Skip to main content

KYA (Know Your Agents) — Open-source trust, governance, and evidentiary assurance infrastructure for autonomous systems. Built on KYP (Know Your Principal), a unified trust model for human users, AI agents, service accounts, and machine identities.

Project description

veldt-kya

KYA (Know Your Agents) is open-source trust, governance, and evidentiary assurance infrastructure for autonomous systems.

It helps organizations answer:

  • Who — or what — acted?
  • What authority did they possess?
  • What data and resources could they access?
  • How did authority propagate across humans, AI agents, and services?
  • Did the actions conform to policy?
  • Can the decision be verified afterward?

The challenge is not simply telemetry. It is identity, authority, evidentiary provenance, and enforceable behavioral contracts across autonomous systems.

KYA builds on KYP (Know Your Principal), a unified trust model spanning human users, AI agents, service accounts, and machine identities. Together they provide trust scoring, delegated-authority attribution, policy enforcement, evidentiary provenance, drift detection, data-sensitivity controls, and compliance-grade evidence chains.

Applicable to LLM agents, multi-agent systems, autonomous workflows, agentic RAG, AutoML pipelines, RPA bots, service accounts, and machine identities.

pip install veldt-kya

KYA does not replace observability. Observability helps explain what happened operationally — latency, cost, traces, and execution paths. KYA helps determine whether actions were authorized, policy-conforming, attributable, and verifiable.

Framework paper (preprint): KYA: A Framework-Agnostic Trust Layer for Autonomous Systems with Verifiable Provenance and Hierarchical Policy Composition.

Quick start

from kya import score_agent, normalize_agent_def

# Score a Veldt-native agent definition
risk = score_agent({
    "agent_key": "my_agent",
    "model": "openai/gpt-4o-mini",
    "tools": ["search_docs", "execute_sql"],
    "human_loop": "in_the_loop",
    "access_level": "write",
    "can_override": True,
    "data_classes": ["pii"],
    "compliance_scope": ["gdpr", "nydfs_500"],
})
print(risk.score, risk.bucket)          # 100 critical
for f in risk.factors:
    print(f.name, f.delta)              # attributable per-factor breakdown

Persistence — zero-config evaluation

score_agent() is a pure function with no I/O. Anything that records evidence, principal trust, agent versions, or invocations needs a database. kya.default_session() gives you that with no setup — it falls back to sqlite:///~/.kya/kya.db if KYA_DB_URL is unset:

from kya import default_session, snapshot_agent, record_invocation, record_evidence

with default_session() as db:
    snapshot_agent(db, tenant_id="t1", agent_key="loan_triage",
                   definition={"agent_key": "loan_triage", "tools": ["check_credit"]})
    inv = record_invocation(db, tenant_id="t1", agent_key="loan_triage",
                            principal_kind="agent", principal_id="loan_triage",
                            mode="observed", outcome="success")
    record_evidence(db, tenant_id="t1", invocation_id=inv,
                    evidence_kind="prompt", payload={"text": "..."})
    db.commit()

For production, set KYA_DB_URL=postgresql://... (or MySQL / DuckDB). All 17 KYA-owned tables are portable across PostgreSQL, MySQL, SQLite, and DuckDB — verified by tests/verify_all_backends_with_data.py (17 tables × 4 backends × non-empty row counts = 68/68 cells green).

Bring your own framework

KYA's normalize_agent_def(framework, raw_def) adapts foreign agent shapes into the canonical schema. 23 built-in adapters across the major agent frameworks (LangChain, CrewAI, OpenAI Agents, Claude Agent SDK, AutoGen, Semantic Kernel, LlamaIndex, Haystack, MCP, Bedrock, Vertex, Pydantic AI, Letta, Smol, Strands, Google ADK, and more):

from kya import normalize_agent_def, score_agent

# LangChain
from langchain.agents import AgentExecutor
ex = AgentExecutor.from_agent_and_tools(agent, tools=[my_sql_tool, my_email_tool])
risk = score_agent(normalize_agent_def("langchain", ex))

# CrewAI
from crewai import Agent
agent = Agent(role="Analyst", goal="...", tools=[...])
risk = score_agent(normalize_agent_def("crewai", agent))

