A governed agent, doing the work.
This agent holds one thing to begin with: the identity the bank published for it, and a key its manufacturer attested. It has no client record at any authorisation server, no shared secret with any of them, and no list of addresses. Everything it needs, it resolves while it runs.
Each scenario below is a real run against the deployed estate. Every row opens onto the document that produced it, and a run that stops, stops on screen.
An agent that chooses who authorises it is not being authorised by anybody, so the person is named by whoever asks for the work. Both of these are authorised signatories on this customer.
- Nothing has run yet. Pick a scenario above.
- Raidiam product the governance control plane: what exists, what each thing is, and what this agent may ask for.
- Reference implementation the authorisation servers and the APIs. They stand in for the platforms CBA already runs. Not Raidiam products.
- Open standard the mechanism, not the story.
The seven authorisation servers on this stage are deployments built to show the integration. CommBiz stands in for the business banking authorisation server, Workforce for the internal one. The Raidiam component is the Trust Controller that publishes what they resolve, and withdraws it when an agent is suspended.