decisions with their chains of authority./terminal/ : The terminal: every decision, replayable.
Procurement agent orders above its approval threshold Order 40 pallets of packaging film from Kilnworks Supplies (demo), £18,400
For: Security and identity teams Risk, compliance and audit Agent and platform builders
Chain of authority Demo data
You learn: Where this agent's authority comes from, at which hop it holds or stops, and what is sealed. You can: Walk the chain hop by hop.
Walk the chain
1
Orrin Logistics (demo)
Principal
2
Dara Quinn, head of procurement
Delegate
kye:authority:orrin.example:procurement-head-2026
procurement.replenish
3
Procurement agent
Agent
kye:authority:orrin.example:proc-04-2026q4
procurement.replenish
4
Procurement agent
Requested action
Order 40 pallets of packaging film from Kilnworks Supplies (demo), £18,400
5
KYE™ policy decision point Needs approval
Decision
approval_threshold_breach
Require approval
6
KYE™ policy decision point
Decision record and evidence pack sealed
kye.decision.record.v1
Decision map hash recomputed in your browser: it matches the sealed record.
Expected outcome Decision Require approval
How this widget is built
Demonstrates Decision feed
Components Principal Delegated grant (actions, purpose, limit, jurisdiction, expiry) Agent grant Policy decision point (kye_decide) Decision record and evidence pack
Flow Principal → delegation → agent → action → allow / deny / approval → sealed decision record and evidence pack. Architecture diagram
Used on /examples/ : On the examples page, with the rest of its scenario.
Clinical summarisation agent asks to read records for marketing Read 1,200 patient records to build a marketing list (demo)
For: Security and identity teams Risk, compliance and audit Agent and platform builders
Chain of authority Demo data
You learn: Where this agent's authority comes from, at which hop it holds or stops, and what is sealed. You can: Walk the chain hop by hop.
Walk the chain
1
Halden Health (demo)
Principal
2
Dr Mira Okoye, clinical lead
Delegate
kye:authority:halden.example:clinical-lead-2026
clinical.summarise
3
Clinical summarisation agent
Agent
kye:authority:halden.example:clin-03-2026q4
clinical.summarise
4
Clinical summarisation agent
Requested action
Read 1,200 patient records to build a marketing list (demo)
5
KYE™ policy decision point Denied
Decision
6
KYE™ policy decision point
Decision record and evidence pack sealed
kye.decision.record.v1
Decision map hash recomputed in your browser: it matches the sealed record.
How this widget is built
Demonstrates Decision feed
Components Principal Delegated grant (actions, purpose, limit, jurisdiction, expiry) Agent grant Policy decision point (kye_decide) Decision record and evidence pack
Flow Principal → delegation → agent → action → allow / deny / approval → sealed decision record and evidence pack. Architecture diagram
Used on /examples/ : On the examples page, with the rest of its scenario.
Delegation chain Each hop can only narrow the authority it received: fewer actions, a lower limit, fewer jurisdictions, an earlier expiry.
Chain builder Each hop can only narrow the authority it received: fewer actions, a lower limit, fewer jurisdictions, an earlier expiry.
For: Security and identity teams Agent and platform builders
Build it, try to widen it, revoke it Demo data
You learn: Why authority can only narrow down a chain, and what a revocation does downstream. You can: Step through delegating, widening and revoking.
Step 1 of 5
Marlow Energy (demo) → Group CFO
Delegate the next hop
kye:authority:marlow.example:cfo-2026
Step 2 of 5
Group CFO → Regional treasurer, EU
Delegate the next hop
kye:authority:marlow.example:treasurer-eu-2026
narrower than its parent
Step 3 of 5
Regional treasurer, EU → Treasury agent (fx-router)
Delegate the next hop
kye:authority:marlow.example:fx-router-2026q4
Chain complete
Step 4 of 5
Treasury agent (fx-router) Denied
Try to widen the agent's grant
graph_delegation_path_disputed
Rejected: the child grant would be wider than its parent
Step 5 of 5
Group CFO → Regional treasurer, EU
Revoke the treasurer's grant
kye:cascade:marlow.example:01JZC7RV2K
Revoked by cascade
Back Next Start again
How this widget is built
Demonstrates Delegation chains
Components Authority grants (kye.authority.grant.v1) Narrowing rule Revocation cascade (kye.signal.revocation.cascaded.v1)
Flow Each hop narrows the authority it received; a wider child grant is rejected; revoking a hop cascades to every hop below it. Architecture diagram
Used on /examples/ : On the examples page, with the rest of its scenario.
Who holds which grant Demo data
You learn: What each hop is allowed to do. You can: Switch between the hops.
