Interactive examples

Every widget here is built from KYE™'s own scenarios and contracts: the decision feed with its chain of authority, delegation chains and Purpose Permission. Demo data: fictional organisations, people and amounts.

Decision feed

Every agent action, decided with its chain of authority

Every agent action, decided with its chain of authority

Fictional organisations, people, agents and amounts. The records follow KYE™'s published contract shapes; hashes are recomputed in your browser, signatures are not real.

For: Security and identity teams Risk, compliance and audit Agent and platform builders

Decision centre: chain of authority, admissibility, finality

Computed

You learn: Who decided what, along which chain, why a request was held or denied, and that the record is final and verifiable. You can: Watch decisions arrive; approve as the delegate (the initiator cannot), verify a seal, revoke a delegation.

Approver's phoneDara Quinn, head of procurement
  1. KYE™ policy decision point

    Procurement agent orders above its approval threshold

    approval_threshold_breach

    ProcurementNeeds approval

    Chain of authority

    1. Orrin Logistics (demo) Principal
    2. Dara Quinn, head of procurement kye:authority:orrin.example:procurement-head-2026
    3. Procurement agent kye:authority:orrin.example:proc-04-2026q4
Approver consoleDara Quinn, head of procurement
  1. KYE™ policy decision point

    Drafting agent prepares a disclosure letter, with redaction

    permission_granted

    LegalAllowed

    Decision record sealed

    1. Decision allow_with_constraints
    2. Obligations kye:obligation:redaction

    ff8305bc6290ca7ef2d60b6290c4c2712c62b1280faf28be46d896685fdea90e

  2. KYE™ policy decision point

    Credit agent acts outside its jurisdiction

    jurisdiction_unsupported

    Financial servicesDenied

    Decision

    1. not_revoked grant in force
    2. within_time_window 2026-10-14T09:09:20Z before 2027-01-12T00:00:00Z
    3. action_in_scope credit.line.approve in [credit.line.approve]
    4. purpose_matches lending.adjudicate = lending.adjudicate
    5. within_jurisdiction US in [GB, IE]
    6. within_constraints GBP 4,200.00 ≤ GBP 25,000.00
agent-decisionsAgent platform team (demo)
  1. KYE™ policy decision point

    Accounts-payable agent pays a supplier invoice

    permission_granted

    Agent paymentsAllowed

    Chain of authority

    1. Brightmoor Retail (demo) Principal
    2. Ana Ruiz, finance lead kye:authority:brightmoor.example:finance-lead-2026
    3. Accounts-payable agent kye:authority:brightmoor.example:ap-11-2026q4
CISO dashboardCISO (demo)
  1. KYE™ policy decision point

    Clinical summarisation agent asks to read records for marketing

    permission_missing

    Healthcare data accessDenied

    Decision

    1. not_revoked grant in force
    2. within_time_window 2026-10-14T09:05:31Z before 2027-01-01T00:00:00Z
    3. action_in_scope record.read in [record.read, record.summarise]
    4. purpose_matches marketing.outreach ≠ clinical.summarise
    5. data_class_in_scope [health.record] in [health.record]
    6. within_jurisdiction GB in [GB]
  2. KYE™ policy decision point

    HR operations agent acts on a revoked delegation

    delegation_revoked

    HRDenied

    Signal

    1. Regional treasurer, EU Revoked
    2. Treasury agent (fx-router) Revoked by cascade
How this widget is built
Demonstrates
Decision feed and approvals
Components
  • Policy decision point (evaluate, kye_decide)
  • Chain of authority
  • Admissibility checks
  • Decision records and evidence packs
  • Revocation cascade
Flow
Each decision lands on the device of whoever must know or act: approvals on the approver's phone, denials on the CISO dashboard, allows in the team channel. Tapping one opens its chain, checks, seal or cascade. Architecture diagram
Used on
  • /examples/: On the examples page; it plays when scrolled into view (Play/Pause).
  • /: The home page, right after its opening.
  • /terminal/: The terminal: the decision centre on its devices.

