AgentGovernanceSDKby KYE Protocol™ · an instrument of agent authority
Whereas capability is not authority —

An agent should arrive with its governance already signed.

Most teams bolt governance onto a working agent and discover the retrofit never holds. This SDK executes the opposite order: identity declared, authority bound, every consequential action admitted before it runs, every outcome sealed — governance as the execution path, not a wrapper around it. The result is an agent your compliance team can counter-sign.

Schedule A — what every governed action carries

Eight fields, answered for every consequential act

A capability without these answers is a liability with a demo. The schedule below is what the SDK enforces per action — and what an auditor reads back.

FieldThe question it closesEnforced
PrincipalWhich declared identity is acting — an agent as a first-class principal, never an anonymous process.✓ at construction
AuthorityUnder whose delegation, within which purpose scope and limits.✓ bound, kill-switched
AdmissionWas this specific action decided before it ran — deny fails closed with a routed refusal.✓ pre-execution
ApprovalWhich acts need a human counter-signature, and from whom.✓ threshold-routed
EvidenceWhat sealed proof each outcome leaves — success and refusal alike.✓ per action
AuditCan the whole run be replayed and verified from public keys alone.✓ replay-stable
ExceptionWhat happens when the engine is unreachable — the verdict path never fails open.✓ fails closed
RollbackHow a bad action is unwound, and who is notified.✓ evidenced
Articles I–V — the order of execution

Declare · Bind · Admit · Act · Attest

Declaration of identity

The agent is born with canonical identity and a declared class — registered, discoverable, revocable.

Binding of authority

Purpose scope, tool allow-list, spend and data limits attach at construction and cannot be shed at runtime.

Admission of actions

Every consequential action is decided by the real engine before its body executes. Your logic stays yours; the boundary is not negotiable.

Performance

The agent does its work on whatever framework you already use — the SDK governs it, and deliberately is not another framework.

Attestation

Every outcome seals evidence; the run as a whole is auditable, replayable, and provable offline.

Proviso. This SDK governs agents as principals — identity, authority, evidence. It does not run agents, does not replace your agent framework, and claims no regulation it has not mapped. What it makes defensible is whichever framework you already chose.
Executed by construction, attested per action — KYE Protocol™, Authority Finality™.
Recital B — the parties

Who executes this instrument

The enterprise

Deploys the agents

You answer for what they do. This SDK makes the answer pre-written: every consequential act arrives with its authority, approval, and evidence attached.

The compliance team

Counter-signs

Schedule A is your review checklist rendered executable — eight fields enforced per action instead of promised per policy.

The platform builder

Ships governed by default

Your framework stays; the boundary comes from the SDK. "Enterprise-ready" stops being a slide and becomes a construction property.

Recital C — the consideration

What each party receives

Sign-off in days, not quarters. The retrofit audit disappears — governance was the execution path from the first line.

Incidents become bounded. A misbehaving agent hits a kill-switched binding and a fails-closed boundary, not a postmortem.

Every run is replayable. Auditors verify from public keys alone; nobody reconstructs intent from logs.

No framework migration. The SDK governs whichever agent stack you already chose — it deliberately is not another one.

Specimen 1 — an act, counter-signed

What one governed act looks like on paper

Sample instrument — illustrative names, the real fields Schedule A binds.

Record of consequential act · payment-triage.v1
ActcloseAlert(#4471) — customer-impacting
Principalagent, bound to compliance-ops delegation
Admissionallowed · purpose in scope · limits held
Approvalcounter-signed — senior analyst, pre-execution
Evidencesealed · replayable from public keys
Executed by construction, attested per action.Approved
Recital D — economy of the instrument

Return, traced to clauses

The retrofit audit never happens. Governance bolted on after the fact is re-reviewed on every change; governance as the execution path is reviewed once, at Schedule A.

Incident cost is bounded ex ante. Kill-switched bindings and fail-closed boundaries convert a would-be postmortem into a refused, evidenced act.

Evidence collection costs zero marginal effort. It is a by-product of execution — the auditor's request is a replay, not a project.

No framework spend is stranded. The SDK governs the stack you already run; nothing is migrated to adopt it.

Schedule B — against alternatives

What competing instruments omit

InstrumentProvidesOmits
Agent frameworksExecution: tools, loops, memoryA boundary they cannot grant themselves — the runner cannot referee its own runs.
Observability / evalsWhat the agent did, measured afterStopping the inadmissible act before it runs; evidence that binds authority, not just output.
Policy documentsIntent, beautifully statedEnforcement. A wiki page has never refused an action.
This SDKPre-execution admissibility + per-act sealed evidence, framework-agnostic. The moat: governance as a construction property cannot be retrofitted by competitors bolted on outside the execution path — and every attested run deepens an evidence corpus that only accrues to the layer holding the boundary.
Annex I — interpretive notes

Questions of construction

Does this run our agents?
No. It governs them as principals — identity, authority, evidence. Your agent framework executes; the SDK is the boundary it executes inside. That separation is deliberate and permanent.
What happens when the decision engine is unreachable?
The verdict path fails closed, never open — a consequential act without an admissibility decision does not proceed. Availability problems degrade throughput, never governance.
Can an agent grant itself more authority?
No. Bindings attach at construction and cannot be shed or widened at runtime; a self-grant attempt is itself a refused, evidenced act.
How do human approvals work?
Thresholds you declare route acts to named approvers before execution; the counter-signature becomes part of the act's sealed evidence.
Which regulations does this satisfy?
The honest answer: the SDK enforces and evidences your declared controls. Regulatory mappings are made explicitly — anything unmapped is stated as out-of-scope rather than implied covered.
Application

For agents facing consequential actions

Payments, KYC, case decisions, customer data — teams putting agents in front of acts that matter receive access first. A person replies from info@agentpayment.dev.

Read the authority stack

Application for access

State your agents' consequential acts — a person replies from info@agentpayment.dev.

Routed via the governed comms rail.

Entered into the record.

Your application is filed — routed to info@agentpayment.dev.