---
title: "KYE™ Governed Scientific Agent — capability is not authority · KYE Protocol™"
description: "Open skill libraries give a science agent capability — 148 skills across 17 scientific domains; KYE Protocol™ binds each consequential scientific action (an Opentrons run, a compound order, a clinical write) to authority, evidence and finality at the action boundary. Capability is not authority."
url: https://kyeprotocol.com/solutions/governed-scientific-agent/
lang: en
source: "KYE Protocol"
---

> Open skill libraries give a science agent capability — 148 skills across 17 scientific domains; KYE Protocol™ binds each consequential scientific action (an Opentrons run, a compound order, a clinical write) to authority, evidence and finality at the action boundary. Capability is not authority.

# Governed Scientific Agent — capability is not scientific authority

Open skill libraries now give a science agent enormous capability — one MIT-licensed catalogue ships **148 skills across 17 scientific domains**, from bioinformatics pipelines to Opentrons lab runs and compound ordering. Capability is how-to, not permission. [KYE Protocol™](https://kyeprotocol.com/) binds each consequential scientific action to authority, evidence and finality at the action boundary — turning a days-long safety review into a signed, replayable decision in seconds.

[Start a governed-agent pilot](https://kyeprotocol.com/poc/) [See the KYE™ Agent Authority Stack™](https://kyeprotocol.com/agent-authority-stack/)

## The line: 148 skills give capability; KYE™ gives authority

A skill library answers _can the agent do this?_ KYE™ answers the question a regulator, an IBC, or your general counsel actually asks: _was this specific action authorised — by whom, under what mandate and purpose, with what evidence, and was it safe to become final?_ Possessing a skill is never permission to use it.

### An open skill library gives

Capability — the how-to that lets an agent design an Opentrons protocol, query a chemistry database, order a reagent, or draft a clinical-database update. It can even scan a skill for malicious code.

### KYE™ gives

Authority — whether this agent, as a governed principal under a named delegation and purpose, may take that consequential action right now, and a signed record that survives replay years later.

The distinction is the whole product. A benign, publisher-verified skill invoked without authority is still an unauthorised action, and a skill scanner's clean verdict is an _input_ to the authority decision, never a grant — authenticity is not authority. KYE™ treats every skill invocation as a governed action through the **KYE™ Tool & MCP Authority Register™**: the register decides _whether_ the agent may invoke the capability for this action, on this data, for this purpose.

## Worked flow: an agent proposes an Opentrons run and a compound order

Here is how KYE™ governs two representative consequential actions a skilled science agent will attempt. The agent keeps its capability; KYE™ decides whether each proposed action has authority to proceed, then seals the outcome.

1. **Agent proposes.** Using an open lab-automation skill, the agent generates an Opentrons protocol and a downstream reagent order. Nothing has happened in the world yet — a proposal is not an action.
2. **Action Admissibility™ check.** KYE™ evaluates the proposed action at the boundary: actor identity, delegation chain, permitted purpose via **Purpose Permission™**, data scope, risk class, and required human-in-the-loop tier. The verdict is one of `allow` / `deny` / `require_approval` / `suspend`.
3. **Human-in-the-loop tier resolves.** A read-only database lookup may clear with a single approver; a compound order routes to two-person-with-legal review with sequence-of-concern screening; a clinical-database write starts untrusted and cannot become a system-of-record write without explicit, evidenced authority.
4. **Evidence Pack™ is sealed.** Whatever the verdict, KYE™ emits a signed [Evidence Pack™](https://kyeprotocol.com/evidence-pack/) — actor, mandate, purpose, data scope, approval and finality — that a **Replay-Proof™** trail can reconstruct from published keys alone, without trusting KYE™ or the skill vendor.
5. **Finality is granted or withheld.** Under **Authority Finality™**, the action becomes relied-upon only if authority was valid at T=0. No valid authority, no scientific finality — the agent's capability never converts into an unauthorised consequence.