Marlow Energy (demo) Group CFO Regional treasurer, EU Treasury agent (fx-router)
Marlow Energy (demo)
Does
Marlow Energy (demo) → Group CFO: Delegate the next hop
Group CFO
Does
Delegate the next hop Revoke the treasurer's grant
Marlow Energy (demo) → Group CFO: Delegate the next hop
Group CFO → Regional treasurer, EU: Delegate the next hop
Group CFO → Regional treasurer, EU: Revoke the treasurer's grant
Regional treasurer, EU
Does
Group CFO → Regional treasurer, EU: Delegate the next hop
Regional treasurer, EU → Treasury agent (fx-router): Delegate the next hop
Group CFO → Regional treasurer, EU: Revoke the treasurer's grant
Treasury agent (fx-router)
Does
Try to widen the agent's grant
Regional treasurer, EU → Treasury agent (fx-router): Delegate the next hop
How this widget is built
Demonstrates Delegation chains
Components Principal Group CFO Regional treasurer Treasury agent
Flow Each hop holds its own grant, narrower than its parent. Architecture diagram
Used on /examples/ : On the examples page, with the rest of its scenario.
Purpose Permission™ lifecycle Issue, admit, reconfirm, revoke
Purpose grant Summarise care records for the treating clinician
For: Risk, compliance and audit Agent and platform builders
Purpose Permission™ lifecycle Demo data
You learn: How a purpose-bound grant is issued, used, renewed and revoked. You can: Run the lifecycle.
Run
Issue the grant
Clinical lead
Summarise care records for the treating clinician
Ask to summarise a record
Clinical summarisation agent
Admitted: every check passed
Reconfirm for 90 days
Clinical lead
Revoke the grant
Clinical lead
grant revoked by the clinical lead
Ask to summarise a record
KYE™ policy decision point
Not admitted: not_revoked failed
How this widget is built
Demonstrates Purpose Permission
Components Purpose grant Admissibility (kye_purpose_admit) Reconfirm / revoke
Flow Issue, admit, reconfirm, revoke; after revocation the same request is not admitted. Architecture diagram
Used on /examples/ : On the examples page, with the rest of its scenario.
Purpose Permission API Demo data
You learn: What the purpose-permission endpoints take and return. You can: Pick a request and send it.
POST Issue the grantPATCH Reconfirm for 90 daysDELETE Revoke the grant
Clinical lead · Issue the grant
Request POST /purpose-permissions
{
"grantee": "<grantee>",
"purpose": "<purpose>",
"scope": "<scope>",
"ttl_days": 90
}
Send request
Response 201 {
"grantee": "kye:ent:halden.example:agent:clin-03",
"id": "kye:purpose:halden:clin-03:clinical-summarise-2026q4",
"issued_by": "kye:ent:halden.example:officer:clinical-lead",
"not_after": "2027-01-01T00:00:00Z",
"not_before": "2026-10-01T00:00:00Z",
"principal": "kye:ent:halden.example",
"purpose": {
"id": "kye:purpose-class:clinical.summarise",
"label": "Summarise care records for the treating clinician"
},
"restrictions": {
"dual_control": false,
"jurisdiction": [
"GB"
],
"rate_cap": {
"requests_per_minute": 20
},
"requires_evidence": true
},
"scope": {
"actions": [
"read",
"summarise"
],
"data_classes": [
"health.record"
],
"resources": [
"kye:res:halden.example:ehr:ward-7"
]
},
"version": 1
}
Clinical lead · Reconfirm for 90 days
Request PATCH /purpose-permissions/%3Cid%3E
{
"ttl_days": 90
}
Send request
Response 200 {
"id": "kye:purpose:halden:clin-03:clinical-summarise-2026q4",
"not_after": "2027-04-01T00:00:00Z",
"reconfirmed_at": "2026-10-14T10:20:00Z"
}
Clinical lead · Revoke the grant
Request DELETE /purpose-permissions/%3Cid%3E
Send request
Response 200 {
"id": "kye:purpose:halden:clin-03:clinical-summarise-2026q4",
"revoked_at": "2026-10-14T10:25:00Z",
"revoked_reason": "Clinical lead revoked the grant (demo)"
}
How this widget is built
Demonstrates App API
Components /api/v1/purpose-permissions OpenAPI contract (app.yaml)
Flow Requests come from the app API contract; the issue response is the demo grant. Architecture diagram
Used on /examples/ : On the examples page, with the rest of its scenario./sandbox/demos/demo/ : The sandbox demo: the same calls, answered from the contract./lab/ : The lab: call the API in your browser.
Admissibility checks (kye.purpose.admissibility.v1) Admitted: every check passed
For: Risk, compliance and audit
You learn: Exactly which checks admit a purpose request. You can: Run the checks.
Run
principal_matches
KYE™ policy decision point
grant principal = halden.example
grantee_matches
KYE™ policy decision point
request.actor = grant.grantee (clin-03)
purpose_matches
KYE™ policy decision point
clinical.summarise
action_in_scope
KYE™ policy decision point
summarise in [read, summarise]
resource_in_scope
KYE™ policy decision point
patient-0412 under ward-7
data_class_in_scope
KYE™ policy decision point
health.record in [health.record]
within_time_window
KYE™ policy decision point
inside [2026-10-01, 2027-01-01)
within_jurisdiction
KYE™ policy decision point
GB in [GB]
within_rate_cap
KYE™ policy decision point
6 of 20 requests a minute
not_revoked
KYE™ policy decision point
grant.revoked_at = null
signature_valid
KYE™ policy decision point
signature verified against the clinical lead's key
dual_control_satisfied
KYE™ policy decision point
dual_control = false
How this widget is built
Demonstrates Purpose Permission
Components kye.purpose.admissibility.v1 12 checks
Flow Every admissibility check runs in order; any failure refuses the request. Architecture diagram
Used on /examples/ : On the examples page, with the rest of its scenario.