Every agent action, decided with its chain of authority

Fictional organisations, people, agents and amounts. The records follow KYE™'s published contract shapes; hashes are recomputed in your browser, signatures are not real.

For: Security and identity teams Risk, compliance and audit Agent and platform builders

Recent decisions

Demo data

You learn: What KYE™ decides for each agent action, why (reason code), and who must act. You can: Replay the feed; approve or decline the held decision.

  1. KYE™ policy decision point Accounts-payable agentpayments.transferAllowed

    Accounts-payable agent pays a supplier invoice

    permission_granted

    Pay €412.90 to Paperhouse Supplies (demo), invoice INV-2026-0917

    In-appWebhook

    • accounts_payable.settle
    • kye_decide
  2. KYE™ policy decision point Procurement agentpurchase_order.createNeeds approval

    Procurement agent orders above its approval threshold

    approval_threshold_breach

    Order 40 pallets of packaging film from Kilnworks Supplies (demo), £18,400

    App pushIn-appWebhook

    • procurement.replenish
    • kye_decide
  3. KYE™ policy decision point Clinical summarisation agentrecord.readDenied

    Clinical summarisation agent asks to read records for marketing

    permission_missing

    Read 1,200 patient records to build a marketing list (demo)

    In-appWebhook

    • marketing.outreach
    • kye_purpose_admit
  4. KYE™ policy decision point HR operations agenthr.record.updateDenied

    HR operations agent acts on a revoked delegation

    delegation_revoked

    Change a staff member's contracted hours (demo)

    In-appWebhook

    • hr.contract.administer
    • kye_authority_check
  5. KYE™ policy decision point Research and drafting agentdocument.draftAllowed

    Drafting agent prepares a disclosure letter, with redaction

    permission_granted

    Draft a disclosure letter for matter M-2207 (demo)

    In-appWebhook

    • legal.matter_support
    • kye_decide
  6. KYE™ policy decision point Credit decisioning agentcredit.line.approveDenied

    Credit agent acts outside its jurisdiction

    jurisdiction_unsupported

    Approve a £4,200 credit line for an applicant in the US (demo)

    In-appWebhook

    • lending.adjudicate
    • kye_decide
How this widget is built
Demonstrates
Decision feed
Components
  • Policy decision point (kye_decide)
  • Decision records (kye.decision.record.v1)
  • Approval routing (dual control)
  • Evidence packs
Flow
Each agent action is decided against its chain of authority; approvals go to the delegate who holds the threshold; every outcome is sealed. Architecture diagram
Used on
  • /examples/: On the examples page, with the rest of its scenario.
  • /developers/: The developer portal: what every call returns.
  • /governed-ui/: GovernedUI™: the decisions it shows.
  • /mcp/: The MCP server: the decisions behind its tools.
  • /platform/: The platform: decisions with their chains of authority.
  • /terminal/: The terminal: every decision, replayable.

Procurement agent orders above its approval threshold

Order 40 pallets of packaging film from Kilnworks Supplies (demo), £18,400

For: Security and identity teams Risk, compliance and audit Agent and platform builders

Chain of authority

Demo data

You learn: Where this agent's authority comes from, at which hop it holds or stops, and what is sealed. You can: Walk the chain hop by hop.

Expected outcome
  • Decision Require approval
How this widget is built
Demonstrates
Decision feed
Components
  • Principal
  • Delegated grant (actions, purpose, limit, jurisdiction, expiry)
  • Agent grant
  • Policy decision point (kye_decide)
  • Decision record and evidence pack
Flow
Principal → delegation → agent → action → allow / deny / approval → sealed decision record and evidence pack. Architecture diagram
Used on
  • /examples/: On the examples page, with the rest of its scenario.

Clinical summarisation agent asks to read records for marketing

Read 1,200 patient records to build a marketing list (demo)

For: Security and identity teams Risk, compliance and audit Agent and platform builders

Chain of authority

Demo data

You learn: Where this agent's authority comes from, at which hop it holds or stops, and what is sealed. You can: Walk the chain hop by hop.

