Protocol
Financial Protocol
The layer beneath every screen. Bounded services with single writers, posting rules that refuse to guess, one command taxonomy, one error contract, and a calculation library where every figure carries its formula. Nothing here is illustrative — each panel runs the same code the platform runs.
Bounded services
15
Each the sole writer of its entities
Commands declared
10
No generic write endpoint exists
Ownership conflicts
0
Two writers on one entity
Orphan commands
2
Commands with no owning service
Bounded service map
Only the owning service writes its entities. Everything else reads through a published query — that rule is verified below, not asserted.
Ownership verified: no entity has more than one writer, and every declared command belongs to a declared service (2 orphan).
Identity Service
control plane · namespace identity
Actors, sessions, agent identities and capability tokens. Never stores financial data.
Owns: User · Session · AgentIdentity · CapabilityToken
Reads: Organization
Invariants
An agent identity is always traceable to the human that provisioned it.
Failure states
Token issuance unavailable — all agent action halts, reads by humans continue.
Recovery: Tokens are short-lived; recovery re-issues rather than extends.
Permission Service
control plane · namespace policy
Resolves capabilities for an actor in an organization. Deny always wins.
Owns: Role · Grant · Delegation
Reads: User · AgentIdentity
Invariants
Absence of a grant is denial.
A delegation cannot exceed the delegator's own capabilities.
Failure states
Resolution unavailable — the platform denies everything rather than assuming access.
Recovery: Fails closed. No cached permissive answer is ever served.
Policy Service
control plane · namespace policy
Evaluates financial policy against a proposed action and explains the verdict.
Owns: PolicyRule · PolicySnapshot · PolicyDecision
Reads: FinancialState · Beneficiary
Invariants
Every decision references the snapshot in force at that instant.
Failure states
Evaluation error — the action is denied and an incident is opened.
Recovery: Snapshots are immutable, so historical decisions replay exactly.
Approval Service
control plane · namespace policy
Human decisions bound to a payload hash, with separation of duties.
Owns: Approval · ApprovalDecision
Reads: PaymentIntent · Recommendation
Invariants
Preparer may not approve.
A changed payload invalidates every decision on it.
Failure states
Expired approval — the execution is refused, not auto-renewed.
Recovery: Requests are re-raised with a fresh hash; nothing is silently reused.
Ledger Service
truth plane · namespace ledger
Double-entry system of record. The single arbiter of accounting truth.
Owns: LedgerAccount · Journal · JournalLine · Period
Reads: Transaction · Invoice · Payment · Contract
Invariants
Debits equal credits per currency on every journal.
Posted journals are immutable; correction is by reversal.
Failure states
Unbalanced posting attempt — refused with no partial write.
Period locked — posting routed to the open period.
Recovery: Replay from the event store reproduces the ledger byte-identically.
Transaction Service
truth plane · namespace txn
Normalized provider transactions with the raw payload retained forever.
Owns: Transaction · RawTransaction · Category
Reads: Account · Connector
Invariants
A pending transaction that settles updates in place and keeps both observations.
Failure states
Duplicate external id — deduplicated by connector + external id.
Recovery: Overlapping sync windows are safe; idempotency makes re-ingestion a no-op.
Account Service
truth plane · namespace account
Accounts and their balance observations. Custody stays with CXR Bank.
Owns: Account · AccountBalance
Reads: Connector
Invariants
A balance is an observation with an as-of time, never a mutable field.
Failure states
No fresh observation — the balance is served labelled stale.
Recovery: Next successful sync supersedes without deleting the earlier observation.
Reconciliation Service
truth plane · namespace txn
Matches external movement to internal records; opens exceptions when unsure.
Owns: MatchProposal · ReconciliationException
Reads: Transaction · Journal · Invoice · Payment
Invariants
An ambiguous match is an exception, never an assumption.
Failure states
Exception backlog beyond threshold — close is blocked.
Recovery: Matching is deterministic and re-runnable over any window.
AR Service
truth plane · namespace ar
Invoices, collections behaviour and aging.
Owns: Invoice · InvoiceLine · Receipt
Reads: Customer · Contract · Transaction
Invariants
Amount paid never exceeds invoice total without an explicit overpayment record.
Failure states
Partial payment below tolerance — held as an exception.
Recovery: Aging recomputes from source invoices; no stored aggregate is trusted.
AP Service
truth plane · namespace ap
Bills, obligations and payment timing.
Owns: Bill · Obligation
Reads: Vendor · Contract · PaymentIntent
Invariants
An obligation is discharged only by a settled payment.
Failure states
Duplicate bill detected — flagged, never auto-paid.
Recovery: Obligations rebuild from contracts and bills deterministically.
Payment Service
execution plane · namespace exec
Intents, authorization and exactly-once settlement through the provider.
Owns: PaymentIntent · Payment · Beneficiary
Reads: Approval · PolicyDecision · AccountBalance
Invariants
Exactly one settlement per intent under any retry or partition.
A beneficiary detail change restarts verification.
Failure states
Provider timeout — status unknown, resolved by reconciliation, never re-sent blindly.
Recovery: Idempotency keys and provider reference lookup close every unknown state.
Forecast Service
intelligence plane · namespace plan
Driver-based projections with model metadata and measured accuracy.
Owns: Forecast · ForecastRun · Feature · ModelVersion
Reads: FinancialState · Transaction · Contract
Invariants
Every forecast states its model, features and error history.
Failure states
Insufficient history — declared no-forecast state.
Recovery: Falls back to a simpler declared model rather than fabricating precision.
Risk Service
intelligence plane · namespace risk
Scores exposure and links each risk to an action that would reduce it.
Owns: Risk · RiskAcceptance · RiskOverride
Reads: FinancialState · Counterparty · DebtInstrument
Invariants
An override records who, why and until when.
Failure states
Scoring inputs stale — score is withheld rather than shown confidently.
Recovery: Deterministic recomputation from current state.
Connector Service
platform plane · namespace connector
Adapter lifecycle, sync cursors, rate limiting and credential health.
Owns: Connector · SyncCursor · Credential · WebhookDelivery
Reads: Account
Invariants
Every ingested record is idempotent on connector + external id.
Failure states
Credential expired — sync halts loudly, data is labelled stale.
Recovery: Cursors rewind by an overlap window; duplicates collapse on ingest.
Audit Service
control plane · namespace audit
Hash-chained record of every state change with before and after.
Owns: AuditRecord
Reads: *
Invariants
Append-only. A broken chain is a platform-level incident.
Failure states
Chain verification failure — Safe Mode engages automatically.
Recovery: Chain is verifiable from genesis at any time.
