---
title: "KYE™ Open Access Authority™ — admissibility for agentic access · KYE Protocol™"
description: "KYE™ Open Access Authority™ answers, at the action boundary, whether an agent may legitimately access, rely upon, invoke, cite, or transact with a resource — under its rights and the applicable jurisdiction. The missing layer for agentic systems is not discovery or routing. It is governed admissibility."
url: https://kyeprotocol.com/open-access-authority/
lang: en
source: "KYE Protocol"
---

> KYE™ Open Access Authority™ answers, at the action boundary, whether an agent may legitimately access, rely upon, invoke, cite, or transact with a resource — under its rights and the applicable jurisdiction. The missing layer for agentic systems is not discovery or routing. It is governed admissibility.

# Authority for agentic access

**KYE™ Open Access Authority™** answers the one question that decides whether an autonomous agent should be let through the door: _may this agent legitimately access, rely upon, invoke, cite, or transact with this resource — under its rights, and the jurisdiction that applies?_

As agents operate across APIs, [MCP (Model Context Protocol) servers](https://kyeprotocol.com/mcp/), datasets, services and marketplaces — across borders — the hard problem stops being _discovery_ or _routing_. The missing layer is **governed admissibility**: deciding whether the access _should_ be allowed, and proving it afterwards.

[Start a governed pilot](https://kyeprotocol.com/poc/) [See the MCP server](https://kyeprotocol.com/mcp/)

## The five access verbs

Every agent-to-resource interaction reduces to exactly one of five access actions. The question is always the same, and Open Access Authority™ adjudicates each one against the requesting principal's rights and the applicable jurisdiction.

### Access

Reach or read the resource at all — an API, dataset, knowledge base, or service endpoint.

### Rely upon

Depend on the resource's output as an authority for a downstream consequential action.

### Invoke

Call the resource as a tool that performs work — an MCP server, an action endpoint, a paid API.

### Cite

Reproduce, quote, or attribute the resource's content in the agent's own output — licence-sensitive by nature.

### Transact

Exchange value — purchase, subscribe, or settle against a marketplace or service. The most jurisdiction-sensitive verb.

## Not a router. An adjudicator.

Open Access Authority™ does not discover content, route connections, or proxy bytes. It is a **projection of KYE™'s governed admissibility decision** onto the agent-to-resource access question — the same governed decision, scoped to an access action. Think of it as _OAuth for agentic admissibility_: a standard checkpoint a system calls to ask "is this access authorised?" — and one that frequently, and legitimately, answers **no**.

1. **Identify the principal.** Resolve the requesting agent to exactly one principal in one tenant — agents are first-class principals with their own identity and authority bindings.
2. **Resolve the rights.** What delegation does the principal hold over this class of resource? What contractual or licensing regime governs it?
3. **Resolve the jurisdiction.** Which jurisdiction applies to this principal-and-resource pair, and what happens when the request crosses a border?
4. **Evaluate admissibility.** The decision returns a verdict — allow, deny, or allow only with notice, consent, or minimisation â through KYE™'s existing decision engine, not a parallel one.
5. **Evidence it.** Every decision emits an [Evidence Pack™](https://kyeprotocol.com/evidence-pack/) that is Replay-Proof™ — independently verifiable from public keys alone, so a regulator or counterparty can re-derive the verdict without trusting you.

Boundary: KYE™ governs _whether an agent may access a resource_. It does not run the agent, build the agent, or route its traffic — that is the job of agent frameworks and networks. Open Access Authority™ is the authority layer they call, not a competitor to them. It is part of the [KYE Protocol™](https://kyeprotocol.com/) platform.

## Why this matters across borders

The moment agentic access expands beyond convenience into regulated services — financial products, telemedicine, legal advice, education, pharmaceutical access, insurance, government services — cross-border execution turns into a jurisdiction-conflict and authority problem. The EU AI Act, GDPR, and your sector's regulators each attach obligations to _who may act, where_. An agent that can reach a service in another country is not the same as an agent that is _authorised_ to use it there. Open Access Authority™ is where that distinction is enforced, and evidenced, at the action boundary — not discovered after the fact. For your auditor or regulator, that evidence is the difference between a claim and a proof.

- The EU AI Act, GDPR, DORA and NIST AI RMF each bind _who may act_, not just what is stored.
- Every access decision emits a signed Evidence Pack™ in JSON, replay-verifiable from public keys alone.
- Exactly one jurisdiction resolves per request; cross-border handoffs are evidenced, never silent.

## The Resource Authority Badge™

A resource earns an authority state as it becomes governable for agentic access:

Unverified Authority asserted Authority evidenced Suspended

"Authority evidenced" is the full state: access decisions against the resource emit Evidence Packs™ and are Replay-Proof™ from public keys alone. A change of rights or jurisdiction, or an upstream revocation, moves a resource to "suspended" pending re-assessment.

## Tiers

Start free with a Resource Authority Badge™, or talk to us about a governed pilot. The free tier gives you the access-verb matrix in minutes.

### Resource Authority Badge™

Free

- Declare a resource's access terms
- Access-verb × resource-class matrix
- Jurisdiction applicability summary
- Badge in "authority-asserted" state

### Standard

Annual · by application

- Per-action admissibility across all five verbs
- Jurisdiction-aware decisioning
- Evidence Pack™ per decision
- Badge in "authority-evidenced" state

### Enterprise

Annual · by application

- Multi-tenant, multi-region, cross-border
- Contestability + revocation on access authority
- Regulator-grade replay export
- SLA + named authority owner

Pricing for the paid tiers is shared with qualified applicants on request, in line with KYE™'s closed-registration policy. Start with the free Resource Authority Badge™, or talk to us about a governed pilot.

[Start a governed pilot](https://kyeprotocol.com/poc/)
