Intent
Keep the user’s requested scope and constraints explicit.
Proposed security boundaries
The concept separates user intent, policy decisions, secrets, execution, and reconciliation. The public prototype does not handle real financial data.
Architecture proposal only · Controls are not presented as implemented, audited, or ready for production.
Keep the user’s requested scope and constraints explicit.
Evaluate the proposal against defined rules and return allow, deny, or needs-review.
Keep credentials, tokens, card data, and unrestricted account access outside model context.
Allow only an approved, bounded proposal to reach a future adapter.
Record the strongest state a future source can actually confirm.
Keep proposal versions, decisions, approvals, and state events inspectable.
Authentication, authorization, storage, providers, observability, incident response, and independent review remain TBD.