Noetfield ABCP Trust Center · v2.9

Vendor assessment surface · doctrine v2.9

Agent execution control

Govern agent-initiated payments and account actions — identity, policy, limits, confirm, verify, receipts — on licensed rails.

Agent → ABCP (identity · policy · limits · confirm · verify · receipt) → Partner rail

Hard boundary. Noetfield is not a chartered bank and not a money transmitter. ABCP is an assurance layer on licensed partner rails — doctrine, schemas, and evaluation twins only.

01

Overview

ABCP sits between the agent tool loop and licensed money rails. It binds identity, enforces policy, caps spend, challenges high-impact actions, verifies rail outcomes, and emits receipts. Fail-closed.

We areWe are notThesis
Agent Execution Assurance for money-moving agents (Banking 3.1–3.2).
  • Not a chartered bank
  • Not a card network
  • Not a money transmitter by ourselves
  • Not an AI-native bank charter product
Agents will move money. Rails will exist. Trust is the product.

02

Control model

Decision pipeline: identity · policy · limits · confirm · verify · receipt. Exhibit maps to Tier-1 vendor questionnaires.

ControlSummaryBank ask
Identity & delegation
identity_delegation
Every tool call binds agent_id ↔ principal (human or service) ↔ tenant_id. Delegation grants are scoped, time-bound, and revocable.
Who is the agent acting for?
Can grants be revoked instantly?
Dual control / confirm for high-value
dual_control
Above-threshold payments and revoke-class tools require a bound, single-use confirm token issued outside the model turn.
What requires a second factor?
Is confirm replayable?
Segregation of duties
sod
Admin (policy/limits), operator (run agents), and auditor (read receipts) are separate roles. Operators cannot rewrite policy; admins cannot silently erase audit.
Who can change limits?
Who can suspend agents?
Idempotency & replay protection
idempotency
Client idempotency keys are required on write tools. Duplicate keys return the original receipt; confirm tokens are single-use.
What happens on network retry?
Can a confirm be reused?
Kill switch / suspend-agent
kill_switch
Admin suspend immediately fails closed for that agent_id. Pending confirms are invalidated.
How fast can we stop an agent?
Does suspend cover in-flight confirms?
Immutable audit (receipts)
immutable_audit
Every money-adjacent decision emits a receipt. Accepted outcomes require required checks to pass. Signed receipt profile: receipt-money-v1.
Can we export for examiners?
Are receipts tamper-evident?
Fail-closed decisioning
fail_closed
Missing policy, schema failure, over limit, failed confirm, or unverified rail status → rejected or error — never soft-accepted.
What is the default on dependency failure?

03

Risk & controls

Laws enforced on every money-adjacent decision.

  1. Receipt law. Every money-adjacent decision emits a receipt; accepted only if required checks pass.
  2. Fail-closed. Missing policy, bad schema, over limit, failed confirm, or unverified rail → no successful money claim.
  3. Least privilege. Allowlisted tools only; JSON Schema with additionalProperties false before side effects.
  4. Confirm high impact. Above-threshold and revoke-class tools need bound, single-use confirm tokens.
  5. Tenant isolation. Identity, memory, cache, vectors, and account refs are namespaced; cross-tenant is a hard error.
  6. Rail separation. ABCP assures; licensed partners move value.
  7. Eval ≠ exec. Public evaluation kits prove the pattern; live money stays on the private control plane.

04

Compliance posture

Honest scope — partner-held licenses; ABCP does not claim bank charter, money-transmitter license, PCI certification, or OSFI approval unless separately evidenced.

Compliance page · Security / threat model

05

Architecture

Public twin for evaluation; private gateway for live rails. Eval ≠ exec.

Agent tooling → ABCP gateway → Partner rail (licensed) → Receipt (signed)

blueprint.json · manifest.json · trust.json

06

API

Vendor-readable OpenAPI 3.1. Live paths require mTLS or bearer service tokens on a private deployment — not on this Worker.

openapi.json · Error catalog · receipt-money-v1

07

Assurance suite

sec.money_v1 — inject pay, confused deputy, SSRF, secret echo, loop drain, missing confirm, revoke without confirm.

Public scorecard · money_v1.json · agent-security-bench

08

Buyer clinic

Field lanes — need, obstacle, gap, and the ABCP path. Not a bank charter; agent execution control on licensed rails.