# OpenAI Assistants
risk = score_agent(normalize_agent_def("openai", openai_assistant_dict))

# Generic dict (everything else)
risk = score_agent(normalize_agent_def("generic", your_dict))

Register your own adapter for proprietary frameworks:

from kya import register_adapter

def my_adapter(raw):
    return {"agent_key": raw.id, "tools": raw.allowed_actions, ...}

register_adapter("acme", my_adapter)
score_agent(normalize_agent_def("acme", proprietary_agent))

Runtime: multi-judge orchestration + trust

score_agent() is pre-deployment. At runtime, check_consensus() runs N third-party judges in parallel and routes the verdict into per-principal trust:

from kya.scorer_orchestrator import (
    check_consensus, register_available_adapters, signals_from_consensus,
)
from kya import record_principal_signal, require_action, AccessDeniedError

register_available_adapters()   # auto-wires opt-in judges if installed

r = check_consensus(input_text=user_msg, response=agent_response,
                    context=rag_context)
# r.consensus -> BREACH/OK/SPLIT/UNCLEAR
# r.per_dimension -> input_safety / safety / faithfulness
# r.judges -> per-judge verdict + score + latency

# Trust decay routed by dimension:
for signal_kind, dim in signals_from_consensus(r):
    record_principal_signal(db, tenant_id="t1", principal_kind="agent",
                            principal_id="my_agent", signal_kind=signal_kind)

# Gate privileged actions on trust:
try:
    require_action(db, tenant_id="t1", principal_kind="agent",
                   principal_id="my_agent", action="kya.budget.write",
                   min_trust=45)
except AccessDeniedError:
    ...   # agent's trust fell below 45 -- auto-block, no operator needed

The orchestrator's default panel splits into three honest tiers so you can tell what works out of the box vs what needs setup:

Bundled (no setup, works after pip install veldt-kya): openai_judge (uses your existing OPENAI_API_KEY if set), refusal_heuristic (substring detection, no API call), kya_pyrit (output data-leak scanning), kya_attack_patterns (7 categories: encoded payloads, exfil paths, indirect injection, PII smuggling, role hijack, authority claims, external redirects).

Optional extras (one install command, no external service): kya_presidio (PII detector, tunable: entities / threshold / min-findings) via pip install veldt-kya[presidio]. arize_phoenix (hallucination-methodology judge via litellm) via pip install veldt-kya[recommended].

BYOC bridges (Bring Your Own Cloud — wraps an existing paid account): fiddler_safety and fiddler_faithfulness adapt your Fiddler Guardrails account into the panel; both require FIDDLER_API_KEY in env. If you don't have an account these judges no-op, the rest of the panel keeps voting, and the orchestrator's consensus stays defensible. The same bucket is where future commercial-guardrail bridges land — KYA orchestrates above the service rather than replacing it.

Customers plug in their own judges (SQL-aware policy engines, internal red-team scorers, etc.) via register_judge(name, fn).

Signal routing is dimension-correct: input_safetyreceived_attack (-1, agent was attacked but may have refused), safetypolicy_violation (-7), faithfulnesshallucination_detected (-5). Identity bindings ship today via kya.auth: JWT introspection, SPIFFE workload identity, and OIDC (Keycloak / Okta / Auth0). See examples/live_e2e_jwt_auth.py, live_e2e_spiffe.py, and live_e2e_keycloak_real_idp.py.

Drift detection

from kya import canonical_hash, detect_drift

# At registration time, store the hash:
declared = canonical_hash(agent_def)

# Later, anywhere — did anyone tamper with the definition?
if detect_drift(declared, current_agent_def):
    alert("agent identity has mutated since registration")

A one-line edit to system_prompt flips the SHA. Observability tools don't watch your config — KYA does.

