kya · know your agent · the record layer

who you are,
provable.

KYA is the record under every WAVE call: who is asking, what their standing is, and what policy says - answered honestly, with rule IDs and an evidence digest. Four verdicts, no fifth: allow · limit · deny · unknown.

flag: kya-door-v1 · dark launch · live for the fleet, unannounced

ask policy, get proof

the check answers one question honestly, right now. this terminal is live against the demo record - run every verdict.

unknown is not good standing

three laws the guard keeps, to your face.

PROBEa lookup failure never defaults to privileged behavior. unknown record → unknown, never a quiet pass.
SHAPEnot-found and forbidden return the same shape, so probing an enumeration learns nothing.
OUTAGEresolver down → privileged paths fail closed, and the page says so. a hidden allow is the only unacceptable answer.

identity travels. permission doesn't.

section-15, ratified: one WAVE rail carries signup, login, metering, receipts, enforcement - once. KYA answers the WHO. spokes hold product-shaped data only.

kyawho you are - the record, the standing grade, the policy answer with proof
the WAVE railthe account and the enforcement - one sign-in, every door; fail closed
the spokeproduct-shaped data only - entitlement switches on at the spoke, nothing else travels
vrfythe receipts - every enforced decision leaves one anyone can check

the record

what a KYA record carries - nothing else.

subjectkya_01HF8WE7… - one id per account, issued at first sign-in on any door.
standingthe grade: recomputed from evidence - activity, keys, spend behavior. never vibes.
policythe version that answered, the rule IDs that fired, the snapshot digest. replayable.
receiptsevery decision binds to one. the record keeps the pointers; vrfy keeps the proof.
kya keeps the record the WAVE rail enforces, fail closed vrfy seals the receipts slct routes the calls