Glossary
Every KYE Protocol™ term, in plain English.
190 terms in 16 groups. One paragraph per term, as published on the live site.
Core protocol 14 terms
Identity, authority, and the chain.
Entity
Anything the protocol can name and reason about.
Core protocolURN
The canonical identifier format.
Core protocolActor
The entity actually performing an action.
Core protocolPrincipal
The entity on whose behalf the actor is acting.
Core protocolon-behalf-of
The relationship between actor and principal.
Core protocolDelegation
A signed grant from one entity to another.
Core protocolAuthority
The protocol's noun for "what an entity is allowed to cause to happen." Authority binds a capability + scope + state to an actor + principal pair.
Core protocolCapability
The named verb in the action vocabulary — e.g., payment.initiate , data.read .
Core protocolScope
The constraint set bounding an authority — amount cap, currency, corridor, time window, beneficiary allowlist, etc.
Core protocolAttenuation
The rule that a child authority's scope must be a subset (⊇) of its parent's.
Core protocolState
The current lifecycle status of an entity / authority / payload — e.g., active, quarantined, suspended, revoked.
Core protocolAuthority Graph™
The protocol's view of entities + delegations + authorities + capabilities + scopes as a typed graph.
Core protocolKYE™ Chain of Authority™
The structural artefact.
Core protocolPurpose Permission™
The purpose and scope rail.
Runtime 13 terms
Decision, enforcement, cascade.
Decision
The runtime's verdict on a single requested action.
RuntimeDecision codes
The standard set. allow_with_constraints , require_approval , deny .
RuntimeDecision Map™
The signed, replayable artefact emitted with every authorise call.
RuntimePEP — Policy Enforcement Point
The component that intercepts an action and asks the PDP for a decision.
RuntimePDP — Policy Decision Point
The component that evaluates the request against authorities + state + scope and returns a decision.
RuntimeePDP — Edge PDP
A locally-cached, offline-capable PDP for the bank/merchant edge.
RuntimeCascade
The propagation pattern applied when an upstream authority is revoked or quarantined.
RuntimeAuthority Finality™
The protocol-level *property* that a request's KYE™ Chain of Authority™ is provably terminal — verified end-to-end with public keys alone before the…
RuntimeAuthority Finality™ Diagnostic
The free 24-question / 6-lens self-assessment that scores an organisation's agentic AI authority posture on a 0–100 scale across 5 bands…
RuntimeAgent-as-Contracting-Party
The legal posture in which an AI agent's authority — the delegation it acts under, the purpose-permission it is scoped to, the revocation conditions…
RuntimeKYE™ Reconciliation Engine™
The check that what you declared is what you actually deployed.
RuntimeKYE™ Edge Governance™
Governance that still reaches a verdict when the network does not.
RuntimeCohesion Cascade™
The discipline that keeps the system one coherent state.
Evidence 10 terms
Audit chain, packs, replay.
Audit chain
The append-only, hash-linked sequence of audit events the runtime emits.
EvidenceEvidence Pack™
A signed bundle of audit-chain entries + Decision Maps™ + signatures + public-key set, replayable end-to-end with public keys alone.
EvidenceEvidence Graph™
The graph view across multiple evidence packs — how decisions, authorities.
EvidenceBlast Radius Map™
The view of which downstream authorities and active sessions a single revocation or quarantine signal will reach.
EvidenceProof bundle
The transport format for an evidence pack.
EvidencePayload state
The lifecycle status of a single payload.
EvidenceCanonicalisation
JCS (RFC 8785) canonical JSON form, used for hashing and signing.
EvidenceEd25519
The default signing primitive across credentials and proof bundles.
EvidenceResilience Loop™
The evidence and replay rail.
EvidenceDelegated Auditability™
Letting an auditor verify your governance without handing them access to your production systems or your customers’ data.
Continuity 10 terms
Decision values, drift types, evidence pack.
KYE™ Continuity Profile™
The runtime profile that binds interpreted intent vs declared intent, multi-dimension authority state, pressure context, incentive context and…
ContinuityAuthority Continuity™
The protocol-level property that an actor's authority at decision time matches the authority granted by its delegation chain — no scope drift, no…
ContinuityAgency Continuity™
The protocol-level property that an actor's interpreted goal at decision time matches its declared intent.
ContinuityContinuity decision values
The standard set includes continuity_preserved , continuity_degraded and continuity_broken .
ContinuityDrift types
Ten named categories.
ContinuityContinuity Decision Map™
The signed, replayable artefact bound to a single continuity decision.
ContinuityContinuity Evidence Pack™
A signed bundle composing intent + interpretation + 6-dimension state + pressure + incentive + decision + execution + drift events under…
ContinuityKYEAgencyDriftEvent
One record per detected drift, signed and hash-chained into the audit ledger.
ContinuityKYE™ Continuity Gateway™
Runtime extension to the reference Gateway adding the continuity decision surface + drift-event endpoints.
ContinuityKYE™ Agency Drift Monitor™
Drift detection + alerting surface (planned commercial layer).
Discoverability 10 terms
Directory, path finder, risk discovery.
KYE™ Discoverability Profile™
The runtime profile that turns a cryptographically-bound authority graph into a queryable surface, with role-and-purpose discovery policy, row-level…
DiscoverabilityDiscovery modes
The standard set. directory_lookup , path_finder , graph_walk , risk_discovery , connector_discovery , evidence_finder .
DiscoverabilityRisk-discovery types
Three non-mutating traversals.
DiscoverabilityKYE™ Authority Directory™
The directory index of cryptographically-bound authority records.
DiscoverabilityKYE™ Discovery Console™
The operator surface over the directory + path finder + risk discovery.