Expected outcome
  • Decision Deny
How this widget is built
Demonstrates
Decision feed
Components
  • Principal
  • Delegated grant (actions, purpose, limit, jurisdiction, expiry)
  • Agent grant
  • Policy decision point (kye_decide)
  • Decision record and evidence pack
Flow
Principal → delegation → agent → action → allow / deny / approval → sealed decision record and evidence pack. Architecture diagram
Used on
  • /examples/: On the examples page, with the rest of its scenario.

Delegation chain

Each hop can only narrow the authority it received: fewer actions, a lower limit, fewer jurisdictions, an earlier expiry.

Chain builder

Each hop can only narrow the authority it received: fewer actions, a lower limit, fewer jurisdictions, an earlier expiry.

For: Security and identity teams Agent and platform builders

Build it, try to widen it, revoke it

Demo data

You learn: Why authority can only narrow down a chain, and what a revocation does downstream. You can: Step through delegating, widening and revoking.

  1. Step 1 of 5

    Marlow Energy (demo) Group CFO

    Delegate the next hop

    kye:authority:marlow.example:cfo-2026

  2. Step 2 of 5

    Group CFO Regional treasurer, EU

    Delegate the next hop

    kye:authority:marlow.example:treasurer-eu-2026

    narrower than its parent

  3. Step 3 of 5

    Regional treasurer, EU Treasury agent (fx-router)

    Delegate the next hop

    kye:authority:marlow.example:fx-router-2026q4

    Chain complete

  4. Step 4 of 5

    Treasury agent (fx-router)Denied

    Try to widen the agent's grant

    graph_delegation_path_disputed

    Rejected: the child grant would be wider than its parent

  5. Step 5 of 5

    Group CFO Regional treasurer, EU

    Revoke the treasurer's grant

    kye:cascade:marlow.example:01JZC7RV2K

    Revoked by cascade

How this widget is built
Demonstrates
Delegation chains
Components
  • Authority grants (kye.authority.grant.v1)
  • Narrowing rule
  • Revocation cascade (kye.signal.revocation.cascaded.v1)
Flow
Each hop narrows the authority it received; a wider child grant is rejected; revoking a hop cascades to every hop below it. Architecture diagram
Used on
  • /examples/: On the examples page, with the rest of its scenario.

Who holds which grant

Demo data

You learn: What each hop is allowed to do. You can: Switch between the hops.

Marlow Energy (demo)

Does

  • Delegate the next hop
Group CFO

Does

  • Delegate the next hop
  • Revoke the treasurer's grant
Regional treasurer, EU

Does

  • Delegate the next hop
Treasury agent (fx-router)

Does

  • Try to widen the agent's grant
How this widget is built
Demonstrates
Delegation chains
Components
  • Principal
  • Group CFO
  • Regional treasurer
  • Treasury agent
Flow
Each hop holds its own grant, narrower than its parent. Architecture diagram
Used on
  • /examples/: On the examples page, with the rest of its scenario.

Purpose Permission™ lifecycle

Issue, admit, reconfirm, revoke

Purpose grant

Summarise care records for the treating clinician

For: Risk, compliance and audit Agent and platform builders

Purpose Permission™ lifecycle

Demo data

You learn: How a purpose-bound grant is issued, used, renewed and revoked. You can: Run the lifecycle.

  1. Issue the grant

    Clinical lead

    Summarise care records for the treating clinician

  2. Ask to summarise a record

    Clinical summarisation agent

    Admitted: every check passed

  3. Reconfirm for 90 days

    Clinical lead

  4. Revoke the grant

    Clinical lead

    grant revoked by the clinical lead

  5. Ask to summarise a record

    KYE™ policy decision point

    Not admitted: not_revoked failed

How this widget is built
Demonstrates
Purpose Permission
Components
  • Purpose grant
  • Admissibility (kye_purpose_admit)
  • Reconfirm / revoke
Flow
Issue, admit, reconfirm, revoke; after revocation the same request is not admitted. Architecture diagram
Used on
  • /examples/: On the examples page, with the rest of its scenario.

