The protocols carry the call. KYE Protocol™ decides if it is authorised.
Agent frameworks and wire protocols — MCP, A2A, the agent protocols — are the plumbing that moves an agent's calls. KYE Protocol™ sits above that plumbing as the authority layer: it checks every consequential action at the boundary, ties it to a delegated-authority chain, and seals replay-verifiable evidence. When an agent calls a tool over MCP, KYE™ proves who authorised it — cutting an auditor's exam-prep for that action from days to minutes.
The agent-protocol stack, bottom to top
Read it as a layer cake. Each layer below KYE™ is something you bring; the keystone layer is the one the protocols leave out — whether an action is admissible, and the proof that it was.
What each layer does for your agents
Whether you are a builder wiring tools over MCP or a CISO answering for what an agent did, each layer maps to one question — and only the top layer answers the regulator's.
- Models — the frontier LLM that reasons and proposes the next step. What does the agent want to do?
- Agent frameworks + wire protocols — LangChain, CrewAI, OpenAI Agents SDK and Claude Agent SDK orchestrate; MCP and A2A carry the tool calls and inter-agent messages. How does the call travel?
- Infrastructure / runtime — where it executes: cloud, edge, confidential compute, sovereign infrastructure. Where does it run?
- KYE Protocol™ — Authority layer — Action Admissibility™ checks each consequential action at the boundary against a delegated-authority chain and governed approval. Is this call authorised, now?
- Admissible action + evidence — the action proceeds and an Evidence Pack™ with Replay-Proof™ is sealed, verifiable from public keys alone. Can you prove it independently?
MCP and A2A carry the call. KYE Protocol™ decides and proves it.
For a platform team the protocols are converging fast, and that is good — a shared wire format is exactly what the ecosystem needed. KYE Protocol™ is not another wire protocol; it is the authority that rides above whichever one you pick.
| The protocol layer gives you | The KYE Protocol™ authority layer adds |
|---|---|
| MCP — a standard way for an agent to call a tool | Action Admissibility™ — was this specific call allowed at the moment it was made? |
| A2A — a standard way for agents to message each other | A delegated-authority chain — on whose authority, and for what purpose, did the second agent act? |
| A framework's allow / deny policy hook | Replay-Proof™ — verifiable from public keys alone, not trust-the-vendor's-log |
| A transport that moves the call | An Evidence Pack™ that proves the call — tying the action to the EU AI Act™, NIST AI RMF and ISO/IEC 42001 artefact that enforces it |
Boundary: KYE Protocol™ governs agents as principals — identity, authority, evidence — it does not run them and does not compete with MCP, A2A, or the agent frameworks. It consumes their signals and turns them into authority decisions and replay-verifiable evidence. Bring your protocols; KYE™ proves the action.
Why above, not inside the protocol
A policy hook inside one framework binds only that framework; an authority layer above the protocols binds every agent action regardless of which one produced it.
- The EU AI Act™ logging and human-oversight duties bind at runtime — KYE Protocol™ discharges them per action over MCP or A2A, not in an annual review.
- Authority is decided once and proven forever: the same sealed Evidence Pack™ serves the incident responder today and the auditor next quarter.
- Protocols and frameworks will keep changing; the authority record and its public-key Replay-Proof™ do not depend on which one carried the call.