---
title: "KYE™ Payment Authorization Authority Agent™ — bounded governed agent · KYE Protocol™"
description: "KYE™ Payment Authorization Authority Agent™ — a bounded, single-purpose KYE™ Governed Agent™ that governed authorize/hold/step-up/decline. It is a first-class principal: authority-bound, evidence-sealed, metered, kill-switched. SKU KYE-AGENT-PAYMENT-AUTH-001, jurisdiction global."
url: https://kyeprotocol.com/governed-agents/payment-authorization-authority-agent/
lang: en
source: "KYE Protocol"
---

> KYE™ Payment Authorization Authority Agent™ — a bounded, single-purpose KYE™ Governed Agent™ that governed authorize/hold/step-up/decline. It is a first-class principal: authority-bound, evidence-sealed, metered, kill-switched. SKU KYE-AGENT-PAYMENT-AUTH-001, jurisdiction global.

KYE™ Governed Agents™ · Payments

# KYE™ Payment Authorization Authority Agent™ — a bounded agent you can defend.

You keep your own systems; KYE Protocol™ governs the one consequential act around them — proving who authorised it, sealing each act as an [Evidence Pack™](https://kyeprotocol.com/evidence-pack/) a regulator can re-derive. That cuts dispute and exam-prep evidence work from days to minutes.

[Start a governed pilot](https://kyeprotocol.com/poc/#tier-PoC-S) [The full Governed Agents™ family](https://kyeprotocol.com/governed-agents/)

Any agent can act. A KYE™-governed agent can be trusted by customers, counterparties, auditors and regulators.

1 · What it governs

## One bounded act, governed authorize/hold/step-up/decline.

governs the consequential payment-authorization decision (authorize / hold / step-up for SCA / decline a payment or payment-initiation) at the action boundary, recording the contestable disposition, bound to PSD2 / PSD3 strong customer authentication (RTS arts. 4-9) and the unauthorised-transaction liability shift (arts. 72-74, 97) plus FCA Consumer Duty. It runs the existing EU Payments governance pack — it does not duplicate it. KYE Protocol™ proves the basis; it does not execute payments, move funds, act as a payment processor or PSP, or run fraud-scoring models.

The Payment Authorization Authority Agent™ does exactly one job under KYE Protocol™ authority, and it is metered (SKU `KYE-AGENT-PAYMENT-AUTH-001`) and stoppable by a kill-switch. Its jurisdiction is global. It is a [first-class principal](https://kyeprotocol.com/agent-native/) — identical in governance weight to any human or system principal.

- **Authority-bound** — it acts only inside its constitution §52 authority binding; an act outside that bound scope is refused and routed, never silently attempted.
- **Evidence-sealed** — each act packs an [Evidence Pack™](https://kyeprotocol.com/evidence-pack/) and seals a Replay-Proof™, verifiable from public keys alone.
- **Metered & kill-switched** — every act is metered under `KYE-AGENT-PAYMENT-AUTH-001` and can be stopped instantly; no act survives a revoked authority.

2 · The end-to-end flow

## Every act, five governed steps.

Whatever the agent does, the act crosses the same boundary, captured as real envelopes against existing protocol schemas. No new schema was minted for this agent — it reuses [Purpose Permission™](https://kyeprotocol.com/mcp/) and the [Evidence Pack™](https://kyeprotocol.com/evidence-pack/).

1. **Admit.** The bounded act crosses the constitution §52 authority boundary; only the agent's allow-listed tools and inputs are admitted.
2. **Decide.** A [Purpose Permission™](https://kyeprotocol.com/mcp/) verdict answers whether this bounded agent may act, as a per-check reason list.
3. **Act.** The agent performs its single-purpose act within the admitted scope — nothing more.
4. **Evidence.** An [Evidence Pack™](https://kyeprotocol.com/evidence-pack/) binds the decision and each act-supporting signal as a signed signal.
5. **Finalise.** A signed Replay-Proof™ seals the act so it re-runs to the same result — Authority Finality™ for the bounded act.