DiscoverabilityKYE™ Authority Path Finder™
The path-resolution engine over the authority graph — given (principal, actor, capability), returns one or more delegation paths with edge-by-edge…
DiscoverabilityKYE™ Evidence Finder™
The resolver over audit-event and evidence-pack indexes.
DiscoverabilityKYE™ Connector Discovery Hub™
The discovery surface for Connector Profile™ implementations and their conformance state.
DiscoverabilityDiscovery policy
The selection rule on (role, purpose, requester-tenant, target-tenant) that determines which authority records appear in a result set and which…
DiscoverabilityFederation trust
The cross-trust-domain trust signal that gates whether a discovery query may traverse an edge into another tenant's authority graph.
Search · Memory · Mapping · Reporting 5 terms
Four new sub-engines.
KYE™ Data Mapping Agent™
Sub-engine of the Directory Engine.
Search · Memory · Mapping · ReportingKYE™ Native Search Engine™
Sub-engine of the Directory Engine.
Search · Memory · Mapping · ReportingKYE™ Memory Engine™
Sub-engine of the Decision Engine.
Search · Memory · Mapping · ReportingKYE™ Reporting Engine™
Sub-engine of the Evidence Engine.
Search · Memory · Mapping · Reportingreports@kyeprotocol.com
The canonical auto-delivery From-address for sealed compliance reports.
Ontology 13 terms
Semantic layer — shared meaning, not just permission.
KYE™ Ontology Profile™
The semantic layer of KYE™.
OntologyOntology domain
One of twelve domains every KYE™ term must declare.
OntologyPredicate
Stable predicate dictionary.
OntologyMapping type
Six explicit categories.
OntologyKYE™ ontology term
One canonical term in the registry.
OntologyKYE™ ontology relationship
One predicate triple (subject, predicate, object) with constraints + evidence requirements.
OntologyKYE™ ontology mapping
External-system → KYE™ term mapping with mapping_type , confidence.
OntologyKYE™ Semantic Assertion
A signed record bound to a runtime decision listing every term, mapping and predicate consulted.
OntologyKYE™ Ontology Registry™
Managed registry for terms, relationships, mappings and semantic assertions.
OntologyKYE™ Semantic Authority Mapper™
Maps OAuth scopes, IAM roles, payment mandates, legal delegations, healthcare consents, API permissions and sector terms into KYE™ without losing…
OntologyKYE™ Semantic Graph™
Graph view of the ontology + live instances.
OntologyKYE™ Ontology Conformance™
Conformance fixture suite + certification track for ontology-correct implementations.
OntologyJSON-LD context
Recommended semantic-interoperability serialisation.
Operating Model 16 terms
Adoption layer — from readiness to runtime control.
KYE™ Operating Model Profile™
The enterprise adoption layer of KYE™.
Operating ModelJourney stages
Ten ordered stages. intake , assess , classify , map_authority , place_gates , configure_runtime , execute , evidence , review , improve .
Operating ModelUse-case intake
Initial proposal for a delegated AI worker.
Operating ModelReadiness assessment
Multi-dimension assessment plus a readiness score plus the required profiles, gates and evidence for the assessed entity.
Operating ModelEntity Authority Record™
Living governance record per delegated actor — owner, accountable entity, purpose, lifecycle state, risk tier, approved + prohibited capabilities,…
Operating ModelKYE™ Authority Gates™
Runtime gate placed before high-impact delegated actions.
Operating ModelKYE™ Commit Boundary™
Separates recommendation from committed action.
Operating ModelReview path
Multi-step human-review chain with required role, decision options, optional condition and SLA per step.
Operating ModelAdoption Evidence Pack™
Signed bundle composing intake + readiness + authority record + gates + commit boundaries + review paths + training + sample runtime decisions.
Operating ModelKYE™ Governed Entity Catalog™ entry
Discovery entry per governed entity — agent, model, tool, service, connector, app, plugin, profile or certified implementation.
Operating ModelKYE™ AI Worker Readiness App™
Assess whether an AI worker is ready for pilot, controlled execution or production deployment.
Operating ModelKYE™ Cloud Portal™
Enterprise dashboard tying use-cases, agents, gates, boundaries, decisions, evidence packs, training and certification together.
Operating ModelKYE™ Academy™
Training and certification track for KYE™ Operating Model Profile™ owners and operators.
Operating ModelKYE™ Comms Engine™
The one engine every outbound message from every KYE Protocol™ surface passes through.
Operating ModelKYE™ Billing Meters™
Usage metering for governed activity.
Operating ModelKYE™ Onboarding Agent™
The guided path from first contact to a working, governed tenant.
Assurance 15 terms
Living lifecycle assurance — system cards become executable.
KYE™ Assurance Card Profile™
The lifecycle assurance layer of KYE™.
AssuranceKYE™ Assurance Card™
Living lifecycle record per delegated entity — owner, accountable entity, intended use, prohibited uses, authority model, human involvement,…
AssuranceAssurance lifecycle stages
Eight stages. design , pilot , deploy , monitor , incident_review , scope_change_review , retention_review , decommission .
AssuranceKYE™ Human Involvement Plan™
Schema-bound record of points where authorised humans must influence, direct, limit, approve, override or review an AI-enabled system.
AssuranceHuman involvement types
Six types. influence , direct , limit , approve , override , review .
AssuranceKYE™ Provenance Evidence
Provenance + supply-chain dimension — model / dataset / tool / hardware / supplier / licence references with verification status.
AssuranceKYE™ Assurance Review Cycle™
Scheduled + event-triggered review windows.
AssuranceKYE™ Decommissioning Plan
Retention windows, off-boarding step sequence, cascade-revocation scope, evidence-archival policy, post-execution verification.
