---
title: "KYE Protocol™ — Ontology Profile · semantic authority across systems"
description: "KYE™ Ontology Profile™ is the semantic layer of KYE™ — shared meaning of entities, authorities, capabilities, scopes, states, decisions, evidence, profiles…"
url: https://kyeprotocol.com/ontology/
lang: en
source: "KYE Protocol"
---

> KYE™ Ontology Profile™ is the semantic layer of KYE™ — shared meaning of entities, authorities, capabilities, scopes, states, decisions, evidence, profiles…

KYE™ Ontology Profile™ · v1.0

# Semantic authority, not just permissions.

How KYE™ names entities. Five classes. One URN scheme. Same shape across SDKs, schemas. And the OpenAPI spec.

[Apply for pilot →](https://kyeprotocol.com/pilot-apply/) [Read the docs](https://kyeprotocol.com/docs/)

**KYE™ Ontology Profile™** defines how entities, authorities, capabilities, scopes, states, decisions and evidence relate across systems, sectors and profiles. **Schemas make data valid. Ontologies make data meaningful.**

Plain Q&A

## Plain Q&A

Short questions. Short answers.

- **What is ontology?** How we name things.
- **What is a class?** A kind of entity.
- **How many classes are there?** Five.
- **What is a URN?** A name with five parts.
- **What goes in part one?** The class.
- **What goes in part two?** The trust domain.
- **What goes in part three?** The subclass.
- **What goes in part four?** The local name.
- **Is it open?** Yes. The vocab is open.

Plain take

## Plain take

Five classes. One URN. Same shape, top to bottom.

- Every entity is a URN.
- Every URN has five parts.
- Same names in TypeScript. Same names in Python.
- Same names in the OpenAPI spec.

1 · Where the semantic layer sits

## Schemas. Dictionaries. Taxonomies. Ontology. Graph. Policy. Runtime.

The ontology layer is not a replacement for any of the others. It gives them shared meaning so different systems can agree on what an entity, agent, authority, capability, state, decision or evidence pack actually _is_.

**Dictionaries** Allowed terms. Stable names KYE™ recognises.

**Taxonomies** Parent / child classification of those names.

**KYE™ Ontology Profile™** Semantic relationships between names — what they mean, what they require, what they are _not_.

**Schemas (JSON Schema)** Runtime validation. Bytes on the wire.

**Knowledge graph** Live instances of entities, authorities, decisions.

**Policy engine** Decisions over meaning + state.

**Runtime gateway** Enforcement at the decision point.

**Evidence Pack™** Signed semantic artefact a regulator can replay offline.

2 · The twelve ontology domains

## Every KYE™ term belongs to exactly one domain.

Domains carve the semantic surface so terms cannot drift across categories silently. `delegated_payment_authority` lives in `authority`. `payment_initiation` lives in `capability`. `amount_limit` lives in `scope`. Mappings between domains are explicit.

### entity

Human, org, agent, model, tool, device, dataset, credential, instrument, asset.

### authority

Delegation, mandate, consent, approval, permission, entitlement, licence, power\_of\_attorney.

### capability

payment\_initiation, card\_purchase, data\_access, contract\_signing, tool\_invocation.

### scope

amount\_limit, time\_window, jurisdiction, data\_class, environment, retention\_limit.

### state

entity, authority, delegation, credential, capability, risk, recovery, continuity, discovery, certification.

### decision

allow, allow\_with\_constraints, require\_approval, deny, continuity\_\*.

### evidence

audit\_event, decision\_map, evidence\_pack, payload\_hash, signature, intent\_trace.

### continuity

Drift types and continuity dimensions.

### discoverability

Discovery modes, risk-discovery types, masking classes.

### connector

Connector Profile™ family kinds.

### sector

payments, open\_finance, legal, health, pensions, cyber, critical\_infrastructure, sovereign\_ai, telecom, pharma\_gxp.

### certification

Conformance / certification artefacts.

3 · Mapping types — interactive

## Six explicit mapping types. Including "not equivalent."

Every external-system term mapped into KYE™ declares exactly one mapping type. The runtime enforces it. An OAuth scope may be `related_not_identical` to a delegated payment authority — presenting the scope alone, without the companion authority record, is denied.

When does it apply?

Source and KYE™ term are interchangeable for runtime purposes. Rare in practice; usually only safe within a single trust domain.

**Example:** `oidc_id_token.sub` ≡ `kye:term:entity:human` when both reference the same KYE-issued URN.

**Runtime effect:** presenting either term resolves to the same KYE™ term. No companion object required.

### does not prove the KYE™ term

Overlap exists but the source term . Companion KYE™ objects MUST be presented.

### Example:

OAuth scope ↔ ; companions required: , , , . payments:write kye:term:capability:payment\_initiation KYEAuthorityGrant KYEScope KYEStateSnapshot KYEPolicyDecision

### Runtime effect:

if any companion is missing, deny with reason code . external\_term\_not\_equivalent

When does it apply?

The source term MUST NOT be treated as the KYE™ term. Asserting equivalence is itself a policy violation.

**Example:** `oauth.scope:profile.read` ≠ `kye:term:legal:power_of_attorney`.

**Runtime effect:** deny with reason code `semantic_equivalence_rejected`.

When does it apply?

A label-level alias only — same KYE™ term under a different display name.

**Example:** `"payment mandate"` alias of `kye:term:authority:delegated_payment_authority`.

**Runtime effect:** presenting either resolves identically; no policy gate.

When does it apply?

The source term is a _narrower_ meaning than the KYE™ term.