Purpose Permission API

Demo data

You learn: What the purpose-permission endpoints take and return. You can: Pick a request and send it.

Clinical lead · Issue the grant

Request
POST /purpose-permissions

{
  "grantee": "<grantee>",
  "purpose": "<purpose>",
  "scope": "<scope>",
  "ttl_days": 90
}
Response 201
{
  "grantee": "kye:ent:halden.example:agent:clin-03",
  "id": "kye:purpose:halden:clin-03:clinical-summarise-2026q4",
  "issued_by": "kye:ent:halden.example:officer:clinical-lead",
  "not_after": "2027-01-01T00:00:00Z",
  "not_before": "2026-10-01T00:00:00Z",
  "principal": "kye:ent:halden.example",
  "purpose": {
    "id": "kye:purpose-class:clinical.summarise",
    "label": "Summarise care records for the treating clinician"
  },
  "restrictions": {
    "dual_control": false,
    "jurisdiction": [
      "GB"
    ],
    "rate_cap": {
      "requests_per_minute": 20
    },
    "requires_evidence": true
  },
  "scope": {
    "actions": [
      "read",
      "summarise"
    ],
    "data_classes": [
      "health.record"
    ],
    "resources": [
      "kye:res:halden.example:ehr:ward-7"
    ]
  },
  "version": 1
}
How this widget is built
Demonstrates
App API
Components
  • /api/v1/purpose-permissions
  • OpenAPI contract (app.yaml)
Flow
Requests come from the app API contract; the issue response is the demo grant. Architecture diagram
Used on
  • /examples/: On the examples page, with the rest of its scenario.
  • /sandbox/demos/demo/: The sandbox demo: the same calls, answered from the contract.
  • /lab/: The lab: call the API in your browser.

Admissibility checks (kye.purpose.admissibility.v1)

Admitted: every check passed

For: Risk, compliance and audit

Pipeline

Demo data

You learn: Exactly which checks admit a purpose request. You can: Run the checks.

  1. principal_matches

    KYE™ policy decision point

    grant principal = halden.example

  2. grantee_matches

    KYE™ policy decision point

    request.actor = grant.grantee (clin-03)

  3. purpose_matches

    KYE™ policy decision point

    clinical.summarise

  4. action_in_scope

    KYE™ policy decision point

    summarise in [read, summarise]

  5. resource_in_scope

    KYE™ policy decision point

    patient-0412 under ward-7

  6. data_class_in_scope

    KYE™ policy decision point

    health.record in [health.record]

  7. within_time_window

    KYE™ policy decision point

    inside [2026-10-01, 2027-01-01)

  8. within_jurisdiction

    KYE™ policy decision point

    GB in [GB]

  9. within_rate_cap

    KYE™ policy decision point

    6 of 20 requests a minute

  10. not_revoked

    KYE™ policy decision point

    grant.revoked_at = null

  11. signature_valid

    KYE™ policy decision point

    signature verified against the clinical lead's key

  12. dual_control_satisfied

    KYE™ policy decision point

    dual_control = false

How this widget is built
Demonstrates
Purpose Permission
Components
  • kye.purpose.admissibility.v1
  • 12 checks
Flow
Every admissibility check runs in order; any failure refuses the request. Architecture diagram
Used on
  • /examples/: On the examples page, with the rest of its scenario.

Authority tour

An agent asks, people approve, a revocation denies: every outcome decided by KYE™'s own engine and sealed.

Authority tour: decide, approve two of two, revoke and verify

Fictional organisations, people, agents and amounts. The records follow KYE™'s published contract shapes; hashes are recomputed in your browser, signatures are not real.

For: Security and identity teams Risk, compliance and audit Agent and platform builders

Authority tour

Computed

You learn: How KYE™ decides, who must approve, why the initiator cannot, and what a revocation does, each step verifiable. You can: Walk the three tasks, jump to any step by link, and open the sandbox at the end.

