KYE™ GovernedUI™

Approve every AI action before it ships.

You see what your agent wants to do. You approve, reject, or edit it. KYE™ GovernedUI™ is your control surface for AI: dashboard, email, Slack, Teams, or mobile.

Recent decisions

Demo data

You learn: What KYE™ decides for each agent action, why (reason code), and who must act. You can: Replay the feed; approve or decline the held decision.

  1. KYE™ policy decision point Accounts-payable agentpayments.transferAllowed

    Accounts-payable agent pays a supplier invoice

    permission_granted

    Pay €412.90 to Paperhouse Supplies (demo), invoice INV-2026-0917

    In-appWebhook

    • accounts_payable.settle
    • kye_decide
  2. KYE™ policy decision point Procurement agentpurchase_order.createNeeds approval

    Procurement agent orders above its approval threshold

    approval_threshold_breach

    Order 40 pallets of packaging film from Kilnworks Supplies (demo), £18,400

    App pushIn-appWebhook

    • procurement.replenish
    • kye_decide
  3. KYE™ policy decision point Clinical summarisation agentrecord.readDenied

    Clinical summarisation agent asks to read records for marketing

    permission_missing

    Read 1,200 patient records to build a marketing list (demo)

    In-appWebhook

    • marketing.outreach
    • kye_purpose_admit
  4. KYE™ policy decision point HR operations agenthr.record.updateDenied

    HR operations agent acts on a revoked delegation

    delegation_revoked

    Change a staff member's contracted hours (demo)

    In-appWebhook

    • hr.contract.administer
    • kye_authority_check
  5. KYE™ policy decision point Research and drafting agentdocument.draftAllowed

    Drafting agent prepares a disclosure letter, with redaction

    permission_granted

    Draft a disclosure letter for matter M-2207 (demo)

    In-appWebhook

    • legal.matter_support
    • kye_decide
  6. KYE™ policy decision point Credit decisioning agentcredit.line.approveDenied

    Credit agent acts outside its jurisdiction

    jurisdiction_unsupported

    Approve a £4,200 credit line for an applicant in the US (demo)

    In-appWebhook

    • lending.adjudicate
    • kye_decide
How this widget is built
Demonstrates
Decision feed
Components
  • Policy decision point (kye_decide)
  • Decision records (kye.decision.record.v1)
  • Approval routing (dual control)
  • Evidence packs
Flow
Each agent action is decided against its chain of authority; approvals go to the delegate who holds the threshold; every outcome is sealed. Architecture diagram
Used on
  • /examples/: On the examples page, with the rest of its scenario.
  • /developers/: The developer portal: what every call returns.
  • /governed-ui/: GovernedUI™: the decisions it shows.
  • /mcp/: The MCP server: the decisions behind its tools.
  • /platform/: The platform: decisions with their chains of authority.
  • /terminal/: The terminal: every decision, replayable.

KYE™ GovernedUI™, stage by stage

Demo data

You learn: How it works, one stage at a time. You can: Run it end to end.

  1. Cross-agent handoff with scope attenuation

    KYE Protocol™

    kye.delegation_chain.v1 + Authority Gate chain-walk guarantee Agent B's authority is always ≤ Agent A's. Visualised in the Authority Scope module.

  2. Authority drift detection

    KYE Protocol™

    kye-drift-detector Worker emits kye.agency_drift.event.v1 for ten drift dimensions (intent / scope / state / payload / timing / frequency / target / semantic / agency / authority). Surfaced live in the Authority Drift…

  3. PDP / ePDP / sPDP admission

    KYE Protocol™

    Production deterministic decision engine, p99 ≤ 30 ms. ActionApproval pre-flights every proposal through it.

  4. WORM audit chain

    KYE Protocol™

    Constitution retention; nine protected tables with append-only triggers. Every approval lands here, single-use enforced.

  5. Replay-proof envelope

    KYE Protocol™

    Constitution deterministic signature. Any verdict re-derivable offline from public material alone.

  6. Regulator-ready exports

    KYE Protocol™

    SR 11-7, EU AI Act Art. 14/15, DORA control mappings. compliance-attestation CI gate enforces 8 of 8 regulated rule packs carry mappings.