**Example:** `card_purchase` subsumes the broader `kye:term:capability:payment_initiation` only for card-rail subset.

**Runtime effect:** resolves to the KYE™ term but only within the declared narrow scope.

When does it apply?

The source term is a _broader_ meaning than the KYE™ term.

**Example:** `generic.access` subsumed\_by `kye:term:authority:delegated_payment_authority` — presenting the broad term is insufficient.

**Runtime effect:** require additional KYE™ objects to narrow the resolution; deny if absent.

4 · Schemas (Apache 2.0, public mirror)

## Five normative objects + JSON-LD context. Validated in CI.

- `ontology-profile.json` — KYE™ Ontology Profile™ manifest
- `ontology-term.json` — one canonical term
- `ontology-relationship.json` — (subject, predicate, object) triple with constraints
- `ontology-mapping.json` — external term → KYE™ term mapping with mapping\_type + companion-objects
- `semantic-assertion.json` — decision-bound semantics, hash-chained into the audit ledger
- `jsonld-context.json` — JSON-LD context for semantic interoperability

RDF / OWL export is supported as an optional serialization for research, public-sector. And regulator integrations. KYE™ is JSON-native at runtime and ontology-aware at the semantic layer.

4b · Canonical relationship terms (derived)

## The terms below are derived from `internal`.

Per Constitution (Transitive Update Cascade), this block regenerates automatically when the ontology dictionary changes. The TypeScript + Python SDK vocabulary modules regenerate at the same time. No hand-edit between the markers below — edit the dictionary instead.

- `delegates_to` — Principal A grants authority to act to Principal B within a bounded scope.
- `accountable_for` — Principal is the responsible accountable owner of an actor or workflow.
- `authorised_by` — Action authorised by a specific authority grant.
- `evidenced_by` — Decision evidenced by a specific Evidence Pack™.
- `scoped_to` — Authority grant is scoped to a specific capability set.
- `supersedes` — New authority/policy supersedes a previous one.
- `depends_on` — Object A depends on Object B for resolution.
- `cascades_to` — A change to Object A automatically propagates to Object B in the same commit, per Constitution (Transitive Update Cascade).
- `interacts_with` — Object A engages in bidirectional runtime exchange with Object B (one of the v1.1 typed-edge relationship-map vocabulary; the bidirectional sibling of produces/consumes).

Cascade source: `internal` · Settled by: `scripts/build-ontology-derivative.mjs` · Coverage gate: `cascade-coverage`

5 · Apps that compose this profile

## Four planned apps. Contracts open; engines paid.

What it is. Why it matters. What to do next.

### KYE™ Ontology Registry™

Define and govern terms, relationships, mappings and semantic assertions.

### KYE™ Semantic Authority Mapper™

Map OAuth scopes, IAM roles, payment mandates, legal delegations and healthcare consents into KYE™ without losing meaning.

### KYE™ Semantic Graph™

Graph view of the ontology + live instances; semantic-path search + risk-ranked traversal.

### KYE™ Ontology Conformance™

Conformance fixture suite + certification track for ontology-correct implementations.

6 · Open / paid boundary

## The contracts are open. The semantic engine is paid.

One sentence: a signed, replayable proof of decision.

Open source

### Open

- KYE™ Ontology Profile™ schema
- Term + relationship + mapping + semantic-assertion schemas
- JSON-LD context
- Predicate dictionary + 6 mapping types
- Reason-code dictionary
- Sample terms + sample mappings
- RDF / OWL optional export examples
- Basic conformance fixtures

Commercial track

### Paid

- KYE™ Ontology Registry™ Pro
- KYE™ Semantic Authority Mapper™
- KYE™ Semantic Graph™ engine
- False-equivalence detection engine
- Cross-profile mapping reconciliation
- Sector ontology packs
- Tenant ontology overlays
- Risk-weighted traversal
- Certification workflow

7 · How it strengthens Continuity + Discoverability

## Ontology makes discovery meaningful and continuity portable.

What it is. Why it matters. What to do next.

### + Discoverability

_Without ontology:_ "find all payment permissions." _With ontology:_ "find all **active delegated payment authorities**, including mapped payment mandates, **excluding** ordinary API scopes that do not prove principal authority."

### + Continuity

User says "book travel." Agent interprets "buy airline ticket." Ontology checks whether `book` implies _prepare-only_, _reserve-only_, or _purchase_ authority — preventing intent / authority drift.

### + Evidence

Each runtime decision emits a signed `KYESemanticAssertion`, hash-chained into the audit ledger; a regulator can re-derive what the decision _meant_, not just what it returned.

**KYE™ is JSON-native at runtime, JSON-LD-ready for semantic interoperability, and graph-aware for authority discovery, continuity and evidence.**

Where to go next

## Adjacent reading.

What it is. Why it matters. What to do next.

[Continuity Profile™ →](https://kyeprotocol.com/continuity/) [Discoverability Profile™ →](https://kyeprotocol.com/discoverability/) [Vocabulary →](https://kyeprotocol.com/vocabulary/) [Glossary — ontology entries](https://kyeprotocol.com/glossary/#ontology) [Whitepaper.6](https://kyeprotocol.com/whitepaper/#sec-7-6)

## Ready to see your AI agents flagged?

Start in shadow mode. We’ll deliver your first Evidence Pack™ in 4–8 weeks.

[Apply for pilot →](https://kyeprotocol.com/pilot-apply/) [Try the sandbox →](https://kyeprotocol.com/sandbox/demos/)

Canonical KYE™ surfaces referenced on this page: [Evidence Pack™](https://kyeprotocol.com/evidence-pack/) · [KYE Protocol™](https://kyeprotocol.com/).
