---
title: "Interactive examples | KYE Protocol™"
description: "Every agent action decided with its chain of authority: the decision feed, two chains of authority, the delegation chain, Purpose Permission™ and its twelve admissibility checks, built from KYE™'s own scenarios and contracts. Fictional data."
url: https://kyeprotocol.com/examples/
lang: en
source: "KYE Protocol"
---

> Every agent action decided with its chain of authority: the decision feed, two chains of authority, the delegation chain, Purpose Permission™ and its twelve admissibility checks, built from KYE™'s own scenarios and contracts. Fictional data.

# Interactive examples

Every widget here is built from KYE™'s own scenarios and contracts: the decision feed with its chain of authority, delegation chains and Purpose Permission. Demo data: fictional organisations, people and amounts.

All Security and identity teams Risk, compliance and audit Agent and platform builders

## Decision feed

Every agent action, decided with its chain of authority

### Every agent action, decided with its chain of authority

Fictional organisations, people, agents and amounts. The records follow KYE™'s published contract shapes; hashes are recomputed in your browser, signatures are not real.

For: Security and identity teams Risk, compliance and audit Agent and platform builders

#### Decision centre: chain of authority, admissibility, finality

Computed

**You learn:** Who decided what, along which chain, why a request was held or denied, and that the record is final and verifiable. **You can:** Watch decisions arrive; approve as the delegate (the initiator cannot), verify a seal, revoke a delegation.

Replay

Approver's phone 1 Approver console 2 CISO dashboard 2 agent-decisions 1

**Approver's phone** Dara Quinn, head of procurement

1. **KYE™ policy decision point** now

   Procurement agent orders above its approval threshold

   approval\_threshold\_breach

   Procurement Needs approval

   Details

   Chain of authority

   1. **Orrin Logistics (demo)** Principal
   2. **Dara Quinn, head of procurement** kye:authority:orrin.example:procurement-head-2026
   3. **Procurement agent** kye:authority:orrin.example:proc-04-2026q4

   Approve Dara Quinn, head of procurement Procurement agent tries to self-approve

**Approver console** Dara Quinn, head of procurement

1. **KYE™ policy decision point** now

   Drafting agent prepares a disclosure letter, with redaction

   permission\_granted

   Legal Allowed

   Details

   Decision record sealed

   1. **Decision** allow\_with\_constraints
   2. **Obligations** kye:obligation:redaction

   `ff8305bc6290ca7ef2d60b6290c4c2712c62b1280faf28be46d896685fdea90e`

   Verify CISO (demo)
2. **KYE™ policy decision point** now

   Credit agent acts outside its jurisdiction

   jurisdiction\_unsupported

   Financial services Denied

   Details

   Decision

   1. **not\_revoked** grant in force
   2. **within\_time\_window** 2026-10-14T09:09:20Z before 2027-01-12T00:00:00Z
   3. **action\_in\_scope** credit.line.approve in \[credit.line.approve\]
   4. **purpose\_matches** lending.adjudicate = lending.adjudicate
   5. **within\_jurisdiction** US in \[GB, IE\]
   6. **within\_constraints** GBP 4,200.00 ≤ GBP 25,000.00

**agent-decisions** Agent platform team (demo)

1. **KYE™ policy decision point** now

   Accounts-payable agent pays a supplier invoice

   permission\_granted

   Agent payments Allowed

   Details

   Chain of authority

   1. **Brightmoor Retail (demo)** Principal
   2. **Ana Ruiz, finance lead** kye:authority:brightmoor.example:finance-lead-2026
   3. **Accounts-payable agent** kye:authority:brightmoor.example:ap-11-2026q4