Decision feed
  1. Step 1 of 2

    KYE™ policy decision point

    Every agent action, decided with its chain of authority

    Recent decisions

  2. Step 2 of 2

    Recent decisionsDara Quinn, head of procurement

    ApprovalProcurement agent orders above its approval threshold

    Procurement
    Require approval

    KYE™ policy decision point ProcurementNeeds approval

    Procurement agent orders above its approval threshold

    Order 40 pallets of packaging film from Kilnworks Supplies (demo), £18,400

Agent asks, two people approve
  1. Step 1 of 7

    Procurement agent KYE™ policy decision point

    Requested action

    Order 40 pallets of packaging film from Kilnworks Supplies (demo), £18,400

    • procurement.replenish
    • kye_decide
  2. Step 2 of 7

    Chain of authorityDara Quinn, head of procurement
    Principal
    Orrin Logistics (demo)
    Delegate
    Dara Quinn, head of procurement
    Agent
    Procurement agent

    KYE™ policy decision point

    Chain of authority

    kye:authority:orrin.example:proc-04-2026q4

    procurement.replenish

  3. Step 3 of 7

    KYE™ policy decision pointNeeds approval

    Decision

    approval_threshold_breach

    require_approval

  4. Step 4 of 7

    Approval requestFinance controller (demo), second approver
    Quorum
    2 of 2 (two_person)
    Agent
    Cannot approve
    Requested action
    Order 40 pallets of packaging film from Kilnworks Supplies (demo), £18,400
    Approve
    On the approver's device

    Procurement agentDenied

    The initiator tries to approve its own request

    Refused: the initiator can never approve (maker is not checker)

  5. Step 5 of 7

    Approval requestFinance controller (demo), second approver
    Quorum
    2 of 2 (two_person)
    Agent
    Cannot approve
    Requested action
    Order 40 pallets of packaging film from Kilnworks Supplies (demo), £18,400
    Approve
    On the approver's device

    Dara Quinn, head of procurement 1 of 2

    Approve

    two_person

  6. Step 6 of 7

    Approval requestFinance controller (demo), second approver
    Quorum
    2 of 2 (two_person)
    Agent
    Cannot approve
    Requested action
    Order 40 pallets of packaging film from Kilnworks Supplies (demo), £18,400
    Approve
    On the approver's device

    Finance controller (demo), second approver 2 of 2Allowed

    Approve

    override_approved

    allow_with_constraints

    • kye:obligation:dual-control
  7. Step 7 of 7

    Evidence packOffline verifier (public keys only)
    Seal
    kye.decision.record.v1
    Verify
    Decision map hash recomputed in your browser: it matches the sealed record.
    Sealed

    KYE™ policy decision point

    Decision record and evidence pack sealed

    kye.decision.record.v1

    Decision map hash recomputed in your browser: it matches the sealed record.

Revoke, deny, verify
  1. Step 1 of 3

    Orrin Logistics (demo) Dara Quinn, head of procurement

    Revoke the delegation

    kye:authority:orrin.example:procurement-head-2026

  2. Step 2 of 3

    KYE™ policy decision pointDenied

    Replay

    delegation_revoked

    deny

  3. Step 3 of 3

    Evidence packOffline verifier (public keys only)
    Seal
    kye.decision.record.v1
    Verify
    Decision map hash recomputed in your browser: it matches the sealed record.
    Details

    Offline verifier (public keys only)

    Verify

    Decision map hash recomputed in your browser: it matches the sealed record.

Try it on your own request

The playground runs the same three-outcome engine and returns a sealed evidence pack you can verify offline.

Open the sandbox
1 of 2
How this widget is built
Demonstrates
Decision feed, approvals and evidence packs
Components
  • Policy decision point (evaluate, kye_decide)
  • Delegation grants and quorum (two_person)
  • Decision records and evidence packs
  • Offline verifier
Flow
Feed → agent request → chain of authority → require approval → 2 of 2 approvals (never the initiator) → sealed pack → revoke → deny → verify offline. Architecture diagram
Used on
  • /examples/: On the examples page; deep links ?task=quorum&step=4 jump to any step.
  • /demos/: The demos page: the guided tour runs in place.
  • /tour/: The authority tour page.