Tier-1 bank · vendor assessment

SoD, kill switch, examiner receipts

Need
Prove agents cannot move value without identity, policy, limits, confirm, verify, and a signed receipt.
Obstacle
Procurement gets static PDFs; no interactive path that shows suspend stops all tools immediately.
Gap
No public twin with sandbox:true and money_moved:false on every response.
On platform
  1. Readiness gate — answer six questions → download signed GO / NO-GO report.
  2. Sandbox walk — eight steps: seed → reject → confirm → mutation → suspend → receipts → verify.
  3. Diligence ZIP — questionnaire CSV + OpenAPI + receipt schema.
  4. attest.json + /verify for machine-readable posture.

Fintech · embedded finance

Agent pay on Banking 3.1

Need
Caps, confirm tokens, and rail verification before create_payment succeeds.
Obstacle
Ship velocity beats control design; agents get tools before limits and confirm are enforced.
Gap
No doctrine + OpenAPI + receipt schema bundle in one diligence ZIP.
On platform
  1. Fintech pack — control mapping for Banking 3.1 asks.
  2. openapi.json — tool surface for vendor API review.
  3. receipt-money-v1 — signed receipt shape.
  4. Request lane 03 — pilot SOW when fit confirmed.

AI gateway · model host

money_v1 assurance in CI

Need
Standard hostile money scenarios in CI plus a public score customers can compare.
Obstacle
Each gateway invents its own “safe agent pay” story without a shared bench.
Gap
No sec.money_v1 JSON suite linked to public scorecard and receipts.
On platform
  1. Public scorecard — compare passing vs failing fixtures.
  2. Run sec.money_v1 locally (see gateway pack).
  3. Request lane 05 — free 1-week log score (separate from pilot).
  4. Map failures to control catalog on this Trust Center.

CISO · GRC · Shield bridge

Tool authority + audit artifacts

Need
MCP DENY at the IDE, SARIF for GHAS, honest framework tags — not certification theater.
Obstacle
Agent risk sits between AppSec and IAM; neither team owns MCP wire enforcement.
Gap
No single buyer path from ABCP receipts to Shield SARIF and org assessment.
On platform
  1. MCP DENY — wire enforcement + install checklist.
  2. SARIF completion — share scan → GHAS upload.
  3. Shield org assessment — unified GRC gate.
  4. SOC 2 readiness map — TSC tags (not certification).

Operations playbook — complete these on-platform before procurement asks for more PDFs.

Form / kitPathWhat to completeYou get
Readiness gate/gate6 radio questions (tools · confirm · kill · tenant · receipts · inject)Signed GO / CONDITIONAL / NO-GO PDF
Policy democontrol sandboxEight-step walk with mutation + verifyJSON receipts sandbox:true
Diligence ZIP/vendor/pack.zipDownload · attach to vendor portalQuestionnaire CSV · SOC2 map · OpenAPI
Vendor request/requestPick lane · email template with Org / Role fieldsWalk · NDA · pilot path
Posture attestation/attest.jsonVerify signature at /verifyEd25519-signed posture file
Shield tool authorityscan buyer clinicMCP install · SARIF · org assessment per laneAgent execution receipts + SARIF

09

Audience packs

Deep dives per segment — same control plane, specialized questionnaire mapping.

Banks

SoD, kill switch, examiner-ready receipts. Pack →

Fintech

Agent pay on Banking 3.1 — limits, confirm, rails. Pack →

AI gateways

money_v1 in CI + free log score. Pack →

10

Commercial

Two pilot slots per quarter. Pilot and embed SKUs. Free 1-week money_v1 score on gateway logs.

Vendor pack · Commercial packet · Request walk

11

FAQ

Is Noetfield a chartered bank?
No. ABCP is an assurance layer on licensed partner rails — not a chartered bank and not a money transmitter by itself.
What does ABCP control?
Identity, policy, limits, confirm, verify, and signed receipts for agent money-adjacent tools — before value moves on a licensed rail.
Where is the public proof?
sec.money_v1 scorecard, OpenAPI, receipt schema, and Ed25519 verify. Live money stays on private customer gateways.

12

Contact

Vendor assessment: /request · operations@noetfield.com · noetfield.com · https://banking.noetfield.com