Compliance regimes

from kya import compliance_summary, REGIME_BREACH_NOTIFY

summary = compliance_summary(agent_def, risk.score)
# {"scope": ["gdpr", "nydfs_500"],
#  "eu_ai_act_tier": "high",
#  "required_controls": [...],
#  "retention_days": 2190}

# What's the regulator's SLA + format if this agent has a breach?
print(REGIME_BREACH_NOTIFY["nydfs_500"])
# {"window_hours": 72, "format": "nydfs_breach",
#  "authority": "NYDFS Superintendent (23 NYCRR §500.17)"}

Built-in regimes: GDPR, EU AI Act, HIPAA, SOX, PCI, CCPA, GLBA, FERPA, ISO 27001, SOC 2, NYDFS 500, DORA, SR 11-7, ISO 42001, EO 14110, AI Bill of Rights — plus federal/defense (ITAR, EAR, CMMC, FedRAMP, DFARS, NIST 800-171, NIST 800-53, FIPS 140-2/3) and international equivalents (IRAP, CCCS, C5, ENS, IL5/IL6).

Optional features (extras)

pip install "veldt-kya[recommended]"   # multi-judge starter pack
                                       # (Presidio PII + litellm for
                                       # arize_phoenix + openai_judge)

pip install "veldt-kya[presidio]"      # Presidio PII detector only
pip install "veldt-kya[judge]"         # litellm (Phoenix + LLM judges)
pip install "veldt-kya[all_judges]"    # presidio + litellm + langkit

pip install "veldt-kya[metrics]"       # Prometheus counters
pip install "veldt-kya[tracing]"       # OpenTelemetry span events
pip install "veldt-kya[webhooks]"      # Outbound emit (Splunk /
                                       # Datadog / regulator formats)
pip install "veldt-kya[attack_chains]" # YAML rule DSL for multi-step
                                       # attack-chain detection
pip install "veldt-kya[all]"           # everything

Core (pip install veldt-kya) is stdlib + SQLAlchemy + requests only. The multi-judge orchestrator auto-registers 6 judges from the core install; opt-in extras add Presidio + Phoenix without changing your code.

Roadmap

This is the standalone packaging of the KYA infrastructure already running in production inside Veldt Decisions. Items still on the roadmap:

  • Lakehouse adapter (Databricks Genie / Snowflake Cortex)
  • Hosted KYA dashboard for self-managed deployments
  • SQL-aware data-policy judge (customers bring this today via register_judge(); bundled adapter in a future release)
  • Third-party-attestable notarization for the evidence chain (Sigstore / RFC 3161). v1 uses single-key HMAC chains — see §11 of the paper for the limitation.
  • Full DAG-wide topology validation for delegated agent graphs. v1 enforces pairwise parent-child ceilings (the Liang-2025 topology-attack defense).

License

Apache License 2.0 — © 2026 Veldt Labs Inc. See LICENSE.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

veldt_kya-0.1.3.tar.gz (544.5 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

veldt_kya-0.1.3-py3-none-any.whl (481.8 kB view details)

Uploaded Python 3

File details

Details for the file veldt_kya-0.1.3.tar.gz.

File metadata

  • Download URL: veldt_kya-0.1.3.tar.gz
  • Upload date:
  • Size: 544.5 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for veldt_kya-0.1.3.tar.gz
Algorithm Hash digest
SHA256 2527393be24aed36ace5ebac266fc8d3a0339be87cbd6c335e364f6e666baabf
MD5 002be17177b98dfa3e2e64c871962c98
BLAKE2b-256 eda9136ee43128a9e374a9f19476895aa32dd8931dd279eac7d7d541d458ab55

See more details on using hashes here.

Provenance

The following attestation bundles were made for veldt_kya-0.1.3.tar.gz:

Publisher: publish.yml on veldtlabs/veldt-kya

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file veldt_kya-0.1.3-py3-none-any.whl.

File metadata

  • Download URL: veldt_kya-0.1.3-py3-none-any.whl
  • Upload date:
  • Size: 481.8 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for veldt_kya-0.1.3-py3-none-any.whl
Algorithm Hash digest
SHA256 cd5780eefb4b52da7467978bb3d6d11356168541305aed0689366730fe5a88f2
MD5 5ff536afb38c4382bb9e70ec7031cf6a
BLAKE2b-256 4ef7b5d9818734049955773a856fd7829adfd8cc51218468732a689e16cce8ad

See more details on using hashes here.

Provenance

The following attestation bundles were made for veldt_kya-0.1.3-py3-none-any.whl:

Publisher: publish.yml on veldtlabs/veldt-kya

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page