Give the agent a role. Not unlimited authority.
Design financial workflows around an identifiable principal, scoped agent access and service-confirmed outcomes. Keep the boundary visible in your application.

Start with the principal, not the prompt.
A model can interpret a request, but the application still needs to establish whose business the request concerns and what that party has authorised. The agent’s conversational context should not become the source of financial permission.
SUPA’s integration direction separates the principal, the agent and the enabled service scope. This gives your application a practical foundation for deciding which information can be retrieved, which preparation tasks can proceed and which consequential actions require an explicit review. A more capable model should not silently receive broader authority.

Keep service access outside the conversation.
Credentials and privileged operations belong behind the application’s controlled integration boundary. A user-facing assistant should request an allowed operation through that boundary, not gain unrestricted access because a conversation contains a convincing instruction.
The precise authentication and permission mechanisms are provided for the agreed integration. This public overview intentionally does not invent endpoints, scopes or production credentials. We begin by mapping your user journey to the capabilities currently available, then document the concrete interface your team can build against.
Model the hand-off as a product feature.
A workflow needs a clear answer when an action falls outside the agent’s scope. That may be a request for approval, a missing-information state or a prepared task handed back to a responsible person. The interface should explain what happened and what is required next.
The same principle applies after a service call. A submitted request is not automatically a completed operation, and a timeout is not evidence that nothing happened. Your application needs to present the provider’s actual state and follow the agreed recovery process before attempting a consequential action again.
Plan for access to change.
An agent may stop serving a business, a team member may leave or a use case may require narrower permissions. Access needs a lifecycle that can be reviewed and withdrawn. The integration should also preserve the relevant record of actions taken under earlier authority.
We work through these requirements alongside the first supported workflow. Start with a concrete task and a clear permission boundary, test the review and exception paths, then consider additional capabilities when the corresponding service requirements are met. Financial execution should never be inferred from access to onboarding or business information.
A tool call with a responsible business behind it.
An assistant prepares a request for a business customer. The application identifies the principal, checks the enabled scope and determines whether the next step is permitted or needs review. The agent receives an appropriate result without controlling the underlying credential or rewriting the permission boundary.
The user experience then shows the real state: prepared, awaiting a decision or confirmed by the relevant service. This pattern can be useful before payment execution is available. The exact operations and state model are specified in the integration materials provided to your team.

Good questions.
Clear answers.
Are production endpoint examples published here?
No. This is a public integration overview. Current endpoint documentation and access details are supplied for the agreed integration scope.
Does an AI integration include permission to move money?
Not automatically. Information retrieval, preparation and financial execution are distinct capabilities with separate availability and authority requirements.
Can a prompt expand an agent’s permissions?
It should not. Permission decisions belong to the controlled application and service layer, not to the model’s interpretation of conversational instructions.
A closer look.
Where could we take you?
Tell us what you want to build, connect or make possible.

