Bring your policy engine. KYE Protocol™ proves the authority.
A policy engine answers may this input pass? A regulator asks who authorised this consequential action, was it in scope, and can I replay it? The KYE Policy Resolver™ lets the Policy Decision Point delegate the raw allow/deny to whatever stack you run — Open Policy Agent, Cedar, AWS Verified Permissions or Microsoft AGT — while KYE™ keeps Purpose Permission™, Authority Finality™ and the Evidence Pack™ above it. You drop engine lock-in to zero and keep one replay-provable authority record.
One adapter port, any policy stack
You choose the engine; you keep the authority guarantees fixed. For your platform team, the engine that decides allow or deny is increasingly a commodity; the evidence that satisfies a regulator is not. The Resolver is a single adapter contract — seven engine kinds, one locked decision vocabulary of ten outcomes — so adopting it is a days-long wrap, not a multi-quarter migration.
- Open Policy Agent — KYE™ marshals your request into an OPA input document, evaluates the Rego bundle in-process via WASM, and seals the raw verdict for replay. You keep your Rego.
- Cedar — your decision becomes a Cedar authorization request (principal, action, resource, context) and the Allow/Deny maps back to a KYE™ outcome. You keep your Cedar policies.
- Cerbos — your request becomes a Cerbos CheckResources call against your YAML policy bundle, and the EFFECT_ALLOW/EFFECT_DENY maps back to a KYE™ outcome with the raw verdict sealed for replay. You keep your Cerbos policies.
- AWS Verified Permissions — the managed Cedar service is called over a remote transport with a 250 ms hard timeout; the same adapter shape, no re-write. You keep your AWS policy store.
- Microsoft AGT — an agent-authorization policy query maps to a KYE™ outcome, folded into the signed decision. You keep your Microsoft control point.
- Native reference — the in-tree evaluator ships working with zero dependencies, and is the safe fallback the moment any external adapter is killed. You always have a floor.
Try it — switch the engine, watch the authority hold
Pick a policy engine and a consequential action. The raw allow/deny changes with the engine; the KYE™ authority pipeline — purpose checked first, one locked outcome vocabulary, sealed evidence, replay, suspendable finality — does not. This is an illustrative projection of the adapter contract, run entirely in your browser.
What KYE Protocol™ keeps above the engine
For a CISO, the question is not which engine you bought — it is what a regulator can prove a year from now. KYE™ never delegates these five guarantees, whichever engine produced the raw allow or deny.
| Your policy engine gives you | The KYE Policy Resolver™ keeps above it |
|---|---|
| A raw allow / deny on an input | Purpose Permission™ — was the action within the purpose the authority was granted for, checked before the engine is even called? |
| An evaluation log you must trust | Replay-Proof™ — the decision, the raw engine verdict and its mapping are verifiable from public keys alone, in minutes not days |
| A decision that is hard to revoke mid-flight | Authority Finality™ — authority can be suspended in-flight and the revocation is itself evidenced |
| One vendor's policy format | Deep mapping to the EU AI Act™, NIST AI RMF, ISO/IEC 42001 and 249-plus frameworks, each tied to the artefact that enforces it |
| A library you embed | A per-adapter kill switch that fails closed to the native deny-by-default floor — no fail-open surprise |
Boundary: KYE Protocol™ integrates the policy-as-code layer; it does not replace your engine. OPA, Cedar, AWS Verified Permissions and Microsoft AGT are stacks KYE™ delegates to and records — the way it already consumes Weights & Biases provenance — and turns into authority decisions and replay-verifiable evidence.
Why a resolver, not a replacement
Replacing a working policy engine is a multi-quarter migration no platform team wants; KYE™ asks for none of it.
- You keep your Rego, your Cedar, your AWS policy store — the Resolver wraps them, it does not rewrite them, so adoption is days not months.
- Every raw verdict is mapped through one locked decision vocabulary, so the same auditor reads an OPA decision and a Cedar decision the same way.
- The external engine can change next year; the sealed authority record and its public-key proof do not depend on which engine produced them.