Every KYE Protocol™ term, in plain English.
Every KYE Protocol™ term in plain English. One paragraph per term. Linked to its schema and its dictionary code.
Plain Q&A
Short questions. Short answers.
- What is an entity? A thing that can act.
- What is authority? The right to do a thing.
- What is scope? The size of the right.
- What is state? The status of the entity now.
- What is a rule? A check the engine runs.
- What is a decision? What the engine returns.
- What is evidence? The proof of the decision.
- What is a replay? Running the proof again.
- What is a code? A short name for a rule.
Plain take
Every KYE™ term. One plain English line. Linked.
- One paragraph per term.
- Each term has a code.
- Each code maps to a schema.
- Each schema has tests in CI.
Identity, authority, and the chain.
What it is. Why it matters. What to do next.
kye:<class>:<trust-domain>:<subclass>:<local>. Stable, namespaced, human-readable. Defined in public/id-format/.payment.initiate, data.read. Capabilities are first-class with their own schemas.Decision, enforcement, cascade.
What it is. Why it matters. What to do next.
allow_with_constraints, require_approval, deny. Stable across versions. mappable to your own code-set via the conformance pack.kye.report.v1 envelope (3 / month / email); unlimited on paid pilot.kye:purpose-permission:supplier-payment:eur-up-to-100k + kye:delegation:cfo — enforceable by reference to bytes rather than inferred from vendor logs. Underpins the Legal Pack™ (KYE-SECTOR-LEGAL-001). See the Legal sector page.Audit chain, packs, replay.
What it is. Why it matters. What to do next.
public/vocabulary/payload-states.md.Decision values, drift types, evidence pack.
Terms introduced by KYE Continuity Profile™ (kye-continuity-v1). Names only. detection algorithms and scoring weights are part of the normative specification and proprietary and are not published.
continuity_preserved, continuity_degraded and continuity_broken. Companion continuity_score is a numeric scalar; the specific range, weighting and threshold construction are proprietary and are not disclosed in this repository.intent_drift, authority_drift, scope_drift, state_drift, capability_drift, execution_drift, incentive_drift, oversight_drift, evidence_drift, delegation_drift. Detection rules are not published.kye.agency_drift.detected signal on the KYE Signal Bus™.Directory, path finder, risk discovery.
Terms introduced by KYE Discoverability Profile™ (kye-discoverability-v1). Names only. graph-traversal mechanisms and pruning rules are proprietary and are not published.
directory_lookup, path_finder, graph_walk, risk_discovery, connector_discovery, evidence_finder.stale (under-exercised authority), over_permissioned (granted scope exceeds observed exercise), pre_revocation_blast_radius (downstream set that would be quarantined if a target authority were revoked).Four new sub-engines.
Sub-engines introduced 2026-05-17 under the locked 10-engine inventory (§14). Names + observable contracts only. Algorithms, anchor predicates, sort rules, sampling rules, retention-derivation rules, projection maps, and render-determinism constructions are part of the normative specification and proprietary and are not disclosed in this repository.
kye.data_flow_graph.v1 envelope replayable offline from the per-tenant signing-key registry. Powers the Data Mapping Widget. Mechanism is proprietary and is not disclosed in this repository.kye.search_result.v1 envelope replayable offline from the per-tenant signing-key registry. CLI: kye search. Mechanism is proprietary and is not disclosed in this repository.kye.agent_memory.v1 records. CLI: kye memory put / recall. Mechanism is proprietary and is not disclosed in this repository.kye.report.v1 envelope replayable offline. CLI: kye report. Mechanism is proprietary and is not disclosed in this repository.report_delivery_preferences table accepts opt-in subscriptions; each delivery emits a signed kye.report.delivery.v1 receipt to the WORM report_deliveries table.Semantic layer — shared meaning, not just permission.
Terms introduced by KYE Ontology Profile™ (kye-ontology-v1). Names only. semantic-resolution algorithms, false-equivalence detection heuristics, cross-profile reconciliation, tenant-overlay resolution and risk-weighted ontology traversal are proprietary and are not published.
entity, authority, capability, scope, state, decision, evidence, continuity, discoverability, connector, sector, certification.grants, requires, constrains, evidenced_by, acts_on_behalf_of, equivalent_to, related_not_identical, not_equivalent_to.equivalent, related_not_identical, not_equivalent, aliased_by, subsumes, subsumed_by. A mapping of related_not_identical MUST list requires_additional_kye_objects.ontology-term.json.(subject, predicate, object) with constraints + evidence requirements. Schema. ontology-relationship.json.mapping_type, confidence. And (for related_not_identical) the list of companion KYE™ objects required at runtime. Schema. ontology-mapping.json.semantic-assertion.json.https://kyeprotocol.com/schemas/jsonld-context.json. KYE™ is JSON-native at runtime and ontology-aware at the semantic layer.Adoption layer — from readiness to runtime control.
Terms introduced by KYE Operating Model Profile™ (kye-operating-model-v1). Names only. readiness scoring, risk tiering, side-effect classification, commit-boundary detection, authority-gate recommendation and runtime gate-enforcement internals are proprietary and are not published.
intake, assess, classify, map_authority, place_gates, configure_runtime, execute, evidence, review, improve.use-case-intake.json.readiness-assessment.json.entity-authority-record.json.payment_execution, external_message, contract_signature, clinical_action, infrastructure_command, data_export, credential_rotation, evidence_export.review-path.json.adoption-evidence-pack.json.Living lifecycle assurance — system cards become executable.