**CISO dashboard** CISO (demo)

1. **KYE™ policy decision point** now

   Clinical summarisation agent asks to read records for marketing

   permission\_missing

   Healthcare data access Denied

   Details

   Decision

   1. **not\_revoked** grant in force
   2. **within\_time\_window** 2026-10-14T09:05:31Z before 2027-01-01T00:00:00Z
   3. **action\_in\_scope** record.read in \[record.read, record.summarise\]
   4. **purpose\_matches** marketing.outreach ≠ clinical.summarise
   5. **data\_class\_in\_scope** \[health.record\] in \[health.record\]
   6. **within\_jurisdiction** GB in \[GB\]
2. **KYE™ policy decision point** now

   HR operations agent acts on a revoked delegation

   delegation\_revoked

   HR Denied

   Details

   Signal

   1. **Regional treasurer, EU** Revoked
   2. **Treasury agent (fx-router)** Revoked by cascade

   Revoke the treasurer's grant CISO (demo)

How this widget is built

**Demonstrates**

[Decision feed and approvals](https://kyeprotocol.com/terminal/)

**Components**

- Policy decision point (evaluate, kye\_decide)
- Chain of authority
- Admissibility checks
- Decision records and evidence packs
- Revocation cascade

**Flow**

Each decision lands on the device of whoever must know or act: approvals on the approver's phone, denials on the CISO dashboard, allows in the team channel. Tapping one opens its chain, checks, seal or cascade. [Architecture diagram](https://github.com/KYE-Protocol/hub/blob/main/docs/diagrams/kye-tour.png)

**Used on**

- [/examples/](https://kyeprotocol.com/examples/): On the examples page; it plays when scrolled into view (Play/Pause).
- [/](https://kyeprotocol.com/): The home page, right after its opening.
- [/terminal/](https://kyeprotocol.com/terminal/): The terminal: the decision centre on its devices.

### Every agent action, decided with its chain of authority

Fictional organisations, people, agents and amounts. The records follow KYE™'s published contract shapes; hashes are recomputed in your browser, signatures are not real.

For: Security and identity teams Risk, compliance and audit Agent and platform builders

#### Recent decisions

Demo data

**You learn:** What KYE™ decides for each agent action, why (reason code), and who must act. **You can:** Replay the feed; approve or decline the held decision.

Replay

1. **KYE™ policy decision point** Accounts-payable agent `payments.transfer` Allowed

   Accounts-payable agent pays a supplier invoice

   permission\_granted

   Pay €412.90 to Paperhouse Supplies (demo), invoice INV-2026-0917

   In-app Webhook

   - accounts\_payable.settle
   - kye\_decide
2. **KYE™ policy decision point** Procurement agent `purchase_order.create` Needs approval

   Procurement agent orders above its approval threshold

   approval\_threshold\_breach

   Order 40 pallets of packaging film from Kilnworks Supplies (demo), £18,400

   App push In-app Webhook

   - procurement.replenish
   - kye\_decide

   Approve Decline
3. **KYE™ policy decision point** Clinical summarisation agent `record.read` Denied

   Clinical summarisation agent asks to read records for marketing

   permission\_missing

   Read 1,200 patient records to build a marketing list (demo)

   In-app Webhook

   - marketing.outreach
   - kye\_purpose\_admit
4. **KYE™ policy decision point** HR operations agent `hr.record.update` Denied

   HR operations agent acts on a revoked delegation

   delegation\_revoked

   Change a staff member's contracted hours (demo)

   In-app Webhook

   - hr.contract.administer
   - kye\_authority\_check
5. **KYE™ policy decision point** Research and drafting agent `document.draft` Allowed

   Drafting agent prepares a disclosure letter, with redaction

   permission\_granted

   Draft a disclosure letter for matter M-2207 (demo)

   In-app Webhook

   - legal.matter\_support
   - kye\_decide
6. **KYE™ policy decision point** Credit decisioning agent `credit.line.approve` Denied

   Credit agent acts outside its jurisdiction

   jurisdiction\_unsupported

   Approve a £4,200 credit line for an applicant in the US (demo)

   In-app Webhook

   - lending.adjudicate
   - kye\_decide

How this widget is built

**Demonstrates**

[Decision feed](https://kyeprotocol.com/terminal/)