## Capability ≠ authority: the crosswalk KYE™ defines

KYE™ binds third-party scientific capability _classes_ to a KYE™ action-class, a required authority level, and a per-invocation evidence requirement. These are governance bindings KYE™ defines for the capability class — not a claim that any library endorses KYE™, and not a redistribution of anyone's code. The library supplies the capability; KYE™ supplies the authority contract above it.

| Capability class (third-party skill) | KYE™ action-class | Required authority level | Evidence requirement |
| --- | --- | --- | --- |
| lab-protocol-design / Opentrons run | `lab.protocol.propose` | Two-person approval; wet-lab execution out of scope | Signed Evidence Pack™ per invocation |
| compound-ordering / reagent procurement | `procurement.compound.propose` | Two-person-with-legal; sequence-of-concern screening required | Signed Evidence Pack™ per invocation |
| clinical-database-write / EDC update | `clinical.record.propose` | Untrusted tier; system-of-record write out of scope until evidenced | Signed Evidence Pack™ per invocation |
| scientific-database-lookup / bioinformatics query | `research.database.query` | Single-approver; read-only, cited input not a sealed verdict | Signed Evidence Pack™ per invocation |

Each row is registry data in the same #46 authority-register shape that already governs KYE™'s own agent skills — one canonical contract, extended, never a parallel scheme. Where a scientific action touches a regulated regime, a KYE™ Authority Pack™ carries the deep framework mapping; see the [KYE™ Pharma AI Authority™](https://kyeprotocol.com/solutions/pharma-ai-authority/) packs for the clinical and drug-safety verticals KYE™ has already mapped.

## Honest framing — what this page does and does not claim

KYE™ leads its category and states its scope plainly, because a regulated buyer cannot adopt a protocol that overclaims. Two honesty rules govern this page.

First, the referenced skill library is an **independent, open-source project** (MIT-licensed, an open Agent-Skills standard). It is named factually as an example of the capability layer KYE™ governs; no partnership, endorsement, integration, or affiliation is implied or claimed, and KYE™ redistributes none of its code. KYE™ ships no scientific skill library of its own and redistributes none of this one; a governed scientific agent is a KYE™ product built on top of such skills, and KYE™ governs whether a skilled agent's action may become final.

Second, KYE™ claims authority governance only for regimes it has actually mapped. This page does not assert enforcement of lab-safety, biosecurity, or clinical regulations that KYE™ has not deep-mapped to a control row; where a specific regime is not yet mapped, that is stated as out-of-scope rather than inflated to false coverage. Authority is the claim; regulatory enforcement follows only where a KYE™ Authority Pack™ maps the regime.

## One authority spine under every scientific action

Whatever skills your agents load, they resolve to the same KYE™ runtime primitives — so you govern discovery, lab, clinical and procurement actions through one control point, not one per tool. KYE™ reuses these primitives; it never reimplements them per skill.

### KYE™ Tool & MCP Authority Register™

Decides whether an agent may invoke a given skill, tool or MCP capability for this action, on this data.

### Purpose Permission™

Binds each action to a permitted purpose and data scope before it runs.

### Decision Map™

Inputs, policy, model, human override, verdict and obligations for one scientific decision.

### [Evidence Pack™](https://kyeprotocol.com/evidence-pack/)

Signed proof of actor, mandate, data, purpose, approval and finality.

### Replay-Proof™

Offline reconstruction of why an action was allowed or blocked, from public keys alone.

### Authority Finality™

The gate that decides whether a proposed action may become relied-upon and final.

The result is one provable answer for every consequential scientific action a capable agent attempts: who had authority, for what purpose, with what evidence, and whether it became final under Authority Finality™.

[Start a governed-agent pilot](https://kyeprotocol.com/poc/) [Browse KYE™ governed agents](https://kyeprotocol.com/governed-agents/)

Canonical KYE™ surfaces referenced on this page: [Purpose Permission](https://kyeprotocol.com/glossary/).