Terms introduced by KYE Assurance Card Profile™ (kye-assurance-card-v1). Names only. assurance-card generation, runtime-evidence binding, review-automation, sector packs and use-case library recommendation algorithms are proprietary and are not published.
assurance-card.json.design, pilot, deploy, monitor, incident_review, scope_change_review, retention_review, decommission.influence, direct, limit, approve, override, review.provenance-evidence.json.scheduled, scope_change, new_capability, incident, risk_state_change, model_update, authority_change, supplier_change, licence_change, retention, decommission.decommissioning-plan.json.revoke_authority, quarantine_credentials, rotate_keys, archive_evidence, notify_owner, notify_supplier, update_catalog, remove_from_runtime.Rights, obligations, prohibitions, powers — enforceable.
Terms introduced by KYE Formal Rules Profile™ (kye-formal-rules-v1). Names only. rule-conflict-detection algorithms, rule-proof internals, rule-compilation engine, contract-to-authority extraction and sector-rule-pack content are proprietary and are not published.
permission, obligation, prohibition, power, immunity, exception. Plus meta_governance recorded under KYEGovernanceRule.P (may), O (must), F (must not), Pow (has authority to), Imm (cannot be altered by), Ex (displaced by, in conditions).permission.json.pending · satisfied · breached · waived · expired · disputed · remediated · superseded. Schema. obligation.json.prohibition.json.power.json.exception.json.governance-rule.json.rule-conflict.json.rule-proof.json.KYEObligation. Append-only. the chain of these records IS the obligation lifecycle. Schema. obligation-state.json.Pre-action layer — before authority.
Terms introduced by KYE Action Admissibility Profile™ (kye-action-admissibility-v1). Names only. admissibility-scoring algorithm, prohibited-action-class detection heuristics, intent-ambiguity detection, source / data admissibility decision rules, agent-proposal quarantine triggers and sector admission packs are proprietary and are not published.
proposed-action.json.admit, reject, require_clarification, require_human_review, quarantine, route_to_authority_check.invalid_intent, ambiguous_intent, out_of_scope_proposal, prohibited_action_class, disallowed_data_source, inadmissible_evidence, unsafe_tool_path, coercion_signal, incentive_conflict, continuity_break, policy_ineligible_action, missing_authority_context, missing_principal, missing_accountable_owner, unsupported_jurisdiction.admissibility-decision.json.admissibility-evidence.json.Mapping rail, OSCAL, frameworks.
Maps to SOC 2, ISO 27001, ISO 42001, OSCAL. One pack, four checks.
core, pdp, epdp, spdp, pep, runtime-authority, evidence-replay, connector, manifest, conformance. Sector specialisation comes from 57 rule packs + 49 sector packs, not from profile forks.Conformance, certification, partner ladder.
What it is. Why it matters. What to do next.
Regulator terms KYE™ binds, by framework.
The clauses, articles, and sections KYE™ artefacts satisfy — one line per term, with the KYE™ binding named. Use this when a procurement form asks "does your platform handle Annex III?" or an auditor cites SR 11-7 §V.
data_flow_graph.v1 + signed mitigation plan, audit-chained.transparency_log.v1 with proof-of-disclosure per call.kye.guard_recommendation.v1 envelope.kye.implementation_registry.v1 + per-model assurance card.kye.lawful_basis.v1 envelope automatically attached to every cross-border call.data_use_manifest.v1 with DPIA flag; signed when high-risk.operating_model.v1 with replay-proof envelope.For reference, not redefinition.
What it is. Why it matters. What to do next.
KYE GovernedUI™ — the visible control layer.
Constitution §36. The protocol decides; you approve, evidence, and audit. Eleven canonical modules across two suites.
kye-drift-detector Worker (ten dimensions: intent, scope, state, payload, timing, frequency, target, semantic, agency, authority). Emits kye.agency_drift.event.v1.none, single_approver, two_person, two_person_with_legal, delegated, auto (forbidden at high+ risk).delegate_authority or modify_own_authority where actor == grantee) are rejected at the PDP gate with reason_code: meta_governance_violation. No human approval can override; the break-glass flow is separately audited.§0 red-line rules.
Four foundational rules. Adopted 2026-05-14 + 2026-05-15. Every shipped surface, schema, runtime. And conformance claim conforms. CI gates enforce each red line.
- §0 — Zero Competing Systems.
- Every concept appears exactly once. No parallel definitions across runtime, build, deploy, dashboard, admin, customer-facing, documentation, CI, CD. CI gate
competing-systems-scan. - Zero Repo↔Prod Drift.
- Every commit on
mainreaches production within minutes. Production state mirrorsorigin/main. Push-triggered deploys mandatory. - Zero Stubs / Placeholders / Mocks.
- Every shipped surface is production-grade, enterprise-grade, banking-grade, and 100% conformant with declared frameworks (SR 11-7, DORA, EU AI Act, ISO 42001, NIS2, HIPAA, PSD3, SOC 2, BCBS 239). No TODO / FIXME / "coming soon" / mock data in production paths. CI gate
no-stubs-placeholders-mocks. - Self-Governance + Canonical-First.
- Every privileged action governed by the KYE Governance Engine™ (Purpose Permission™ + Decision Engine™). Every shipped framework claim attested by the KYE Compliance Engine™ with a control row + ≤ 90-day attestation. No
kye.<ns>.*reference may precede its canonical declaration in schemas / vocabulary / constitution. CI gatecanonical-first.
Adjacent reading.
What it is. Why it matters. What to do next.
Ready to see your AI agents flagged?
Start in shadow mode. We’ll deliver your first Evidence Pack™ in 4–8 weeks.