**Components**

- Policy decision point (kye\_decide)
- Decision records (kye.decision.record.v1)
- Approval routing (dual control)
- Evidence packs

**Flow**

Each agent action is decided against its chain of authority; approvals go to the delegate who holds the threshold; every outcome is sealed. [Architecture diagram](https://github.com/KYE-Protocol/hub/blob/main/docs/diagrams/kye-architecture.png)

**Used on**

- [/examples/](https://kyeprotocol.com/examples/): On the examples page, with the rest of its scenario.
- [/developers/](https://kyeprotocol.com/developers/): The developer portal: what every call returns.
- [/governed-ui/](https://kyeprotocol.com/governed-ui/): GovernedUI™: the decisions it shows.
- [/mcp/](https://kyeprotocol.com/mcp/): The MCP server: the decisions behind its tools.
- [/platform/](https://kyeprotocol.com/platform/): The platform: decisions with their chains of authority.
- [/terminal/](https://kyeprotocol.com/terminal/): The terminal: every decision, replayable.

### Procurement agent orders above its approval threshold

Order 40 pallets of packaging film from Kilnworks Supplies (demo), £18,400

For: Security and identity teams Risk, compliance and audit Agent and platform builders

#### Chain of authority

Demo data

**You learn:** Where this agent's authority comes from, at which hop it holds or stops, and what is sealed. **You can:** Walk the chain hop by hop.

Walk the chain

1. **Orrin Logistics (demo)**

   Principal

   kye:org:orrin.example
2. **Dara Quinn, head of procurement**

   Delegate

   kye:authority:orrin.example:procurement-head-2026

   procurement.replenish
3. **Procurement agent**

   Agent

   kye:authority:orrin.example:proc-04-2026q4

   procurement.replenish
4. **Procurement agent**

   Requested action

   Order 40 pallets of packaging film from Kilnworks Supplies (demo), £18,400
5. **KYE™ policy decision point** Needs approval

   Decision

   approval\_threshold\_breach

   Require approval
6. **KYE™ policy decision point**

   Decision record and evidence pack sealed

   kye.decision.record.v1

   Decision map hash recomputed in your browser: it matches the sealed record.

##### Expected outcome

- **Decision** Require approval

How this widget is built

**Demonstrates**

[Decision feed](https://kyeprotocol.com/terminal/)

**Components**

- Principal
- Delegated grant (actions, purpose, limit, jurisdiction, expiry)
- Agent grant
- Policy decision point (kye\_decide)
- Decision record and evidence pack

**Flow**

Principal → delegation → agent → action → allow / deny / approval → sealed decision record and evidence pack. [Architecture diagram](https://github.com/KYE-Protocol/hub/blob/main/docs/diagrams/kye-architecture.png)

**Used on**

- [/examples/](https://kyeprotocol.com/examples/): On the examples page, with the rest of its scenario.

### Clinical summarisation agent asks to read records for marketing

Read 1,200 patient records to build a marketing list (demo)

For: Security and identity teams Risk, compliance and audit Agent and platform builders

#### Chain of authority

Demo data

**You learn:** Where this agent's authority comes from, at which hop it holds or stops, and what is sealed. **You can:** Walk the chain hop by hop.

Walk the chain

1. **Halden Health (demo)**

   Principal

   kye:org:halden.example
2. **Dr Mira Okoye, clinical lead**

   Delegate

   kye:authority:halden.example:clinical-lead-2026

   clinical.summarise
3. **Clinical summarisation agent**

   Agent

   kye:authority:halden.example:clin-03-2026q4

   clinical.summarise
4. **Clinical summarisation agent**

   Requested action

   Read 1,200 patient records to build a marketing list (demo)
5. **KYE™ policy decision point** Denied

   Decision

   permission\_missing

   Deny
6. **KYE™ policy decision point**

   Decision record and evidence pack sealed

   kye.decision.record.v1

   Decision map hash recomputed in your browser: it matches the sealed record.

