Vendor assessment surface · doctrine v2.9
Agent execution control
Govern agent-initiated payments and account actions — identity, policy, limits, confirm, verify, receipts — on licensed rails.
Agent → ABCP (identity · policy · limits · confirm · verify · receipt) → Partner rail
Hard boundary. Noetfield is not a chartered bank and not a money transmitter. ABCP is an assurance layer on licensed partner rails — doctrine, schemas, and evaluation twins only.
01
Overview
ABCP sits between the agent tool loop and licensed money rails. It binds identity, enforces policy, caps spend, challenges high-impact actions, verifies rail outcomes, and emits receipts. Fail-closed.
| We are | We are not | Thesis |
| Agent Execution Assurance for money-moving agents (Banking 3.1–3.2). |
- Not a chartered bank
- Not a card network
- Not a money transmitter by ourselves
- Not an AI-native bank charter product
|
Agents will move money. Rails will exist. Trust is the product. |
02
Control model
Decision pipeline: identity · policy · limits · confirm · verify · receipt. Exhibit maps to Tier-1 vendor questionnaires.
| Control | Summary | Bank ask |
Identity & delegation identity_delegation |
Every tool call binds agent_id ↔ principal (human or service) ↔ tenant_id. Delegation grants are scoped, time-bound, and revocable. |
Who is the agent acting for? Can grants be revoked instantly? |
Dual control / confirm for high-value dual_control |
Above-threshold payments and revoke-class tools require a bound, single-use confirm token issued outside the model turn. |
What requires a second factor? Is confirm replayable? |
Segregation of duties sod |
Admin (policy/limits), operator (run agents), and auditor (read receipts) are separate roles. Operators cannot rewrite policy; admins cannot silently erase audit. |
Who can change limits? Who can suspend agents? |
Idempotency & replay protection idempotency |
Client idempotency keys are required on write tools. Duplicate keys return the original receipt; confirm tokens are single-use. |
What happens on network retry? Can a confirm be reused? |
Kill switch / suspend-agent kill_switch |
Admin suspend immediately fails closed for that agent_id. Pending confirms are invalidated. |
How fast can we stop an agent? Does suspend cover in-flight confirms? |
Immutable audit (receipts) immutable_audit |
Every money-adjacent decision emits a receipt. Accepted outcomes require required checks to pass. Signed receipt profile: receipt-money-v1. |
Can we export for examiners? Are receipts tamper-evident? |
Fail-closed decisioning fail_closed |
Missing policy, schema failure, over limit, failed confirm, or unverified rail status → rejected or error — never soft-accepted. |
What is the default on dependency failure? |
03
Risk & controls
Laws enforced on every money-adjacent decision.
- Receipt law. Every money-adjacent decision emits a receipt; accepted only if required checks pass.
- Fail-closed. Missing policy, bad schema, over limit, failed confirm, or unverified rail → no successful money claim.
- Least privilege. Allowlisted tools only; JSON Schema with additionalProperties false before side effects.
- Confirm high impact. Above-threshold and revoke-class tools need bound, single-use confirm tokens.
- Tenant isolation. Identity, memory, cache, vectors, and account refs are namespaced; cross-tenant is a hard error.
- Rail separation. ABCP assures; licensed partners move value.
- Eval ≠ exec. Public evaluation kits prove the pattern; live money stays on the private control plane.
04
Compliance posture
Honest scope — partner-held licenses; ABCP does not claim bank charter, money-transmitter license, PCI certification, or OSFI approval unless separately evidenced.
Compliance page · Security / threat model
05
Architecture
Public twin for evaluation; private gateway for live rails. Eval ≠ exec.
Agent tooling → ABCP gateway → Partner rail (licensed) → Receipt (signed)
blueprint.json · manifest.json · trust.json
08
Buyer clinic
Field lanes — need, obstacle, gap, and the ABCP path. Not a bank charter; agent execution control on licensed rails.