AssuranceOff-boarding actions
Eight named actions. revoke_authority , quarantine_credentials , rotate_keys , archive_evidence , notify_owner , notify_supplier , update_catalog ,…
AssuranceKYE™ Assurance Card Builder™
Generate living assurance cards from KYE™ runtime objects.
AssuranceKYE™ Assurance Card Library™
Discoverable library of governed AI use cases + assurance patterns.
AssuranceKYE™ Human Involvement Planner™
Define where authorised humans must review, approve, limit or override AI-enabled actions across the lifecycle.
AssuranceKYE™ Provenance & Supply Chain Evidence App™
Track datasets, models, tools, suppliers, licences and hardware lineage as runtime-bound evidence.
AssuranceKYE™ Assurance Review Scheduler™
Scheduled + event-triggered + scope-change + incident + retention + decommissioning review cycles.
AssuranceKYE™ Governed Use Case Library™
Sector-curated library of governed AI use cases linking authority records, gates, commit boundaries, decisions, evidence packs and assurance cards.
Formal Rules 17 terms
Rights, obligations, prohibitions, powers — enforceable.
KYE™ Formal Rules Profile™
The rights, obligations and governance layer of KYE™.
Formal RulesRule families
Six families. permission , obligation , prohibition , power , immunity , exception .
Formal RulesNormative operators
Compact operator notation.
Formal RulesKYE™ Permission
Standing rule that an actor MAY perform a capability under defined scope + state.
Formal RulesKYE™ Obligation
Lifecycle object — actor MUST perform a required action by a deadline.
Formal RulesKYE™ Prohibition
Standing rule — actor MUST NOT perform the prohibited capability.
Formal RulesKYE™ Power
Authority to create, modify, revoke, waive or override a normative state.
Formal RulesKYE™ Exception
A rule that displaces or modifies another rule under enumerated exceptional conditions (incident response, business continuity, regulatory…
Formal RulesKYE™ Governance Rule
Meta-rule on who may override which rules, under what conditions, with what evidence.
Formal RulesKYE™ Rule Conflict
Detected conflict between two or more rules with the resolution strategy applied (e.g., specific overrides general, prohibition overrides permission).
Formal RulesKYE™ Rule Proof
Test result over a rule set checking enumerated consistency properties.
Formal RulesKYE™ Obligation State
One state-transition record on a KYEObligation .
Formal RulesKYE™ Rights & Obligations Engine™
Runtime engine that evaluates permissions, obligations, prohibitions, powers, exceptions and governance rules.
Formal RulesKYE™ Obligation Ledger™
Append-only ledger tracking every obligation lifecycle, hash-chained into the audit ledger.
Formal RulesKYE™ Rule Prover™
Pre-runtime consistency checker for rule sets — conflicts, unbounded obligations, missing satisfaction paths, circular delegation, override gaps.
Formal RulesKYE™ Control Compiler™
Compiles formal KYE™ rules into runtime PDP/PEP policies, authority gates, commit boundaries, signal events and evidence requirements.
Formal RulesKYE™ Contract-to-Authority Mapper™
Phase-2 — extracts permissions, obligations, prohibitions and powers from contracts, policies and mandates into KYE™ formal rules.
Admissibility 9 terms
Pre-action layer — before authority.
KYE™ Action Admissibility Profile™
The upstream pre-action layer of KYE™.
AdmissibilityKYE™ Proposed Action
The candidate action submitted to KYE™ Admission Gate™ for admissibility check before any authority decisioning.
AdmissibilityKYE™ Admission Gate™
Pre-admission gate placed UPSTREAM of authority gates.
AdmissibilityAdmissibility decision values
Six values. admit , reject , require_clarification , require_human_review , quarantine , route_to_authority_check .
AdmissibilityInadmissibility classes
Fifteen classes the engine actively detects.
AdmissibilityKYE™ Admissibility Decision
Signed verdict for a proposed action with checked dimensions, next-step routing, obligations and reference to the admissibility-evidence record.
AdmissibilityKYE™ Admissibility Evidence
Hash-chained record of the inputs and signals consulted at admission time.
AdmissibilityKYE™ Admissibility Engine™
Runtime engine performing the admission check across intent, source, data, policy and rule dimensions.
AdmissibilityKYE™ Pre-Action Filter™
Product-friendly synonym for the admission surface in marketing copy.
Compliance 5 terms
Mapping rail, OSCAL, frameworks.
Control mapping
The named link from a protocol artefact to a regulatory control — e.g., evidence pack → SOC 2 CC7.2.
ComplianceKYE™ Compliance Mapping Rail™
The runtime channel through which evidence becomes per-framework projection.
ComplianceAI System Compliance Card™
The public-key-verifiable nutrition label for any AI system.
ComplianceProfile
One of 10 canonical conformance profiles — core , pdp , epdp , spdp , pep , runtime-authority , evidence-replay , connector , manifest , conformance .
ComplianceNon-goals
Things the protocol explicitly does NOT do — replace SCA, replace tokenisation, run fraud scoring, etc.
Program 8 terms
Conformance, certification, partner ladder.
Conformance pack
The 133 black-box fixtures any implementation runs to demonstrate spec compliance.
ProgramKYE™ Self-Tested™
L1 of the conformance ladder.
ProgramKYE™ Self-Attested™
L2. Signed self-attestation (Ed25519, JWS) bundled with fixture results.
ProgramKYE™ Conformant™
L3. Program-reviewed conformance report + badge + registry listing.
ProgramKYE™ Certified™
L4. Third-party-audited certification by an approved firm.
ProgramKYE™ Cloud Gateway™
The optional commercial layer.
