Step 2 · Taxonomies
Sort KYE™ names into parent / child trees.
Step 1 names the things. Step 2 groups them. You get 16 signed taxonomies so an auditor, regulator, or developer can talk about a whole class without listing every member.
Taxonomies, step by step
Demo dataYou learn: What happens at each step. You can: Step through it.
-
Step 1 of 4
KYE Protocol™
Auditors
map side_effect_level values to ISO 42001 controls without re-listing each tool.
-
Step 2 of 4
KYE Protocol™
Regulators
ask for data_class = pii coverage under GDPR Art. 30, and the taxonomy enumerates the leaves.
-
Step 3 of 4
KYE Protocol™
Developers
filter the Signal Bus by signal_family instead of by event name.
-
Step 4 of 4
KYE Protocol™
Operators
set policy on risk_tier bands aligned to NIST AI RMF tiers 1–4.
How this widget is built
- Demonstrates
- KYE Protocol™
- Components
- The steps this page describes
- Flow
- Each step in order, as the page sets it out. Architecture diagram
- Used on
- /taxonomies/: On this page, after its opening.
1 · What ships
Sixteen v1.0 canonical trees.
Each tree is a published JSON file with a stable $id URL. Each value carries a SHA-256 hash. You can cite a class, not a list.
- Entity-class taxonomy
- Capability-family taxonomy
- Side-effect-level taxonomy
- Data-class taxonomy
- Decision-code taxonomy
- Lifecycle-state taxonomy
- Jurisdiction taxonomy
- Sector-namespace taxonomy
- Profile-family taxonomy
- Certification-tier taxonomy
- Risk-tier taxonomy
- Evidence-kind taxonomy
- Signal-family taxonomy
- Action-family taxonomy
- Redaction-class taxonomy
- Oversight-role taxonomy
2 · Why bother
Cite a class, not a list.
A rule that says "deny move_money for tier_3 agents" stays stable as new tools ship. The taxonomy resolves the class for you, so policy authors do not chase every new member.
- Auditors map
side_effect_levelvalues to ISO 42001 controls without re-listing each tool. - Regulators ask for
data_class = piicoverage under GDPR Art. 30, and the taxonomy enumerates the leaves. - Developers filter the Signal Bus by
signal_familyinstead of by event name. - Operators set policy on
risk_tierbands aligned to NIST AI RMF tiers 1–4.
3 · Taxonomy vs ontology
Hierarchy first. Then meaning.
A taxonomy organises terms. An ontology defines how terms relate. KYE™ needs both — taxonomy first, then ontology — so rules stay short and meaning stays explicit.
- Taxonomy says:
card_purchaseis a kind ofpayment_initiation. - Ontology says:
card_purchaseneeds anauthority_grantbound by anamount_limit. - You query the tree to find all kinds of payment. You query the ontology to find what each one needs.
4 · How you wire it in
Three patterns. Two minutes each.
Fetch the JSON. Bind a leaf to a payload field. Validate in CI. The same trees feed your OpenAPI schemas, your webhook filters, and your audit reports.
- Bind a payload field. Constrain
side_effect_levelin JSON Schema 2020-12 to taxonomy leaves only. - Filter a webhook. Subscribe to events where
signal_family ∈ {risk, drift, evidence}. - Report on a class. Group Evidence Packs by
action_familyfor an EU AI Act Annex IV log.
Where to go next
Continue the stack →
Step 3 adds the meaning layer. Step 4 turns the named classes into wire-level JSON contracts.
Ready to see your AI agents flagged?
Start in shadow mode. We’ll deliver your first Evidence Pack™ in 4–8 weeks.
Canonical KYE™ surfaces referenced on this page: Evidence Pack™ · KYE Protocol™.