##### Expected outcome

- **Decision** Deny

How this widget is built

**Demonstrates**

[Decision feed](https://kyeprotocol.com/terminal/)

**Components**

- Principal
- Delegated grant (actions, purpose, limit, jurisdiction, expiry)
- Agent grant
- Policy decision point (kye\_decide)
- Decision record and evidence pack

**Flow**

Principal → delegation → agent → action → allow / deny / approval → sealed decision record and evidence pack. [Architecture diagram](https://github.com/KYE-Protocol/hub/blob/main/docs/diagrams/kye-architecture.png)

**Used on**

- [/examples/](https://kyeprotocol.com/examples/): On the examples page, with the rest of its scenario.

## Delegation chain

Each hop can only narrow the authority it received: fewer actions, a lower limit, fewer jurisdictions, an earlier expiry.

### Chain builder

Each hop can only narrow the authority it received: fewer actions, a lower limit, fewer jurisdictions, an earlier expiry.

For: Security and identity teams Agent and platform builders

#### Build it, try to widen it, revoke it

Demo data

**You learn:** Why authority can only narrow down a chain, and what a revocation does downstream. **You can:** Step through delegating, widening and revoking.

1. Step 1 of 5

   **Marlow Energy (demo)** Group CFO

   Delegate the next hop

   kye:authority:marlow.example:cfo-2026
2. Step 2 of 5

   **Group CFO** Regional treasurer, EU

   Delegate the next hop

   kye:authority:marlow.example:treasurer-eu-2026

   narrower than its parent
3. Step 3 of 5

   **Regional treasurer, EU** Treasury agent (fx-router)

   Delegate the next hop

   kye:authority:marlow.example:fx-router-2026q4

   Chain complete
4. Step 4 of 5

   **Treasury agent (fx-router)** Denied

   Try to widen the agent's grant

   graph\_delegation\_path\_disputed

   Rejected: the child grant would be wider than its parent
5. Step 5 of 5

   **Group CFO** Regional treasurer, EU

   Revoke the treasurer's grant

   kye:cascade:marlow.example:01JZC7RV2K

   Revoked by cascade

Back Next Start again

How this widget is built

**Demonstrates**

[Delegation chains](https://kyeprotocol.com/terminal/)

**Components**

- Authority grants (kye.authority.grant.v1)
- Narrowing rule
- Revocation cascade (kye.signal.revocation.cascaded.v1)

**Flow**

Each hop narrows the authority it received; a wider child grant is rejected; revoking a hop cascades to every hop below it. [Architecture diagram](https://github.com/KYE-Protocol/hub/blob/main/docs/diagrams/kye-architecture.png)

**Used on**

- [/examples/](https://kyeprotocol.com/examples/): On the examples page, with the rest of its scenario.

#### Who holds which grant

Demo data

**You learn:** What each hop is allowed to do. **You can:** Switch between the hops.

Marlow Energy (demo) Group CFO Regional treasurer, EU Treasury agent (fx-router)

##### Marlow Energy (demo)

Does

- Delegate the next hop

Marlow Energy (demo) Group CFO: Delegate the next hop

##### Group CFO

Does

- Delegate the next hop
- Revoke the treasurer's grant

Marlow Energy (demo) Group CFO: Delegate the next hop

Group CFO Regional treasurer, EU: Delegate the next hop

Group CFO Regional treasurer, EU: Revoke the treasurer's grant

##### Regional treasurer, EU

Does

- Delegate the next hop

Group CFO Regional treasurer, EU: Delegate the next hop

Regional treasurer, EU Treasury agent (fx-router): Delegate the next hop

Group CFO Regional treasurer, EU: Revoke the treasurer's grant

##### Treasury agent (fx-router)

Does

- Try to widen the agent's grant

Regional treasurer, EU Treasury agent (fx-router): Delegate the next hop

How this widget is built

**Demonstrates**

[Delegation chains](https://kyeprotocol.com/terminal/)

**Components**

- Principal
- Group CFO
- Regional treasurer
- Treasury agent

**Flow**

Each hop holds its own grant, narrower than its parent. [Architecture diagram](https://github.com/KYE-Protocol/hub/blob/main/docs/diagrams/kye-architecture.png)

**Used on**

- [/examples/](https://kyeprotocol.com/examples/): On the examples page, with the rest of its scenario.

