For CFOs · finance, FP&A, risk officers

Spend signed off, before authority commits.

KYE Action Admissibility™ refuses spend, contract, or settlement actions BEFORE authority is invoked — the CFO's thresholds become a Purpose Permission™ grant, not a Slack approval.

What goes wrong without runtime enforcement

The 4-question test your existing stack fails.

  1. 1

    Agent-driven spend lands on the AP run before Finance sees it. Refunds, supplier wires, settlements — autonomous, in your name, no pre-authorisation chain.

  2. 2

    Approval thresholds live in Slack messages, e-mail trails, and per-tool config. No single record proves the agent stayed inside the CFO's declared limits.

  3. 3

    When a payment goes wrong, reconstructing "who authorised this" takes finance-ops + IT + legal weeks. Counterparties and auditors don't accept "we checked the logs".

  4. 4

    Auditors and regulators are starting to ask the question your logs were never designed to answer: was this AI-agent action within the human-declared authority, AT THE MOMENT it executed?

KYE Runtime Console™ — your view

What KYE™ refuses (or admits) on your watch.

A 3-row preview of the canonical 6-row PDP state grid, filtered to action_class = financial — the action classes that matter to cfo. The full grid (Authority · Scope · Delegation · Policy · Decision · Evidence) renders at /runtime-console.html with a live synthetic stream.

sample filter: action_class = financial
CheckStateDetail
Authority verified delegated from CFO at 09:02 UTC, valid 7 days
Scope exceeded wire €4.2M to off-whitelist supplier — over single-payment cap (€1M)
Decision deny refused before commit; signed envelope ready for Treasury review

monitor_heart See the full Runtime Console →

Cost of inaction

What the gap costs your organisation.

  • A single mis-issued wire transfer typically costs 1.5× the principal once recovery + legal + supplier-trust costs are tallied. Mid-market exposure on a 24-month horizon: low-7-figure range.

  • Internal audit cycles around an AI-agent incident burn 3–6 weeks of FP&A + IT + legal partner time. Cycle cost compounds on the next incident.

  • Insurers are excluding AI-driven loss from cyber and crime cover. Without runtime evidence of authority, your stop-loss is your balance sheet.

Indicative ranges drawn from open public-filing data + industry incident reports. Customer-specific figures are scoped during the pilot intake.

What KYE™ delivers

4 concrete deliverables, no vapour.

  • Purpose Permission™ grants — the CFO's spend thresholds, supplier whitelists, contract-tier limits, jurisdiction caps, all declared once as machine-readable scope. Refusals are automatic, signed, replayable.

  • Action Admissibility™ — every AI-agent privileged call (wire, contract, settlement, refund) is checked against the grant BEFORE it commits. Out-of-scope = refused, with a signed refusal envelope counsel can show in court.

  • Evidence Pack™ — per-transaction signed receipt: who authorised, under which grant, at what time, in what state, with what data. Verifiable offline against KYE™'s published JWKS — no portal log-in, no vendor cooperation.

  • Dual-channel sign-off — admin-panel + signed-email-action token on every irreversible decision (refund > threshold, supplier switch, contract amendment). Belt-and-braces for the actions that can't be undone.

Beyond compliance

What you also get — that the compliance line item doesn’t price.

  • Audit cycle time on an AI-agent incident drops from weeks to hours. The Evidence Pack™ is the audit; the auditor verifies offline.

  • Insurers and brokers re-open AI-driven loss coverage when there is signed, offline-verifiable evidence of runtime authority. Premium and excess-layer terms improve materially.

  • Treasury + Finance get a real-time picture of "what authority was committed today" — not after month-end reconciliation. Cash and risk visibility become continuous.

How you measure ROI

The 4 signals we baseline on day 0 and report on weekly.

SignalWhat we measure
Avoided lossesRefunds / mis-wires / supplier disputes intercepted at the admissibility layer, by quarter.
Audit cycle compressionPerson-hours per AI-agent incident — internal audit + IT + legal + finance combined.
Insurer termsAI-loss exclusion lifted; premium delta vs the pre-KYE™ policy.
Contract speedTime from "agent proposes spend" to "spend committed" with full evidence — eliminates Slack-chain approvals.
Decision criteria

How to evaluate KYE™ — 5 pass/fail tests any vendor should answer.

  1. 1

    Can the protocol REFUSE an out-of-scope payment in <500ms at the action perimeter, not just record it after the fact? (KYE™: yes — PDP + PEP in front of the rail.)

  2. 2

    Can the auditor verify a transaction OFFLINE against published public keys, without a portal log-in or vendor cooperation? (KYE™: yes — Ed25519 signed envelope.)

  3. 3

    Does the policy live as machine-readable scope, not as Slack messages? (KYE™: yes — Purpose Permission™ JSON.)

  4. 4

    When a control fails, does the system emit a signed refusal envelope a court can subpoena? (KYE™: yes — every refusal carries an Ed25519 signature verifiable offline against the published JWKS.)

  5. 5

    Is there a kill-switch and dual-channel sign-off for irreversible actions? (KYE™: yes — admin panel + signed-email-action token.)

Decision route

From "interesting" to "decided" in 4 steps.

  1. 1
    Week 0 — Shadow mode

    KYE™ runs alongside your existing finance + agent stack, OBSERVING every privileged AI-agent call but enforcing nothing. Zero risk to in-flight transactions. You see what the gates would block.

  2. 2
    Week 1–2 — Scope declaration

    Your spend thresholds, supplier whitelist, contract tiers, jurisdictions become a written Purpose Permission™ grant. KYE™ reviews; legal signs off.

  3. 3
    Week 3–6 — Pilot enforcement

    KYE™ flips on enforcement for a bounded SKU (one supplier category, one transaction class, one jurisdiction). Real refusals, real Evidence Packs, real auditor walkthrough.

  4. 4
    Week 7–8 — Decision

    Read the Evidence Pack™ against your control framework (SOX, IFRS, COSO, DORA). Decide: roll out, narrow, defer. No lock-in.

Pilot pricing closed-signup; talk to the team via the apply form.

Full reference index — every page tagged for cfo (84) ↓
Derived from the graph

84 pages tagged for cfo.

This page is a derived view over internal. Adding or retagging a page rebuilds this landing on the next CI run — no hand-curated list to maintain.

Evaluate

Evaluate — 67 pages

Decide whether KYE Protocol™ is the right rail for the problem in front of you.

Build

Build — 1 page

Build against the rail — SDKs, agents, conformance pack, sandbox.

Learn

Learn — 10 pages

Learn the rail — glossary, frameworks, frameworks-explained.

Reference

Reference — 6 pages

Look up the canonical definition — schemas, dictionaries, ID format.

Ready to evaluate KYE Protocol™?

Start in shadow mode. We’ll deliver your first Evidence Pack™ in 4–8 weeks.