How this widget is built
Demonstrates
KYE™ runtime
Components
  • The stages this page describes
Flow
Each stage in order, as the page sets it out. Architecture diagram
Used on

Every decision lands in a WORM (Write-Once-Read-Many) audit chain. A regulator can replay your verdict offline from the public key alone.

Banking-grade · Replay-proof · Multi-channel · WORM-audited · SR 11-7 (Supervisory Guidance on Model Risk Management) / EU AI Act / DORA-aligned

ActionApproval · kye.governedui.action_proposal.v1 live preview

Customer-Support Agent #A41

kye:agent:acme-bank:support:a41

Action issue_refund

Target system payments.acme-bank.com

Payload £420.00 · cust 8841

Risk level high

Approval mode two_person

Policy decision admit_with_human_approval

Authority chain agent ← ops_lead ← bank

Evidence Timeline · kye.governedui.evidence_timeline.v1 replay-proof

Proposed by agent

2026-05-19T10:42:18Z

sig: ed25519:<signed>

Authority chain walked

delegation_depth=2 · scope_ok

Policy evaluated (PDP)

verdict=admit_with_human_approval · p99=22ms

Human approval — awaiting

required: 2 approvers (two_person mode)

Executed or blocked

target=payments.acme-bank.com

Audit sealed (WORM)

retention=7y · replay-proof

What KYE™ GovernedUI™ controls

The product focuses on dangerous moments — not normal UI activity. Twenty critical-action classes, every one a moment where uncontrolled AI execution costs an enterprise meaningful money, regulatory exposure, or customer trust:

  • send_email · send_message · delete_file · export_data · access_sensitive_data
  • update_crm · issue_refund · create_invoice · submit_form · deploy_code
  • switch_traffic · run_sql · modify_policy · approve_workflow · share_document
  • call_paid_api · trigger_payment · change_customer_record
  • delegate_authority · modify_own_authority (meta-governance — )

Every class triggers a signed, replay-proof approval flow with full audit lineage. Locked in the seven governance modules.

Three pillars

See agent authority

Understand who or what is acting, what it can do, and what policy applies. The Entity Passport + Authority Scope widgets show every entity's declared scope, active delegations, and trust posture at a glance.

Control critical actions

Approve, reject, edit, escalate, or require second approval before execution. ActionApproval and Critical Point Review widgets gate every consequential moment with policy-aware human review — from any channel: dashboard, email, Slack, Teams, mobile.

Prove what happened

Replay-proof evidence timelines for every action, policy decision, approval, and outcome. A regulator with the timeline + the public verification key can re-derive every verdict offline — SCITT-receipt equivalent.

How KYE Protocol™ + GovernedUI fit together

KYE Protocol™KYE™ GovernedUI™
Governance brainVisible control surface
Identity, authority, policy, auditApproval, evidence, review, accountability
/v1/* API + Decision Map™Widgets + dashboards + multi-channel approvals
Replay-proof envelopesThe human decisions that produce the envelopes
PDP / ePDP / sPDP admissionThe UI that surfaces the PDP's policy decision to a human

The strengths KYE Protocol™ brings

  • Cross-agent handoff with scope attenuation. kye.delegation_chain.v1 + Authority Gate chain-walk guarantee Agent B's authority is always ≤ Agent A's. Visualised in the Authority Scope module.
  • Authority drift detection. kye-drift-detector Worker emits kye.agency_drift.event.v1 for ten drift dimensions (intent / scope / state / payload / timing / frequency / target / semantic / agency / authority). Surfaced live in the Authority Drift module.
  • PDP / ePDP / sPDP admission. Production deterministic decision engine, p99 ≤ 30 ms. ActionApproval pre-flights every proposal through it.
  • WORM audit chain. Constitution retention; nine protected tables with append-only triggers. Every approval lands here, single-use enforced.
  • Replay-proof envelope. Constitution deterministic signature. Any verdict re-derivable offline from public material alone.
  • Regulator-ready exports. SR 11-7, EU AI Act Art. 14/15, DORA control mappings. compliance-attestation CI gate enforces 8 of 8 regulated rule packs carry mappings.

How to engage

Canonical KYE™ surfaces referenced on this page: KYE Protocol™.