Authorization
How a decision to allow or deny is made per data element, per purpose, per delegation — and how the resulting evidence is used.
Last updated 23 July 2026 · Trust Center
1. The model
Every read and every write is evaluated against four things: the caller, the record, the purpose asserted for the access, and the delegation in force at that moment. The evaluation is performed by B5 Secure™, licensed into the platform by B5 Secure, LLC, a separate entity.
The practical consequence is that access is not a property of a role held indefinitely. It is a decision made at the moment of access and recorded as one.
2. Purpose
The same person may legitimately read a record for one purpose and not another. An operations analyst resolving a funding break has a reason to see bank instructions; the same analyst browsing has not. Purpose is asserted at the call and evaluated, which makes “why did you open this record” an answerable question rather than an interview.
3. Delegation
Authority is delegable and hierarchical. An authorised person may act under an entity, an authorised person above may terminate one below, and revocation takes effect at the next decision rather than at the next review cycle.
The case worth picturing: an account holder authorises their financial adviser to act, retains approval rights over transactions, and can revoke that authority unilaterally without a service ticket. Each of those is an evidenced decision.
4. Approval gates
An approval requirement can be configured so a transaction is not final until a named party approves it — by threshold, by record class, by counter party or by asset type. Because the gate is enforced rather than procedural, the approval and the approver are part of the record instead of an email someone has to find later.
5. The Investor Passport
The Investor Passport is the reusable identity and eligibility layer: verified identity, entity and ownership data, accreditation, tax and banking details, authority and consent, captured once and reused across eligible offerings and accounts. A Passport is held by an authorised person, and Passports nest — which is the same delegation graph described above, seen from the investor’s side rather than the platform’s.
That is deliberate. The commercial unit and the enforcement object are one structure, so there is no entitlement model to reconcile against a permission model.
6. Scoped suspension
Because decisions are per data element and per purpose, a response to risk can be narrowed to a purpose, a delegation or a record class instead of disabling an institution. That matters during an incident, when the blunt option is usually the only one available.
7. What is recorded
For each decision: the acting identity, the record, the purpose asserted, the delegation relied upon, the decision, the time, and the policy version in force. See Examination support.
Financial Infrastructure, Inc. is a technology provider and is not a bank, trust company, broker-dealer or investment adviser. Nothing on this page is legal, regulatory, tax or investment advice. Institutional Trust Company is a proposed trust entity seeking a South Dakota non-depository trust charter; it is not yet chartered and is not accepting accounts.
Questions about this document? Contact security@a8core.com or write to Financial Infrastructure, Inc., PO Box 1410, Menlo Park, California 94026-1410.