A payment is easier to trust when you can follow it. Most cross-border instructions vanish into a chain of intermediaries and reappear, later, at the other end. The interesting question is what happens in between — and whether it can be described precisely at every stage rather than reconstructed after the fact.
From initiation to validation
An instruction can start from a human through an interface, from an agent through an API or MCP, or from an institution through ISO 20022. It then enters a single validation step: reliance confirmation, sanctions screening, the agent's mandate, whether the operation fits the client profile, and network anomaly signals. Passing that gate, the instruction is legitimate for the network, not just for one bank.
Over-limit operations are not simply rejected; they become a human approval request, which keeps judgement in the loop at the point where limits are reached.
Through the order book
Validated operations enter one order book. Offsetting flows cancel internally, participants settle instantly among themselves, and internal FX handles currency. What cannot be netted is passed on for routing, where the AI layer weighs cost, settlement time, reliability and regulatory fit before choosing a path.
Attribution at every step
The ledger is double-entry, built on TigerBeetle, and attributes every operation to the principal, the agent and the policy version in force. That means the same instruction can be read three ways: who stood behind it, which software executed it, and which rules applied at the moment it ran. Policy limits, approved counterparties and approval thresholds sit below the model, where an agent cannot argue with them.
The lifecycle is therefore not a black box with a receipt at the end, but a sequence in which each stage is named, matched and recorded.
In short
- Instructions begin with a human, an agent or an institution.
- Validation happens once and is shared across the network.
- The order book nets offsetting flows before external settlement.
- Every operation is attributed to principal, agent and policy version.
Follow the flow at /protocol/.