Tier-1 bank · vendor assessment
SoD, kill switch, examiner receipts
- Need
- Prove agents cannot move value without identity, policy, limits, confirm, verify, and a signed receipt.
- Obstacle
- Procurement gets static PDFs; no interactive path that shows suspend stops all tools immediately.
- Gap
- No public twin with
sandbox:true and money_moved:false on every response.
- On platform
- Readiness gate — answer six questions → download signed GO / NO-GO report.
- Sandbox walk — eight steps: seed → reject → confirm → mutation → suspend → receipts → verify.
- Diligence ZIP — questionnaire CSV + OpenAPI + receipt schema.
- attest.json + /verify for machine-readable posture.
Fintech · embedded finance
Agent pay on Banking 3.1
- Need
- Caps, confirm tokens, and rail verification before
create_payment succeeds.
- Obstacle
- Ship velocity beats control design; agents get tools before limits and confirm are enforced.
- Gap
- No doctrine + OpenAPI + receipt schema bundle in one diligence ZIP.
- On platform
- Fintech pack — control mapping for Banking 3.1 asks.
- openapi.json — tool surface for vendor API review.
- receipt-money-v1 — signed receipt shape.
- Request lane 03 — pilot SOW when fit confirmed.
AI gateway · model host
money_v1 assurance in CI
- Need
- Standard hostile money scenarios in CI plus a public score customers can compare.
- Obstacle
- Each gateway invents its own “safe agent pay” story without a shared bench.
- Gap
- No
sec.money_v1 JSON suite linked to public scorecard and receipts.
- On platform
- Public scorecard — compare passing vs failing fixtures.
- Run
sec.money_v1 locally (see gateway pack).
- Request lane 05 — free 1-week log score (separate from pilot).
- Map failures to control catalog on this Trust Center.
CISO · GRC · Shield bridge
Tool authority + audit artifacts
- Need
- MCP DENY at the IDE, SARIF for GHAS, honest framework tags — not certification theater.
- Obstacle
- Agent risk sits between AppSec and IAM; neither team owns MCP wire enforcement.
- Gap
- No single buyer path from ABCP receipts to Shield SARIF and org assessment.
- On platform
- MCP DENY — wire enforcement + install checklist.
- SARIF completion — share scan → GHAS upload.
- Shield org assessment — unified GRC gate.
- SOC 2 readiness map — TSC tags (not certification).
Operations playbook — complete these on-platform before procurement asks for more PDFs.
| Form / kit | Path | What to complete | You get |
| Readiness gate | /gate | 6 radio questions (tools · confirm · kill · tenant · receipts · inject) | Signed GO / CONDITIONAL / NO-GO PDF |
| Policy demo | control sandbox | Eight-step walk with mutation + verify | JSON receipts sandbox:true |
| Diligence ZIP | /vendor/pack.zip | Download · attach to vendor portal | Questionnaire CSV · SOC2 map · OpenAPI |
| Vendor request | /request | Pick lane · email template with Org / Role fields | Walk · NDA · pilot path |
| Posture attestation | /attest.json | Verify signature at /verify | Ed25519-signed posture file |
| Shield tool authority | scan buyer clinic | MCP install · SARIF · org assessment per lane | Agent execution receipts + SARIF |
09
Audience packs
Deep dives per segment — same control plane, specialized questionnaire mapping.
Banks
SoD, kill switch, examiner-ready receipts. Pack →
Fintech
Agent pay on Banking 3.1 — limits, confirm, rails. Pack →
AI gateways
money_v1 in CI + free log score. Pack →
11
FAQ
- Is Noetfield a chartered bank?
- No. ABCP is an assurance layer on licensed partner rails — not a chartered bank and not a money transmitter by itself.
- What does ABCP control?
- Identity, policy, limits, confirm, verify, and signed receipts for agent money-adjacent tools — before value moves on a licensed rail.
- Where is the public proof?
- sec.money_v1 scorecard, OpenAPI, receipt schema, and Ed25519 verify. Live money stays on private customer gateways.