Soltuition logoSoltuition

Protocol

Financial Protocol

The layer beneath every screen. Bounded services with single writers, posting rules that refuse to guess, one command taxonomy, one error contract, and a calculation library where every figure carries its formula. Nothing here is illustrative — each panel runs the same code the platform runs.

Bounded services

15

Each the sole writer of its entities

Commands declared

10

No generic write endpoint exists

Ownership conflicts

0

Two writers on one entity

Orphan commands

2

Commands with no owning service

Bounded service map

Only the owning service writes its entities. Everything else reads through a published query — that rule is verified below, not asserted.

Ownership verified: no entity has more than one writer, and every declared command belongs to a declared service (2 orphan).

Identity Service

control plane · namespace identity

extractable

Actors, sessions, agent identities and capability tokens. Never stores financial data.

Owns: User · Session · AgentIdentity · CapabilityToken

Reads: Organization

Invariants

An agent identity is always traceable to the human that provisioned it.

Failure states

Token issuance unavailable — all agent action halts, reads by humans continue.

Recovery: Tokens are short-lived; recovery re-issues rather than extends.

Permission Service

control plane · namespace policy

extractable

Resolves capabilities for an actor in an organization. Deny always wins.

Owns: Role · Grant · Delegation

Reads: User · AgentIdentity

Invariants

Absence of a grant is denial.

A delegation cannot exceed the delegator's own capabilities.

Failure states

Resolution unavailable — the platform denies everything rather than assuming access.

Recovery: Fails closed. No cached permissive answer is ever served.

Policy Service

control plane · namespace policy

extractable

Evaluates financial policy against a proposed action and explains the verdict.

Owns: PolicyRule · PolicySnapshot · PolicyDecision

Reads: FinancialState · Beneficiary

Invariants

Every decision references the snapshot in force at that instant.

Failure states

Evaluation error — the action is denied and an incident is opened.

Recovery: Snapshots are immutable, so historical decisions replay exactly.

Approval Service

control plane · namespace policy

extractable

Human decisions bound to a payload hash, with separation of duties.

Owns: Approval · ApprovalDecision

Reads: PaymentIntent · Recommendation

Invariants

Preparer may not approve.

A changed payload invalidates every decision on it.

Failure states

Expired approval — the execution is refused, not auto-renewed.

Recovery: Requests are re-raised with a fresh hash; nothing is silently reused.

Ledger Service

truth plane · namespace ledger

core — stays in-process

Double-entry system of record. The single arbiter of accounting truth.

Owns: LedgerAccount · Journal · JournalLine · Period

Reads: Transaction · Invoice · Payment · Contract

Invariants

Debits equal credits per currency on every journal.

Posted journals are immutable; correction is by reversal.

Failure states

Unbalanced posting attempt — refused with no partial write.

Period locked — posting routed to the open period.

Recovery: Replay from the event store reproduces the ledger byte-identically.

Transaction Service

truth plane · namespace txn

extractable

Normalized provider transactions with the raw payload retained forever.

Owns: Transaction · RawTransaction · Category

Reads: Account · Connector

Invariants

A pending transaction that settles updates in place and keeps both observations.

Failure states

Duplicate external id — deduplicated by connector + external id.

Recovery: Overlapping sync windows are safe; idempotency makes re-ingestion a no-op.

Account Service

truth plane · namespace account

extractable

Accounts and their balance observations. Custody stays with CXR Bank.

Owns: Account · AccountBalance

Reads: Connector

Invariants

A balance is an observation with an as-of time, never a mutable field.

Failure states

No fresh observation — the balance is served labelled stale.

Recovery: Next successful sync supersedes without deleting the earlier observation.

Reconciliation Service

truth plane · namespace txn

extractable

Matches external movement to internal records; opens exceptions when unsure.

Owns: MatchProposal · ReconciliationException

Reads: Transaction · Journal · Invoice · Payment

Invariants

An ambiguous match is an exception, never an assumption.

Failure states

Exception backlog beyond threshold — close is blocked.

Recovery: Matching is deterministic and re-runnable over any window.

AR Service

truth plane · namespace ar

extractable

Invoices, collections behaviour and aging.

Owns: Invoice · InvoiceLine · Receipt

Reads: Customer · Contract · Transaction

Invariants

Amount paid never exceeds invoice total without an explicit overpayment record.

Failure states

Partial payment below tolerance — held as an exception.

Recovery: Aging recomputes from source invoices; no stored aggregate is trusted.

AP Service

truth plane · namespace ap

extractable

Bills, obligations and payment timing.

Owns: Bill · Obligation

Reads: Vendor · Contract · PaymentIntent

Invariants

An obligation is discharged only by a settled payment.

Failure states

Duplicate bill detected — flagged, never auto-paid.

Recovery: Obligations rebuild from contracts and bills deterministically.

Payment Service

execution plane · namespace exec

core — stays in-process

Intents, authorization and exactly-once settlement through the provider.

Owns: PaymentIntent · Payment · Beneficiary

Reads: Approval · PolicyDecision · AccountBalance

Invariants

Exactly one settlement per intent under any retry or partition.

A beneficiary detail change restarts verification.

Failure states

Provider timeout — status unknown, resolved by reconciliation, never re-sent blindly.

Recovery: Idempotency keys and provider reference lookup close every unknown state.

Forecast Service

intelligence plane · namespace plan

extractable

Driver-based projections with model metadata and measured accuracy.

Owns: Forecast · ForecastRun · Feature · ModelVersion

Reads: FinancialState · Transaction · Contract

Invariants

Every forecast states its model, features and error history.

Failure states

Insufficient history — declared no-forecast state.

Recovery: Falls back to a simpler declared model rather than fabricating precision.

Risk Service

intelligence plane · namespace risk

extractable

Scores exposure and links each risk to an action that would reduce it.

Owns: Risk · RiskAcceptance · RiskOverride

Reads: FinancialState · Counterparty · DebtInstrument

Invariants

An override records who, why and until when.

Failure states

Scoring inputs stale — score is withheld rather than shown confidently.

Recovery: Deterministic recomputation from current state.

Connector Service

platform plane · namespace connector

extractable

Adapter lifecycle, sync cursors, rate limiting and credential health.

Owns: Connector · SyncCursor · Credential · WebhookDelivery

Reads: Account

Invariants

Every ingested record is idempotent on connector + external id.

Failure states

Credential expired — sync halts loudly, data is labelled stale.

Recovery: Cursors rewind by an overlap window; duplicates collapse on ingest.

Audit Service

control plane · namespace audit

core — stays in-process

Hash-chained record of every state change with before and after.

Owns: AuditRecord

Reads: *

Invariants

Append-only. A broken chain is a platform-level incident.

Failure states

Chain verification failure — Safe Mode engages automatically.

Recovery: Chain is verifiable from genesis at any time.

© 2026 Soltuition · Wealth Intelligence Solutions

Powered by: C.X.R Technologies · A Xavania Company