Agents are becoming software executors with real economic roles. The moment an agent needs to move value — pay a supplier, receive a settlement, hold a working balance — it needs more than a language model. It needs an interface to financial infrastructure. The Model Context Protocol (MCP) is one way to provide that interface, and SUPA exposes it as one of several entry points for an agent business unit.
Three ways in
An agent can reach the protocol through an API, through OpenAPI, or through MCP. The three are not competitors; they suit different integration styles.
- API — direct, explicit calls from your own code.
- OpenAPI — a described surface that tools and generators can consume.
- MCP — a context-protocol entry point, useful when the agent itself is the client.
In all three cases the result is the same: an operation attributed to a principal, an agent and a policy version.
What an agent unit is
An agent unit is composed of five layers: an identified principal legally standing behind every operation; a revocable agent identity that owns nothing and is never anonymous; policy applied below the model; partner rails behind one interface; and a ledger with evidence. MCP is simply a door into that structure — it does not change the structure.
Because each entry resolves to a principal and a policy version, an agent's activity can be inspected after the fact as well as controlled in advance. Registration is per unit, and the identity can be revoked, so access is a decision that can be changed rather than a credential that persists indefinitely.
Policy below the model
The design detail worth emphasising is where policy lives. Limits, approved counterparties and approval thresholds are applied beneath the model, where the agent cannot argue with them. An operation that exceeds a limit becomes a human approval request rather than a rejection — a queue a person resolves, not an error an agent retries blindly.
In short
- MCP joins API and OpenAPI as an entry point for agent business units.
- Every operation stays attributed to principal, agent and policy version.
- Policy sits below the model and is not negotiable by the agent.
- Over-limit operations route to human approval, not automatic failure.
Connect an agent through any of the three entry points: ai.