## Purpose Permission™ lifecycle

Issue, admit, reconfirm, revoke

### Purpose grant

Summarise care records for the treating clinician

For: Risk, compliance and audit Agent and platform builders

#### Purpose Permission™ lifecycle

Demo data

**You learn:** How a purpose-bound grant is issued, used, renewed and revoked. **You can:** Run the lifecycle.

Run

1. Issue the grant

   Clinical lead

   Summarise care records for the treating clinician
2. Ask to summarise a record

   Clinical summarisation agent

   Admitted: every check passed
3. Reconfirm for 90 days

   Clinical lead
4. Revoke the grant

   Clinical lead

   grant revoked by the clinical lead
5. Ask to summarise a record

   KYE™ policy decision point

   Not admitted: not\_revoked failed

How this widget is built

**Demonstrates**

[Purpose Permission](https://kyeprotocol.com/terminal/)

**Components**

- Purpose grant
- Admissibility (kye\_purpose\_admit)
- Reconfirm / revoke

**Flow**

Issue, admit, reconfirm, revoke; after revocation the same request is not admitted. [Architecture diagram](https://github.com/KYE-Protocol/hub/blob/main/docs/diagrams/kye-architecture.png)

**Used on**

- [/examples/](https://kyeprotocol.com/examples/): On the examples page, with the rest of its scenario.

#### Purpose Permission API

Demo data

**You learn:** What the purpose-permission endpoints take and return. **You can:** Pick a request and send it.

`POST` Issue the grant `PATCH` Reconfirm for 90 days `DELETE` Revoke the grant

**Clinical lead** · Issue the grant

##### Request

```
POST /purpose-permissions

{
  "grantee": "<grantee>",
  "purpose": "<purpose>",
  "scope": "<scope>",
  "ttl_days": 90
}
```

Send request

##### Response `201`

```
{
  "grantee": "kye:ent:halden.example:agent:clin-03",
  "id": "kye:purpose:halden:clin-03:clinical-summarise-2026q4",
  "issued_by": "kye:ent:halden.example:officer:clinical-lead",
  "not_after": "2027-01-01T00:00:00Z",
  "not_before": "2026-10-01T00:00:00Z",
  "principal": "kye:ent:halden.example",
  "purpose": {
    "id": "kye:purpose-class:clinical.summarise",
    "label": "Summarise care records for the treating clinician"
  },
  "restrictions": {
    "dual_control": false,
    "jurisdiction": [
      "GB"
    ],
    "rate_cap": {
      "requests_per_minute": 20
    },
    "requires_evidence": true
  },
  "scope": {
    "actions": [
      "read",
      "summarise"
    ],
    "data_classes": [
      "health.record"
    ],
    "resources": [
      "kye:res:halden.example:ehr:ward-7"
    ]
  },
  "version": 1
}
```

How this widget is built

**Demonstrates**

[App API](https://kyeprotocol.com/developers/)

**Components**

- /api/v1/purpose-permissions
- OpenAPI contract (app.yaml)

**Flow**

Requests come from the app API contract; the issue response is the demo grant. [Architecture diagram](https://github.com/KYE-Protocol/hub/blob/main/docs/diagrams/kye-architecture.png)

**Used on**

- [/examples/](https://kyeprotocol.com/examples/): On the examples page, with the rest of its scenario.
- [/sandbox/demos/demo/](https://kyeprotocol.com/sandbox/demos/demo/): The sandbox demo: the same calls, answered from the contract.
- [/lab/](https://kyeprotocol.com/lab/): The lab: call the API in your browser.

