Agents and Data Access
An agent layer that reads context out of unrelated systems and initiates changes in them for its owner, inside a mandate the client sets.
- Agentic
- MCP
- Mandates
Overview
Getting to the data
An agent's questions do not belong in the transactional path, so the data it reads sits apart from it, native and curated, with a model of concepts on top: the agent asks in business terms and gets an answer in them, and it can ask outside the fixed parameter set inside bounds you set. It reads across systems with nothing in common — fuel level off a vehicle bus, the same driver's balance out of a payment core — one context neither could produce alone.
What an agent may do
Every agent is registered: who owns it, who it acts for, and how it authenticates. A mandate then grants the right — which actions, what amounts, over what period — and a policy decides whether that right applies in the situation at hand. One customer can run several agents under different mandates, which is how a scope stays small enough to be worth granting at all.
Acting on it
Writes go down a separate channel, with a confirmation and a trail behind each one. Reading and calculating changes nothing, which is where agent analytics stops; a system that changes state has to prove what it changed. An agent initiates, the mandate is checked, and the transfer itself runs over trusted rails — the client's own scheme, or an existing open one. The same identity and policy rules cover agents on the other side, so the system can act as an agent too.
Staying in control
Every query and every change is recorded with the mandate it happened under, which is the record an audit asks for first. Stop rules and circuit-breakers cut an agent off mid-run, escalation hands the decision back to a person, and a change can be rolled back — which is the whole difference between an agent you can grant a mandate to and one you cannot.
Ownership
On us
- The layersPrepared data, a semantic model over it, and read and write kept on separate channels.
- The control setAgent identity, mandates and policies, and the record of every action taken under them.
- The connectionInto systems with nothing in common, assembled into one context.
On you
- The scopeWhat an agent may do, for how much, and for how long is yours to set.
- The systems and the dataWhatever the agent reads, and whoever owns it.
- The railsWhere a payment actually runs: your own scheme, or an existing open one.
Fit
- Who it is for
- Any business domain. Financial institutions with data. Product companies building agent features. Companies looking to cut operating cost by delegating work.
- When it comes up
- Data sits in several systems and every question about it goes through an analyst. There is a process worth delegating. Card schemes are already promoting their own rails for agent payments.
- The objection we hear
- That the client will build it themselves, which most of them believe. What they underestimate is the control set: mandates, policies, read split from write, and a record of every action.
Limits
No agent that runs your money. We build the layer it works inside.
No scope set by us. What an agent may do is yours to decide.