ProgramRFC
The four-stage process for landing changes.
ProgramUniversal Engagement Rail
One intake surface for every external party — pilot, partner, trainer, auditor.
Framework dictionary 27 terms
Regulator terms KYE™ binds, by framework.
Annex III high-risk system (EU AI Act Art 6)
(EU AI Act Art 6)
Framework dictionaryEU AI Act Art 9 — Risk management
— Risk management
Framework dictionaryEU AI Act Art 12 — Record-keeping
— Record-keeping
Framework dictionaryEU AI Act Art 13 — Transparency to deployer
— Transparency to deployer
Framework dictionaryEU AI Act Art 50 — Interaction disclosure
— Interaction disclosure
Framework dictionaryHAARF §4.2 verifiable-by-third-party
verifiable-by-third-party
Framework dictionaryHAARF Risk-Reduction-per-Effort
HAARF v1.0 ranking heuristic for guard recommendations.
Framework dictionarySR 11-7 §V — Model risk management
— Model risk management
Framework dictionarySR 11-7 §VI — Model inventory
— Model inventory
Framework dictionaryDORA Art 28 — Critical third-party
— Critical third-party
Framework dictionaryDORA Art 6 — ICT risk framework
— ICT risk framework
Framework dictionaryGDPR Art 30 — Record of Processing Activities (RoPA)
— Record of Processing Activities (RoPA)
Framework dictionaryGDPR Art 44-49 — Cross-border transfers
— Cross-border transfers
Framework dictionaryGDPR Art 35 — DPIA
— DPIA
Framework dictionarySEC 17a-4(f) — Records preservation
— Records preservation
Framework dictionaryFINRA 4511(d) — Books and records
— Books and records
Framework dictionaryPCI DSS 6.4.1 — Segregated environments
— Segregated environments
Framework dictionaryISO 42001 Annex A.4 — Lifecycle
— Lifecycle
Framework dictionaryISO 27001 9.1 — Monitoring of operational controls
— Monitoring of operational controls
Framework dictionaryNIST AI RMF GOVERN-1.2 — Traceability
— Traceability
Framework dictionaryNIST 800-207 — Zero Trust Architecture
— Zero Trust Architecture
Framework dictionaryBCBS 239 §6 — Maker-checker / dual control
— Maker-checker / dual control
Framework dictionaryFCA OpRes IBS — Important Business Service
— Important Business Service
Framework dictionaryMHRA SaMD & AI
UK Medicines and Healthcare products Regulatory Agency Software-as-a-Medical-Device regime.
Framework dictionaryOSCAL — Open Security Controls Assessment Language (NIST)
(NIST)
Framework dictionaryHIPAA §164.312 — Technical safeguards
— Technical safeguards
Framework dictionaryUK NCSC CAF Principle B6 — Staff awareness & training
— Staff awareness & training
External standards we compose with 7 terms
For reference, not redefinition.
OAuth 2.0 / OIDC
Human-centric authorisation + identity federation.
External standards we compose withSPIFFE / SPIRE
Workload identity for services.
External standards we compose withMCP — Model Context Protocol
Tool / agent communication protocol.
External standards we compose withKYA — Know Your Agent
The general industry term for agent attestation.
External standards we compose withPSD3
EU revised Payment Services Directive.
External standards we compose withDORA
EU Digital Operational Resilience Act.
External standards we compose withEU AI Act
The Union's horizontal AI regulation.
Human-control surface for AI authority 11 terms
KYE™ GovernedUI™ — the visible control layer.
KYE™ GovernedUI™
The human-facing control layer.
Human-control surface for AI authorityAction Approval
Pre-action human review of an agent’s proposed action.
Human-control surface for AI authorityEntity Passport
At-a-glance identity for any agent / human / system / external app — verification status, authority profile, allowed capabilities, restricted…
Human-control surface for AI authorityAuthority Scope
Three-way can / cannot / needs-approval breakdown for any entity.
Human-control surface for AI authorityCritical Point Review
Heavy-weight review for irreversible / regulated actions.
Human-control surface for AI authorityEvidence Timeline
Replay-proof chain from proposal to execute-or-block.
Human-control surface for AI authorityApproval Queue
Multi-reviewer queue with pending / high-risk / escalations / second-approval-pending / SLA-breached / evidence-gap views.
Human-control surface for AI authorityAuthority Drift Detector
Live drift events from the kye-drift-detector Worker (ten dimensions: intent, scope, state, payload, timing, frequency, target, semantic, agency,…
Human-control surface for AI authorityApproval modes
Locked set (§36 §6): none , single_approver , two_person , two_person_with_legal , delegated , auto (forbidden at high+ risk).
Human-control surface for AI authorityMeta-governance gate
§36 §9 (LOCKED). Self-grants ( delegate_authority or modify_own_authority where actor == grantee) are rejected at the PDP gate with reason_code:…
Human-control surface for AI authorityCritical-action catalogue
Twenty action classes that trigger a signed, replay-proof approval flow: send_email, send_message, delete_file, export_data, access_sensitive_data,…
No term matches this search.
Learn the terms in context: the academy.
- Action ApprovalAction Approval: Pre-action human review of an agent’s proposed action.
- ActorActor: The entity actually performing an action.
- Admissibility decision valuesAdmissibility decision values: Six values. admit , reject , require_clarification , require_human_review , quarantine , route_to_authority_check .
- Adoption Evidence Pack™Adoption Evidence Pack™: Signed bundle composing intake + readiness + authority record + gates + commit boundaries + review paths + training + sample runtime…
- Agency Continuity™Agency Continuity™: The protocol-level property that an actor's interpreted goal at decision time matches its declared intent.