### Admissibility checks (kye.purpose.admissibility.v1)

Admitted: every check passed

For: Risk, compliance and audit

#### Pipeline

Demo data

**You learn:** Exactly which checks admit a purpose request. **You can:** Run the checks.

Run

1. principal\_matches

   KYE™ policy decision point

   grant principal = halden.example
2. grantee\_matches

   KYE™ policy decision point

   request.actor = grant.grantee (clin-03)
3. purpose\_matches

   KYE™ policy decision point

   clinical.summarise
4. action\_in\_scope

   KYE™ policy decision point

   summarise in \[read, summarise\]
5. resource\_in\_scope

   KYE™ policy decision point

   patient-0412 under ward-7
6. data\_class\_in\_scope

   KYE™ policy decision point

   health.record in \[health.record\]
7. within\_time\_window

   KYE™ policy decision point

   inside \[2026-10-01, 2027-01-01)
8. within\_jurisdiction

   KYE™ policy decision point

   GB in \[GB\]
9. within\_rate\_cap

   KYE™ policy decision point

   6 of 20 requests a minute
10. not\_revoked

    KYE™ policy decision point

    grant.revoked\_at = null
11. signature\_valid

    KYE™ policy decision point

    signature verified against the clinical lead's key
12. dual\_control\_satisfied

    KYE™ policy decision point

    dual\_control = false

How this widget is built

**Demonstrates**

[Purpose Permission](https://kyeprotocol.com/terminal/)

**Components**

- kye.purpose.admissibility.v1
- 12 checks

**Flow**

Every admissibility check runs in order; any failure refuses the request. [Architecture diagram](https://github.com/KYE-Protocol/hub/blob/main/docs/diagrams/kye-architecture.png)

**Used on**

- [/examples/](https://kyeprotocol.com/examples/): On the examples page, with the rest of its scenario.

## Authority tour

An agent asks, people approve, a revocation denies: every outcome decided by KYE™'s own engine and sealed.

### Authority tour: decide, approve two of two, revoke and verify

Fictional organisations, people, agents and amounts. The records follow KYE™'s published contract shapes; hashes are recomputed in your browser, signatures are not real.

For: Security and identity teams Risk, compliance and audit Agent and platform builders

#### Authority tour

Computed

**You learn:** How KYE™ decides, who must approve, why the initiator cannot, and what a revocation does, each step verifiable. **You can:** Walk the three tasks, jump to any step by link, and open the sandbox at the end.

1. [**Decision feed** Every agent action, decided with its chain of authority 0 of 2](https://kyeprotocol.com/examples/?task=feed&step=1#w-authority-tour-en)
2. [**Agent asks, two people approve** Two of two approvers; the initiator can never approve. 0 of 7](https://kyeprotocol.com/examples/?task=quorum&step=1#w-authority-tour-en)
3. [**Revoke, deny, verify** A revoked delegation denies the same request; both packs verify offline. 0 of 3](https://kyeprotocol.com/examples/?task=revoke&step=1#w-authority-tour-en)

##### Decision feed

1. Step 1 of 2

   **KYE™ policy decision point**

   Every agent action, decided with its chain of authority

   Recent decisions
2. Step 2 of 2

   **Recent decisions** Dara Quinn, head of procurement

   Approval Procurement agent orders above its approval threshold

   **Procurement**

   Require approval

   **KYE™ policy decision point** Procurement Needs approval

   Procurement agent orders above its approval threshold

   Order 40 pallets of packaging film from Kilnworks Supplies (demo), £18,400

##### Agent asks, two people approve

1. Step 1 of 7

   **Procurement agent** KYE™ policy decision point

   Requested action

   Order 40 pallets of packaging film from Kilnworks Supplies (demo), £18,400

   - procurement.replenish
   - kye\_decide
2. Step 2 of 7

   **Chain of authority** Dara Quinn, head of procurement

   **Principal**

   Orrin Logistics (demo)