3 · SKU & bound perimeter

## Metered, jurisdictioned, framework-bound.

This agent is one declared SKU with a named regulatory perimeter — reused, never re-mapped. Your team buys the governance, not raw agent capability.

- **SKU** — `KYE-AGENT-PAYMENT-AUTH-001`, metered per governed act.
- **Pricing** — metered per governed act; commercial terms follow the [KYE Protocol™ pricing model](https://kyeprotocol.com/pricing/) (PoC → Pilot → Annual Licence), confirmed during scoping.
- **Jurisdiction** — global.
- **Sector** — Payments.
- **Bound frameworks** — the named regulatory perimeter the agent governs against is stated in full above; KYE Protocol™ maps each governed act to that perimeter and seals the reasonable-steps evidence.

4 · The honest boundary

## It proves the basis — it does not execute the act.

Constitution §0.30 makes agents first-class principals; constitution §32 keeps KYE Protocol™ out of the agent-framework business. This agent lives precisely on that line.

KYE Protocol™ proves the basis for the bounded act; it does not run your screening, scoring, modelling, retrieval, or execution engines. The honest non-goals are stated in full in the agent description above. An act outside the agent's bounded scope is refused and routed, never silently attempted — the refusal is itself evidenced. Read the governing clause on the [agents-as-first-class-principals](https://kyeprotocol.com/agent-native/) page.

5 · Verify it yourself

## Provable from public keys alone.

Every signed envelope this Governed Agent™ emits verifies against the published key set at `trust/self-audit-jwks.json` — the same Ed25519 verification surface KYE Protocol™ uses to audit itself. No credentials, no vendor portal: parse the JSON, canonicalise the payload, and check the signature. The [self-audit](https://kyeprotocol.com/trust-self-audit/) page walks the verifier step by step — turning each governed act into evidence a regulator can re-derive, cutting exam-prep from days to minutes.

[Start a governed pilot](https://kyeprotocol.com/poc/#tier-PoC-S) [Agents as principals](https://kyeprotocol.com/agent-native/)

6 · From evaluation to live

## Three steps to a governed agent in production.

You do not rip out your stack. A KYE Protocol™ engagement governs this one act in stages — each with a signed deliverable you keep.

1. **Pilot.** A paid, fixed-scope [Proof-of-Concept](https://kyeprotocol.com/poc/#tier-PoC-S) delivers a signed Evidence Pack™ for this agent's act on one real workflow — replayable offline by your auditor. 100% of the fee credits against a Pilot or Annual Licence signed within 60 days.
2. **Onboard.** Bind the agent to your stack (SSO, data store, API gateway) and set its constitution §52 authority scope. Commercial terms follow the [KYE Protocol™ pricing model](https://kyeprotocol.com/pricing/); create your workspace at [account setup](https://kyeprotocol.com/account-create/).
3. **Live.** The agent runs as a metered, kill-switched first-class principal under SKU `KYE-AGENT-PAYMENT-AUTH-001` — every act sealed and verifiable from public keys alone. Operate and approve from [GovernedUI™](https://kyeprotocol.com/governed-ui/).

[Start a governed pilot](https://kyeprotocol.com/poc/#tier-PoC-S) [How buyers evaluate KYE Protocol™](https://kyeprotocol.com/buyers/)

More in Payments

## Other governed agents in Payments.

- [**KYE™ Chargeback Evidence Agent™**](https://kyeprotocol.com/governed-agents/chargeback-evidence-agent/) — governed card-dispute evidence.
- [**KYE™ Credit Card Action Authority Agent™**](https://kyeprotocol.com/governed-agents/credit-card-action-authority-agent/) — govern limit/APR/issuance.
- [**KYE™ Settlement Finality Authority Agent™**](https://kyeprotocol.com/governed-agents/settlement-finality-authority-agent/) — governed, final settlement decisions.

[See all 43 Governed Agents™ →](https://kyeprotocol.com/governed-agents/)

Canonical KYE™ surfaces referenced on this page: [KYE Protocol™](https://kyeprotocol.com/) · [Purpose Permission](https://kyeprotocol.com/glossary/).