- Agent-as-Contracting-PartyAgent-as-Contracting-Party: The legal posture in which an AI agent's authority — the delegation it acts under, the purpose-permission it is scoped to, the…
- AI System Compliance Card™AI System Compliance Card™: The public-key-verifiable nutrition label for any AI system.
- Annex III high-risk system (EU AI Act Art 6)Annex III high-risk system (EU AI Act Art 6): (EU AI Act Art 6)
- Approval modesApproval modes: Locked set (§36 §6): none , single_approver , two_person , two_person_with_legal , delegated , auto (forbidden at high+ risk).
- Approval QueueApproval Queue: Multi-reviewer queue with pending / high-risk / escalations / second-approval-pending / SLA-breached / evidence-gap views.
- Assurance lifecycle stagesAssurance lifecycle stages: Eight stages. design , pilot , deploy , monitor , incident_review , scope_change_review , retention_review , decommission .
- AttenuationAttenuation: The rule that a child authority's scope must be a subset (⊇) of its parent's.
- Audit chainAudit chain: The append-only, hash-linked sequence of audit events the runtime emits.
- AuthorityAuthority: The protocol's noun for "what an entity is allowed to cause to happen." Authority binds a capability + scope + state to an actor + principal pair.
- Authority Continuity™Authority Continuity™: The protocol-level property that an actor's authority at decision time matches the authority granted by its delegation chain — no scope…
- Authority Drift DetectorAuthority Drift Detector: Live drift events from the kye-drift-detector Worker (ten dimensions: intent, scope, state, payload, timing, frequency, target…
- Authority Finality™ (Glossary)Authority Finality™: The protocol-level *property* that a request's KYE™ Chain of Authority™ is provably terminal — verified end-to-end with public keys alone…
- Authority Finality™ DiagnosticAuthority Finality™ Diagnostic: The free 24-question / 6-lens self-assessment that scores an organisation's agentic AI authority posture on a 0–100 scale…
- Authority Graph™Authority Graph™: The protocol's view of entities + delegations + authorities + capabilities + scopes as a typed graph.
- Authority ScopeAuthority Scope: Three-way can / cannot / needs-approval breakdown for any entity.
- BCBS 239 §6BCBS 239 §6 — Maker-checker / dual control: — Maker-checker / dual control
- Blast Radius Map™Blast Radius Map™: The view of which downstream authorities and active sessions a single revocation or quarantine signal will reach.
- CanonicalisationCanonicalisation: JCS (RFC 8785) canonical JSON form, used for hashing and signing.
- CapabilityCapability: The named verb in the action vocabulary — e.g., payment.initiate , data.read .
- CascadeCascade: The propagation pattern applied when an upstream authority is revoked or quarantined.
- Cohesion Cascade™Cohesion Cascade™: The discipline that keeps the system one coherent state.
- Conformance packConformance pack: The 133 black-box fixtures any implementation runs to demonstrate spec compliance.
- Continuity Decision Map™Continuity Decision Map™: The signed, replayable artefact bound to a single continuity decision.
- Continuity decision valuesContinuity decision values: The standard set includes continuity_preserved , continuity_degraded and continuity_broken .
- Continuity Evidence Pack™Continuity Evidence Pack™: A signed bundle composing intent + interpretation + 6-dimension state + pressure + incentive + decision + execution + drift events…
- Control mappingControl mapping: The named link from a protocol artefact to a regulatory control — e.g., evidence pack → SOC 2 CC7.2.
- Critical Point ReviewCritical Point Review: Heavy-weight review for irreversible / regulated actions.
- Critical-action catalogueCritical-action catalogue: Twenty action classes that trigger a signed, replay-proof approval flow: send_email, send_message, delete_file, export_data…
- DecisionDecision: The runtime's verdict on a single requested action.
- Decision codesDecision codes: The standard set. allow_with_constraints , require_approval , deny .
- Decision Map™Decision Map™: The signed, replayable artefact emitted with every authorise call.
- Delegated Auditability™Delegated Auditability™: Letting an auditor verify your governance without handing them access to your production systems or your customers’ data.
- DelegationDelegation: A signed grant from one entity to another.
- Discovery modesDiscovery modes: The standard set. directory_lookup , path_finder , graph_walk , risk_discovery , connector_discovery , evidence_finder .
- Discovery policyDiscovery policy: The selection rule on (role, purpose, requester-tenant, target-tenant) that determines which authority records appear in a result set and…
- DORA (Glossary)DORA: EU Digital Operational Resilience Act.
- DORA Art 28DORA Art 28 — Critical third-party: — Critical third-party
- DORA Art 6DORA Art 6 — ICT risk framework: — ICT risk framework
- Drift typesDrift types: Ten named categories.
- Ed25519Ed25519: The default signing primitive across credentials and proof bundles.
- EntityEntity: Anything the protocol can name and reason about.
- Entity Authority Record™Entity Authority Record™: Living governance record per delegated actor — owner, accountable entity, purpose, lifecycle state, risk tier, approved + prohibited…
- Entity PassportEntity Passport: At-a-glance identity for any agent / human / system / external app — verification status, authority profile, allowed capabilities, restricted…
- ePDPePDP — Edge PDP: A locally-cached, offline-capable PDP for the bank/merchant edge.
- EU AI Act (Glossary)EU AI Act: The Union's horizontal AI regulation.
- EU AI Act Art 12EU AI Act Art 12 — Record-keeping: — Record-keeping
- EU AI Act Art 13EU AI Act Art 13 — Transparency to deployer: — Transparency to deployer
- EU AI Act Art 50EU AI Act Art 50 — Interaction disclosure: — Interaction disclosure
- EU AI Act Art 9EU AI Act Art 9 — Risk management: — Risk management
- Evidence Graph™Evidence Graph™: The graph view across multiple evidence packs — how decisions, authorities.