Authority tour An agent asks, people approve, a revocation denies: every outcome decided by KYE™'s own engine and sealed.
Authority tour: decide, approve two of two, revoke and verify Fictional organisations, people, agents and amounts. The records follow KYE™'s published contract shapes; hashes are recomputed in your browser, signatures are not real.
For: Security and identity teams Risk, compliance and audit Agent and platform builders
You learn: How KYE™ decides, who must approve, why the initiator cannot, and what a revocation does, each step verifiable. You can: Walk the three tasks, jump to any step by link, and open the sandbox at the end.
Decision feed Every agent action, decided with its chain of authority 0 of 2 Agent asks, two people approve Two of two approvers; the initiator can never approve. 0 of 7 Revoke, deny, verify A revoked delegation denies the same request; both packs verify offline. 0 of 3
Decision feed
Step 1 of 2
KYE™ policy decision point
Every agent action, decided with its chain of authority
Recent decisions
Step 2 of 2
Recent decisions Dara Quinn, head of procurement
Approval Procurement agent orders above its approval threshold
Procurement Require approval
KYE™ policy decision point Procurement Needs approval
Procurement agent orders above its approval threshold
Order 40 pallets of packaging film from Kilnworks Supplies (demo), £18,400
Agent asks, two people approve
Step 1 of 7
Procurement agent → KYE™ policy decision point
Requested action
Order 40 pallets of packaging film from Kilnworks Supplies (demo), £18,400
procurement.replenish kye_decide
Step 2 of 7
Chain of authority Dara Quinn, head of procurement
Principal Orrin Logistics (demo)
Delegate Dara Quinn, head of procurement
Agent Procurement agent
KYE™ policy decision point
Chain of authority
kye:authority:orrin.example:proc-04-2026q4
procurement.replenish
Step 3 of 7
KYE™ policy decision point Needs approval
Decision
approval_threshold_breach
require_approval
Step 4 of 7
Approval request Finance controller (demo), second approver
Quorum 2 of 2 (two_person)
Agent Cannot approve
Requested action Order 40 pallets of packaging film from Kilnworks Supplies (demo), £18,400
Approve
On the approver's device Procurement agent Denied
The initiator tries to approve its own request
Refused: the initiator can never approve (maker is not checker)
Step 5 of 7
Approval request Finance controller (demo), second approver
Quorum 2 of 2 (two_person)
Agent Cannot approve
Requested action Order 40 pallets of packaging film from Kilnworks Supplies (demo), £18,400
Approve
On the approver's device Dara Quinn, head of procurement 1 of 2
Approve
two_person
Step 6 of 7
Approval request Finance controller (demo), second approver
Quorum 2 of 2 (two_person)
Agent Cannot approve
Requested action Order 40 pallets of packaging film from Kilnworks Supplies (demo), £18,400
Approve
On the approver's device Finance controller (demo), second approver 2 of 2 Allowed
Approve
override_approved
allow_with_constraints
kye:obligation:dual-control
Step 7 of 7
Evidence pack Offline verifier (public keys only)
Seal kye.decision.record.v1
Verify Decision map hash recomputed in your browser: it matches the sealed record.
Sealed KYE™ policy decision point
Decision record and evidence pack sealed
kye.decision.record.v1
Decision map hash recomputed in your browser: it matches the sealed record.
Revoke, deny, verify
Step 1 of 3
Orrin Logistics (demo) → Dara Quinn, head of procurement
Revoke the delegation
kye:authority:orrin.example:procurement-head-2026
Step 2 of 3
KYE™ policy decision point Denied
Replay
delegation_revoked
deny
Step 3 of 3
Evidence pack Offline verifier (public keys only)
Seal kye.decision.record.v1
Verify Decision map hash recomputed in your browser: it matches the sealed record.
Details Offline verifier (public keys only)
Verify
Decision map hash recomputed in your browser: it matches the sealed record.
Try it on your own request The playground runs the same three-outcome engine and returns a sealed evidence pack you can verify offline.
Open the sandbox
Back 1 of 2 Next
How this widget is built
Demonstrates Decision feed, approvals and evidence packs
Components Policy decision point (evaluate, kye_decide) Delegation grants and quorum (two_person) Decision records and evidence packs Offline verifier
Flow Feed → agent request → chain of authority → require approval → 2 of 2 approvals (never the initiator) → sealed pack → revoke → deny → verify offline. Architecture diagram
Used on /examples/ : On the examples page; deep links ?task=quorum&step=4 jump to any step./demos/ : The demos page: the guided tour runs in place./tour/ : The authority tour page.