EC-Council ADG ↔ KYE Protocol crosswalk

ADG defines what controls. KYE proves which actions met them.

EC-Council ADG (Adopt · Defend · Govern, 2026) names three pillars, nine governance surfaces, twelve minimum controls (MC-1..MC-12), and three autonomy tiers (HITL / HOTL / HOOTL). It is an operating-model framework — it tells an organisation what controls to operate. KYE Protocol is the runtime authority layer beneath it — it proves a specific action was authorised, admissible, evidenced, and final. The two stacks are complementary, not competing. This page is the analyst-grade crosswalk: every ADG surface and every MC-1..MC-12 control mapped to the KYE Minimum Authority Control (KAC) and canonical evidence schema that materially discharges it at runtime.

Positioning

Complementary stacks — distinct accountability layers.

StackLayerUnit of accountabilityBuyer-facing artefact
EC-Council ADGOperating modelControl declarationFramework adoption attestation
KYE ProtocolRuntime authorityAction admissibility + evidencePer-action Replay-Proof envelope

A regulator-grade deployment runs both: ADG as the operating frame, KYE as the per-action runtime proof. ADG without KYE relies on after-the-fact log scraping to prove the control held. KYE without ADG ships a runtime authority layer without the operating-model frame that puts it in the board pack.

The nine ADG governance surfaces

Surface → KYE primitive.

ADG surfaceKYE primitiveKACCanonical schema
Identity surfaceVerified EntityKAC-1entity.json + kye.governedui.entity_passport.v1
Tools & MCP RegisterKYE Tool & MCP Authority RegisterKAC-4kye.tool_mcp_register.v1
Agentic orchestrationChain of AuthorityKAC-3kye.federation.cross_org_delegation.v1
Runtime monitoringEvidence Pack + drift signalKAC-7kye.evidence.pack.v1 + kye.signal.drift.detected.v1
Incident response / forensic replayReplay ProofKAC-8kye.evidence.trace_replay_spec.v1
Decision rights / authorityAuthority FinalityKAC-9kye.estate.authority_finality.v1
Lifecycle / revocationRevocation + expiry controlKAC-10kye.purpose.grant.v1 + kye.purpose.admissibility.v1
Human oversightGovernedUI critical-point reviewKAC-11kye.governedui.critical_point_review.v1
Assurance / certificationKYE SealKAC-12kye.compliance.attestation.v1
ADG minimum controls MC-1..MC-12 ↔ KAC-1..KAC-12

Same twelve. KYE materially enforces them.

ADG MCTitleKACCoverage on KYE
MC-1Verified entity / identity registerKAC-1 Entity Registryenforced
MC-2Delegation envelopeKAC-2 Delegation Envelopeenforced
MC-3Chain of authority across organisationsKAC-3 Chain of Authority Mapenforced
MC-4Action-class declaration / scopeKAC-2 + KAC-5 (admissibility scope)enforced
MC-5Admissibility floorKAC-5 Action Admissibility Gateenforced
MC-6Runtime policy resolutionKAC-6 Runtime Policy Resolutionenforced
MC-7Tools & MCP registerKAC-4 Tool & MCP Authority Registerenforced — pilot SKU live
MC-8Revocation + expiry controlKAC-10 Revocation and Expiry Controlenforced
MC-9Evidence capture per actionKAC-7 Evidence Capture at T=0enforced
MC-10Forensic replay capabilityKAC-8 Replay Proofenforced
MC-11Decision rights / authority terminalityKAC-9 Authority Finality Recordenforced
MC-12Human oversight + critical-point reviewKAC-11 Human Oversight and Escalationenforced
Autonomy tiers

HITL / HOTL / HOOTL ↔ A0 / A1 / A2 / A3.

ADG names three autonomy tiers. KYE Autonomy Tiers compresses to four so that the runtime-controls floor is unambiguous. See /autonomy-tiers.html for the per-tier control matrix.

ADG tierKYE tierKYE requiredKAC floor
(n/a)A0 Human-onlynonone
HITLA1 AssistoptionalKAC-1
HITL / HOTLA2 Scoped delegationyesKAC-1, 2, 4, 5, 6, 7, 8, 10, 11, 12
HOOTLA3 Autonomous with Authority FinalityyesKAC-1..KAC-12 (all twelve)
Deep-mapping coverage

35 ADG requirements → KYE canonical artefacts — bijection enforced.

The full requirement-by-requirement deep mapping lives at /compliance/ec-council-adg.html, generated from internal on every build. Every cited kye.<ns>.*.v1 schema MUST resolve to a canonical declaration on disk; the framework-coverage-bijection gate fails the merge if anything drifts. Honest coverage breakdown: 22 enforced / 11 designed / 2 advisory / 0 out-of-scope (63% enforced; the runtime-authority surface where KYE's wheelhouse sits is enforced wall-to-wall, with deployer-side operating-model concerns honestly marked advisory).

Same twelve controls. ADG declares them. KYE proves them.

A regulator-grade deployment runs both stacks. The crosswalk is the analyst-grade artefact that lets a CISO, regulator, or auditor see which KYE primitive discharges which ADG control without translation.