Bring your policy engine. KYE Protocol™ proves the authority.

A policy engine answers may this input pass? A regulator asks who authorised this consequential action, was it in scope, and can I replay it? The KYE Policy Resolver™ lets the Policy Decision Point delegate the raw allow/deny to whatever stack you run — Open Policy Agent, Cedar, AWS Verified Permissions or Microsoft AGT — while KYE™ keeps Purpose Permission™, Authority Finality™ and the Evidence Pack™ above it. You drop engine lock-in to zero and keep one replay-provable authority record.

One adapter port, any policy stack

You choose the engine; you keep the authority guarantees fixed. For your platform team, the engine that decides allow or deny is increasingly a commodity; the evidence that satisfies a regulator is not. The Resolver is a single adapter contract — seven engine kinds, one locked decision vocabulary of ten outcomes — so adopting it is a days-long wrap, not a multi-quarter migration.

Try it — switch the engine, watch the authority hold

Pick a policy engine and a consequential action. The raw allow/deny changes with the engine; the KYE™ authority pipeline — purpose checked first, one locked outcome vocabulary, sealed evidence, replay, suspendable finality — does not. This is an illustrative projection of the adapter contract, run entirely in your browser.

What KYE Protocol™ keeps above the engine

For a CISO, the question is not which engine you bought — it is what a regulator can prove a year from now. KYE™ never delegates these five guarantees, whichever engine produced the raw allow or deny.

Your policy engine gives youThe KYE Policy Resolver™ keeps above it
A raw allow / deny on an inputPurpose Permission™ — was the action within the purpose the authority was granted for, checked before the engine is even called?
An evaluation log you must trustReplay-Proof™ — the decision, the raw engine verdict and its mapping are verifiable from public keys alone, in minutes not days
A decision that is hard to revoke mid-flightAuthority Finality™ — authority can be suspended in-flight and the revocation is itself evidenced
One vendor's policy formatDeep mapping to the EU AI Act™, NIST AI RMF, ISO/IEC 42001 and 249-plus frameworks, each tied to the artefact that enforces it
A library you embedA per-adapter kill switch that fails closed to the native deny-by-default floor — no fail-open surprise

Boundary: KYE Protocol™ integrates the policy-as-code layer; it does not replace your engine. OPA, Cedar, AWS Verified Permissions and Microsoft AGT are stacks KYE™ delegates to and records — the way it already consumes Weights & Biases provenance — and turns into authority decisions and replay-verifiable evidence.

Why a resolver, not a replacement

Replacing a working policy engine is a multi-quarter migration no platform team wants; KYE™ asks for none of it.

Start a governed pilot