   **Delegate**

   Dara Quinn, head of procurement

   **Agent**

   Procurement agent

   **KYE™ policy decision point**

   Chain of authority

   kye:authority:orrin.example:proc-04-2026q4

   procurement.replenish
3. Step 3 of 7

   **KYE™ policy decision point** Needs approval

   Decision

   approval\_threshold\_breach

   require\_approval
4. Step 4 of 7

   **Approval request** Finance controller (demo), second approver

   **Quorum**

   2 of 2 (two\_person)

   **Agent**

   Cannot approve

   **Requested action**

   Order 40 pallets of packaging film from Kilnworks Supplies (demo), £18,400

   Approve

   On the approver's device

   **Procurement agent** Denied

   The initiator tries to approve its own request

   Refused: the initiator can never approve (maker is not checker)
5. Step 5 of 7

   **Approval request** Finance controller (demo), second approver

   **Quorum**

   2 of 2 (two\_person)

   **Agent**

   Cannot approve

   **Requested action**

   Order 40 pallets of packaging film from Kilnworks Supplies (demo), £18,400

   Approve

   On the approver's device

   **Dara Quinn, head of procurement** 1 of 2

   Approve

   two\_person
6. Step 6 of 7

   **Approval request** Finance controller (demo), second approver

   **Quorum**

   2 of 2 (two\_person)

   **Agent**

   Cannot approve

   **Requested action**

   Order 40 pallets of packaging film from Kilnworks Supplies (demo), £18,400

   Approve

   On the approver's device

   **Finance controller (demo), second approver** 2 of 2 Allowed

   Approve

   override\_approved

   allow\_with\_constraints

   - kye:obligation:dual-control
7. Step 7 of 7

   **Evidence pack** Offline verifier (public keys only)

   **Seal**

   kye.decision.record.v1

   **Verify**

   Decision map hash recomputed in your browser: it matches the sealed record.

   Sealed

   **KYE™ policy decision point**

   Decision record and evidence pack sealed

   kye.decision.record.v1

   Decision map hash recomputed in your browser: it matches the sealed record.

##### Revoke, deny, verify

1. Step 1 of 3

   **Orrin Logistics (demo)** Dara Quinn, head of procurement

   Revoke the delegation

   kye:authority:orrin.example:procurement-head-2026
2. Step 2 of 3

   **KYE™ policy decision point** Denied

   Replay

   delegation\_revoked

   deny
3. Step 3 of 3

   **Evidence pack** Offline verifier (public keys only)

   **Seal**

   kye.decision.record.v1

   **Verify**

   Decision map hash recomputed in your browser: it matches the sealed record.

   Details

   **Offline verifier (public keys only)**

   Verify

   Decision map hash recomputed in your browser: it matches the sealed record.

##### Try it on your own request

The playground runs the same three-outcome engine and returns a sealed evidence pack you can verify offline.

[Open the sandbox](https://sandbox.kyeprotocol.com/)

Back 1 of 2 Next

How this widget is built

**Demonstrates**

[Decision feed, approvals and evidence packs](https://kyeprotocol.com/terminal/)

**Components**

- Policy decision point (evaluate, kye\_decide)
- Delegation grants and quorum (two\_person)
- Decision records and evidence packs
- Offline verifier

**Flow**

Feed → agent request → chain of authority → require approval → 2 of 2 approvals (never the initiator) → sealed pack → revoke → deny → verify offline. [Architecture diagram](https://github.com/KYE-Protocol/hub/blob/main/docs/diagrams/kye-tour.png)

**Used on**

- [/examples/](https://kyeprotocol.com/examples/): On the examples page; deep links ?task=quorum&step=4 jump to any step.
- [/demos/](https://kyeprotocol.com/demos/): The demos page: the guided tour runs in place.
- [/tour/](https://kyeprotocol.com/tour/): The authority tour page.
