---
title: "KYE™ Governed Prompts™ — the prompt is an authority act · KYE Protocol™"
description: "KYE™ Governed Prompts™ deliver Agentic Governance™ with Authority Finality™ at the prompt boundary: every prompt that drives an agent action is governed as an authority act — bound to a purpose, a scope, and a replay-derivable evidence chain — not merely firewalled as input."
url: https://kyeprotocol.com/governed-prompts/
lang: en
source: "KYE Protocol"
---

> KYE™ Governed Prompts™ deliver Agentic Governance™ with Authority Finality™ at the prompt boundary: every prompt that drives an agent action is governed as an authority act — bound to a purpose, a scope, and a replay-derivable evidence chain — not merely firewalled as input.

KYE™ Governed Prompts™

# Agentic Governance™ with Authority Finality™ at the prompt boundary.

A prompt that invokes a tool, generates code that will be committed, or produces a plan that drives the next act _is an authority act_ — it spends authority a principal delegated, within a purpose and a scope. KYE™ Governed Prompts™ govern it as one: emitted before transmission, decided allow / tool-restrict / escalate / refuse, and sealed into a signed, replay-derivable evidence chain. **Prompt-as-authority-act, not prompt-as-input.**

[See the GovernedUI surface](https://kyeprotocol.com/governed-ui/) Integrations vs prompt firewalls

## Two envelopes — before transmission, and after the decision.

Your agents emit two signed envelopes per prompt: one before the model sees it, one after the verdict. A developer wires both with one middleware call.

Before a prompt reaches the model, the emitting agent emits a governance envelope binding the agent, the purpose it serves, the scope it acts within, the target model, the prompt class, a prompt hash (the body never leaves the boundary), and the attached PII categories. The governance decision then emits an outcome envelope — allowed, refused, escalated, or tool-restricted — sealing the act into the attestation chain.

## Integrations — wherever the prompt is transmitted.

- **LangChain wrapper** — wraps LLM / ChatModel calls.
- **OpenAI SDK middleware** — intercepts chat.completions.
- **Anthropic SDK middleware** — intercepts messages.create.
- **Claude Agent SDK hook** — a pre-prompt / PreToolUse hook.
- **MCP intercept** — every tool-call prompt crossing the gateway.

## Versus prompt firewalls — complementary, but a different altitude.

A firewall asks whether the prompt is safe. KYE™ asks whether the agent holds the authority to send it.

Prompt firewalls (Lakera, Robust Intelligence, Cisco AI Defense, NVIDIA NeMo Guardrails) govern the prompt _as input_ — scanning for injection, jailbreaks, and toxicity. KYE™ Governed Prompts™ govern the prompt _as an authority act_ — bound to a purpose, a scope, and a replay-derivable evidence chain. A firewall verdict can feed the governance decision; it does not replace it.

## Govern every prompt your agents send.

KYE™ Governed Prompts™ is a governance projection of [KYE Protocol™](https://kyeprotocol.com/), surfaced through [KYE™ GovernedUI™](https://kyeprotocol.com/governed-ui/). Every operator decision emits a signed [Evidence Pack™](https://kyeprotocol.com/evidence-pack/).

[GovernedUI](https://kyeprotocol.com/governed-ui/) [KYE™ MCP Server™](https://kyeprotocol.com/mcp/)