- Evidence Pack™ (Glossary)Evidence Pack™: A signed bundle of audit-chain entries + Decision Maps™ + signatures + public-key set, replayable end-to-end with public keys alone.
- Evidence TimelineEvidence Timeline: Replay-proof chain from proposal to execute-or-block.
- FCA OpRes IBSFCA OpRes IBS — Important Business Service: — Important Business Service
- Federation trustFederation trust: The cross-trust-domain trust signal that gates whether a discovery query may traverse an edge into another tenant's authority graph.
- FINRA 4511(d)FINRA 4511(d) — Books and records: — Books and records
- GDPR Art 30GDPR Art 30 — Record of Processing Activities (RoPA): — Record of Processing Activities (RoPA)
- GDPR Art 35GDPR Art 35 — DPIA: — DPIA
- GDPR Art 44-49GDPR Art 44-49 — Cross-border transfers: — Cross-border transfers
- Glossary (Learn)Canonical AI governance glossary — definitions for AI governance, delegated authority, Purpose Permission™, evidence pack, Replay-Proof™, authority gap, and…
- HAARF §4.2 verifiable-by-third-partyHAARF §4.2 verifiable-by-third-party: verifiable-by-third-party
- HAARF Risk-Reduction-per-EffortHAARF Risk-Reduction-per-Effort: HAARF v1.0 ranking heuristic for guard recommendations.
- HIPAA §164.312HIPAA §164.312 — Technical safeguards: — Technical safeguards
- Human involvement typesHuman involvement types: Six types. influence , direct , limit , approve , override , review .
- Inadmissibility classesInadmissibility classes: Fifteen classes the engine actively detects.
- ISO 27001 9.1ISO 27001 9.1 — Monitoring of operational controls: — Monitoring of operational controls
- ISO 42001 Annex A.4ISO 42001 Annex A.4 — Lifecycle: — Lifecycle
- Journey stagesJourney stages: Ten ordered stages. intake , assess , classify , map_authority , place_gates , configure_runtime , execute , evidence , review , improve .
- JSON-LD contextJSON-LD context: Recommended semantic-interoperability serialisation.
- KYAKYA — Know Your Agent: The general industry term for agent attestation.
- KYEAgencyDriftEventKYEAgencyDriftEvent: One record per detected drift, signed and hash-chained into the audit ledger.
- KYE™ Academy™KYE™ Academy™: Training and certification track for KYE™ Operating Model Profile™ owners and operators.
- KYE™ Action Admissibility Profile™KYE™ Action Admissibility Profile™: The upstream pre-action layer of KYE™.
- KYE™ Admissibility DecisionKYE™ Admissibility Decision: Signed verdict for a proposed action with checked dimensions, next-step routing, obligations and reference to the…
- KYE™ Admissibility Engine™KYE™ Admissibility Engine™: Runtime engine performing the admission check across intent, source, data, policy and rule dimensions.
- KYE™ Admissibility EvidenceKYE™ Admissibility Evidence: Hash-chained record of the inputs and signals consulted at admission time.
- KYE™ Admission Gate™KYE™ Admission Gate™: Pre-admission gate placed UPSTREAM of authority gates.
- KYE™ Agency Drift Monitor™KYE™ Agency Drift Monitor™: Drift detection + alerting surface (planned commercial layer).
- KYE™ AI Worker Readiness App™KYE™ AI Worker Readiness App™: Assess whether an AI worker is ready for pilot, controlled execution or production deployment.
- KYE™ Assurance Card Builder™KYE™ Assurance Card Builder™: Generate living assurance cards from KYE™ runtime objects.
- KYE™ Assurance Card Library™KYE™ Assurance Card Library™: Discoverable library of governed AI use cases + assurance patterns.
- KYE™ Assurance Card Profile™KYE™ Assurance Card Profile™: The lifecycle assurance layer of KYE™.
- KYE™ Assurance Card™KYE™ Assurance Card™: Living lifecycle record per delegated entity — owner, accountable entity, intended use, prohibited uses, authority model, human…
- KYE™ Assurance Review Cycle™KYE™ Assurance Review Cycle™: Scheduled + event-triggered review windows.
- KYE™ Assurance Review Scheduler™KYE™ Assurance Review Scheduler™: Scheduled + event-triggered + scope-change + incident + retention + decommissioning review cycles.
- KYE™ Authority Directory™KYE™ Authority Directory™: The directory index of cryptographically-bound authority records.
- KYE™ Authority Gates™KYE™ Authority Gates™: Runtime gate placed before high-impact delegated actions.
- KYE™ Authority Path Finder™KYE™ Authority Path Finder™: The path-resolution engine over the authority graph — given (principal, actor, capability), returns one or more delegation paths…
- KYE™ Billing Meters™KYE™ Billing Meters™: Usage metering for governed activity.
- KYE™ Certified™KYE™ Certified™: L4. Third-party-audited certification by an approved firm.
- KYE™ Chain of Authority™KYE™ Chain of Authority™: The structural artefact.
- KYE™ Cloud Gateway™KYE™ Cloud Gateway™: The optional commercial layer.
- KYE™ Cloud Portal™KYE™ Cloud Portal™: Enterprise dashboard tying use-cases, agents, gates, boundaries, decisions, evidence packs, training and certification together.
- KYE™ Commit Boundary™KYE™ Commit Boundary™: Separates recommendation from committed action.
- KYE™ Comms Engine™KYE™ Comms Engine™: The one engine every outbound message from every KYE Protocol™ surface passes through.
- KYE™ Compliance Mapping Rail™KYE™ Compliance Mapping Rail™: The runtime channel through which evidence becomes per-framework projection.
- KYE™ Conformant™KYE™ Conformant™: L3. Program-reviewed conformance report + badge + registry listing.
- KYE™ Connector Discovery Hub™KYE™ Connector Discovery Hub™: The discovery surface for Connector Profile™ implementations and their conformance state.
- KYE™ Continuity Gateway™KYE™ Continuity Gateway™: Runtime extension to the reference Gateway adding the continuity decision surface + drift-event endpoints.
- KYE™ Continuity Profile™KYE™ Continuity Profile™: The runtime profile that binds interpreted intent vs declared intent, multi-dimension authority state, pressure context, incentive…
- KYE™ Contract-to-Authority Mapper™KYE™ Contract-to-Authority Mapper™: Phase-2 — extracts permissions, obligations, prohibitions and powers from contracts, policies and mandates into KYE™ formal…
- KYE™ Control Compiler™KYE™ Control Compiler™: Compiles formal KYE™ rules into runtime PDP/PEP policies, authority gates, commit boundaries, signal events and evidence requirements.
- KYE™ Data Mapping Agent™KYE™ Data Mapping Agent™: Sub-engine of the Directory Engine.
- KYE™ Decommissioning PlanKYE™ Decommissioning Plan: Retention windows, off-boarding step sequence, cascade-revocation scope, evidence-archival policy, post-execution verification.
- KYE™ Discoverability Profile™KYE™ Discoverability Profile™: The runtime profile that turns a cryptographically-bound authority graph into a queryable surface, with role-and-purpose…
- KYE™ Discovery Console™KYE™ Discovery Console™: The operator surface over the directory + path finder + risk discovery.
- KYE™ Edge Governance™KYE™ Edge Governance™: Governance that still reaches a verdict when the network does not.
- KYE™ Evidence Finder™KYE™ Evidence Finder™: The resolver over audit-event and evidence-pack indexes.
- KYE™ ExceptionKYE™ Exception: A rule that displaces or modifies another rule under enumerated exceptional conditions (incident response, business continuity, regulatory…
- KYE™ Formal Rules Profile™KYE™ Formal Rules Profile™: The rights, obligations and governance layer of KYE™.
- KYE™ Governance RuleKYE™ Governance Rule: Meta-rule on who may override which rules, under what conditions, with what evidence.
- KYE™ Governed Entity Catalog™ entryKYE™ Governed Entity Catalog™ entry: Discovery entry per governed entity — agent, model, tool, service, connector, app, plugin, profile or certified…
- KYE™ Governed Use Case Library™KYE™ Governed Use Case Library™: Sector-curated library of governed AI use cases linking authority records, gates, commit boundaries, decisions, evidence packs…
- KYE™ GovernedUI™ (Glossary)KYE™ GovernedUI™: The human-facing control layer.
- KYE™ Human Involvement Planner™KYE™ Human Involvement Planner™: Define where authorised humans must review, approve, limit or override AI-enabled actions across the lifecycle.
- KYE™ Human Involvement Plan™KYE™ Human Involvement Plan™: Schema-bound record of points where authorised humans must influence, direct, limit, approve, override or review an AI-enabled…
- KYE™ Memory Engine™KYE™ Memory Engine™: Sub-engine of the Decision Engine.
- KYE™ Native Search Engine™KYE™ Native Search Engine™: Sub-engine of the Directory Engine.
- KYE™ ObligationKYE™ Obligation: Lifecycle object — actor MUST perform a required action by a deadline.
- KYE™ Obligation Ledger™KYE™ Obligation Ledger™: Append-only ledger tracking every obligation lifecycle, hash-chained into the audit ledger.
- KYE™ Obligation StateKYE™ Obligation State: One state-transition record on a KYEObligation .
- KYE™ Onboarding Agent™KYE™ Onboarding Agent™: The guided path from first contact to a working, governed tenant.
- KYE™ Ontology Conformance™KYE™ Ontology Conformance™: Conformance fixture suite + certification track for ontology-correct implementations.
- KYE™ ontology mappingKYE™ ontology mapping: External-system → KYE™ term mapping with mapping_type , confidence.
- KYE™ Ontology Profile™KYE™ Ontology Profile™: The semantic layer of KYE™.
- KYE™ Ontology Registry™KYE™ Ontology Registry™: Managed registry for terms, relationships, mappings and semantic assertions.
- KYE™ ontology relationshipKYE™ ontology relationship: One predicate triple (subject, predicate, object) with constraints + evidence requirements.
- KYE™ ontology termKYE™ ontology term: One canonical term in the registry.
- KYE™ Operating Model Profile™KYE™ Operating Model Profile™: The enterprise adoption layer of KYE™.
- KYE™ PermissionKYE™ Permission: Standing rule that an actor MAY perform a capability under defined scope + state.
- KYE™ PowerKYE™ Power: Authority to create, modify, revoke, waive or override a normative state.
- KYE™ Pre-Action Filter™KYE™ Pre-Action Filter™: Product-friendly synonym for the admission surface in marketing copy.
- KYE™ ProhibitionKYE™ Prohibition: Standing rule — actor MUST NOT perform the prohibited capability.
- KYE™ Proposed ActionKYE™ Proposed Action: The candidate action submitted to KYE™ Admission Gate™ for admissibility check before any authority decisioning.
- KYE™ Provenance & Supply Chain Evidence App™KYE™ Provenance & Supply Chain Evidence App™: Track datasets, models, tools, suppliers, licences and hardware lineage as runtime-bound evidence.
- KYE™ Provenance EvidenceKYE™ Provenance Evidence: Provenance + supply-chain dimension — model / dataset / tool / hardware / supplier / licence references with verification status.
- KYE™ Reconciliation Engine™KYE™ Reconciliation Engine™: The check that what you declared is what you actually deployed.
- KYE™ Reporting Engine™KYE™ Reporting Engine™: Sub-engine of the Evidence Engine.
- KYE™ Rights & Obligations Engine™KYE™ Rights & Obligations Engine™: Runtime engine that evaluates permissions, obligations, prohibitions, powers, exceptions and governance rules.
- KYE™ Rule ConflictKYE™ Rule Conflict: Detected conflict between two or more rules with the resolution strategy applied (e.g., specific overrides general, prohibition overrides…
- KYE™ Rule ProofKYE™ Rule Proof: Test result over a rule set checking enumerated consistency properties.
- KYE™ Rule Prover™KYE™ Rule Prover™: Pre-runtime consistency checker for rule sets — conflicts, unbounded obligations, missing satisfaction paths, circular delegation, override…
- KYE™ Self-Attested™KYE™ Self-Attested™: L2. Signed self-attestation (Ed25519, JWS) bundled with fixture results.
- KYE™ Self-Tested™KYE™ Self-Tested™: L1 of the conformance ladder.
- KYE™ Semantic AssertionKYE™ Semantic Assertion: A signed record bound to a runtime decision listing every term, mapping and predicate consulted.
- KYE™ Semantic Authority Mapper™KYE™ Semantic Authority Mapper™: Maps OAuth scopes, IAM roles, payment mandates, legal delegations, healthcare consents, API permissions and sector terms into…
- KYE™ Semantic Graph™KYE™ Semantic Graph™: Graph view of the ontology + live instances.
- Mapping typeMapping type: Six explicit categories.
- MCPMCP — Model Context Protocol: Tool / agent communication protocol.
- Meta-governance gateMeta-governance gate: §36 §9 (LOCKED). Self-grants ( delegate_authority or modify_own_authority where actor == grantee) are rejected at the PDP gate with…
- MHRA SaMD & AIMHRA SaMD & AI: UK Medicines and Healthcare products Regulatory Agency Software-as-a-Medical-Device regime.
- NIST 800-207NIST 800-207 — Zero Trust Architecture: — Zero Trust Architecture
- NIST AI RMF GOVERN-1.2NIST AI RMF GOVERN-1.2 — Traceability: — Traceability
- Non-goalsNon-goals: Things the protocol explicitly does NOT do — replace SCA, replace tokenisation, run fraud scoring, etc.
- Normative operatorsNormative operators: Compact operator notation.
- OAuth 2.0 / OIDCOAuth 2.0 / OIDC: Human-centric authorisation + identity federation.
- Off-boarding actionsOff-boarding actions: Eight named actions. revoke_authority , quarantine_credentials , rotate_keys , archive_evidence , notify_owner , notify_supplier…
- On-behalf-ofon-behalf-of: The relationship between actor and principal.
- Ontology domainOntology domain: One of twelve domains every KYE™ term must declare.
- OSCALOSCAL — Open Security Controls Assessment Language (NIST): (NIST)
- Payload statePayload state: The lifecycle status of a single payload.
- PCI DSS 6.4.1PCI DSS 6.4.1 — Segregated environments: — Segregated environments
- PDPPDP — Policy Decision Point: The component that evaluates the request against authorities + state + scope and returns a decision.
- PEPPEP — Policy Enforcement Point: The component that intercepts an action and asks the PDP for a decision.
- PredicatePredicate: Stable predicate dictionary.
- PrincipalPrincipal: The entity on whose behalf the actor is acting.
- ProfileProfile: One of 10 canonical conformance profiles — core , pdp , epdp , spdp , pep , runtime-authority , evidence-replay , connector , manifest , conformance .
- Proof bundleProof bundle: The transport format for an evidence pack.
- PSD3PSD3: EU revised Payment Services Directive.
- Purpose Permission™Purpose Permission™: The purpose and scope rail.
- Readiness assessmentReadiness assessment: Multi-dimension assessment plus a readiness score plus the required profiles, gates and evidence for the assessed entity.
- Reports@kyeprotocol.comreports@kyeprotocol.com: The canonical auto-delivery From-address for sealed compliance reports.
- Resilience Loop™Resilience Loop™: The evidence and replay rail.
- Review pathReview path: Multi-step human-review chain with required role, decision options, optional condition and SLA per step.
- RFCRFC: The four-stage process for landing changes.
- Risk-discovery typesRisk-discovery types: Three non-mutating traversals.
- Rule familiesRule families: Six families. permission , obligation , prohibition , power , immunity , exception .
- ScopeScope: The constraint set bounding an authority — amount cap, currency, corridor, time window, beneficiary allowlist, etc.
- SEC 17a-4(f)SEC 17a-4(f) — Records preservation: — Records preservation
- SPIFFE / SPIRESPIFFE / SPIRE: Workload identity for services.
- SR 11-7 §VSR 11-7 §V — Model risk management: — Model risk management
- SR 11-7 §VISR 11-7 §VI — Model inventory: — Model inventory
- StateState: The current lifecycle status of an entity / authority / payload — e.g., active, quarantined, suspended, revoked.
- UK NCSC CAF Principle B6UK NCSC CAF Principle B6 — Staff awareness & training: — Staff awareness & training
- Universal Engagement RailUniversal Engagement Rail: One intake surface for every external party — pilot, partner, trainer, auditor.
- URNURN: The canonical identifier format.
- Use-case intakeUse-case intake: Initial proposal for a delegated AI worker.