The Investor Passport. Onboard once, invest across the ecosystem.
The Investor Passport is a reusable, permissioned investor profile on A8 Core™. It composes the identity, compliance, accreditation, ownership, tax, document, and permission data an institution needs to open and service an account — so a verified investor can move between products and providers without starting over.
What the Passport composes
One permissioned profile, assembled from the records an institution already has to collect and keep.
Verified identity Identity
Natural persons and entities, with the identifiers, relationships, and verification history that establish who the investor is.
Compliance KYC · KYB · AML
Know-your-customer, know-your-business, and anti-money-laundering evidence, with the checks and outcomes retained as records.
Accreditation Accreditation
Accredited-investor and qualified-purchaser status, the basis for it, and the evidence supporting each determination.
Ownership & tax Ownership
Beneficial ownership, tax identification, and withholding data reused across accounts rather than re-collected per product.
Documents & permissions Documents
Governing documents, agreements, and the permissions that control who may see and act on each part of the profile.
Investor history History
A durable record of prior onboarding, determinations, and account activity that the next provider can rely on.
How reuse works
The Passport turns onboarding from a per-product event into a one-time, reusable outcome.
Assemble once
The investor is verified and the profile is assembled, with each fact stored as an evidenced record.
Permission per use
For each new account, the investor grants scoped, revocable permission to the data a provider needs — nothing more.
Reuse across providers
Verified identity, compliance, accreditation, and ownership are reused instead of rebuilt, shortening time to first investment.
Every element is protected by Select to Secure™ and enforced by B5 Secure™ at the level of the individual record.
Give investors a reusable identity.
See how the Investor Passport shortens onboarding and follows the investor across your products.
The authority model
A8 Core separates who owns from who may act. Ownership is a set of parties with percentages and an ownership form. Authority is a separate set of capacities. Delegation is the mechanism by which a capacity is granted, bounded and withdrawn.
Three levels, and a grant may attach to any of them. A Client holds accounts. An Account may exist n times for the same account type — three Roth IRAs is a valid state, so “delegate my IRA” is not specific enough to act on. A Position is an asset held inside an account, and is where custody lives. A grant can name one position.
What a grant contains
| Property | Values |
|---|---|
| Grantee | A natural person. A grant to a firm is rejected. The firm is recorded as context, never as the subject. |
| Scope | Client · Account · AssetClass · Position — a set, with exactly one reference per row. |
| Actions | View, ReceiveDocuments, Submit, Execute, Sign, AdministerParties — separate rights, not a bundle. |
| Threshold | Any amount. Above it, approval is required. |
| Aggregate window | A number of days, set by the grantor. Amounts accumulate across it. |
| Approval mode | None · grantor only · a sequential ladder of named tiers. |
| Term | Effective from, effective to. The end date is mandatory. There is no perpetual grant. |
| On death | Terminate. Not configurable. |
| On incapacity | Terminate by default; continue only if the grantor deliberately elects it. |
| On revocation, in flight | OnRevokeInFlight — Fail by default: an instruction already moving fails the moment the grant is withdrawn. AllowCompletion only if the grantor elected it in advance, and that election is recorded on the grant. |
The grant is an immutable executed record. It is never updated in place — extension writes a new record that supersedes the old one, and suspension, reinstatement and revocation are lifecycle transitions. That is the same Create-then-lifecycle discipline the platform applies to every executed instrument.
Decide, Act, Know
Authority vocabulary collapses into three tiers, and keeping them distinct is what stops a control reading stronger than it operates. The same three tiers bound an AI agent acting under a Passport — see agentic payments.
| Tier | Verbs | Delegable? |
|---|---|---|
| Decide | Approve, sign, grant, authorise | No. Approval belongs to the grantor or a named approver. |
| Act | Submit, execute, create, set up | Yes, bounded by scope and threshold. |
| Know | View, receive documents, be notified | Yes. The cheapest and most common grant. |
Verify and validate sit between Act and Decide — an action with a gate. They are labelled separately rather than folded into either.
How a decision is made
Every delegated instruction resolves, at the moment of the instruction: the caller, the record, the purpose asserted, a resolvable unexpired grant covering that record and that action, the running aggregate for the window, and the tier state. If no grant resolves, the decision is deny. There is no fallback to a role and no implicit authority from a capacity row alone.
The aggregate is the part most often built wrongly. The window is a rolling trailing period, not a calendar month — a calendar month resets on the first, which is a predictable gap. Approved items still count toward the total. If approval reset the counter, a limit could be defeated simply by asking repeatedly. And debits aggregate while credits do not, because the risk is not symmetrical.
Approval ladders
Tiers are named and sequential, and a higher tier does not satisfy a lower one. “The CFO approved, so we skipped operations” is the segregation-of-duties failure an examiner tests for.
| Amount | Tiers required |
|---|---|
| Up to $50,000 | One approval |
| Above $500,000 | Two tiers, in order |
| Above $5,000,000 | Three tiers, in order |
Available on joint and entity accounts, with named approvers and per-approver thresholds. On an entity, the right to add or remove authorised persons is held separately and cannot itself be delegated — otherwise the ladder can be rewritten by someone standing inside it.
How authority ends
On death, authority has already ended. A financial power of attorney is valid only during the principal’s life. From the moment of death it confers no authority to act, sign or instruct — whether or not anyone has been notified. The termination timestamp is the date of death, not the notice timestamp, so any decision recorded after that date is flagged for retrospective review.
Notice is when the platform learns, not when authority ends. A certified death certificate takes time. Verbal notice restricts outgoing activity immediately and suspends every grant on the party. Formal notice terminates. Authority then passes to the executor, successor trustee or court-appointed administrator — modelled as a new capacity, never as a reinstated delegation. Authority shifts; it does not resume.
Other endings: the term expires, and the grantor is asked before it lapses rather than after. The grantor revokes, and the revocation is effective at the time of the change — the grant is over the moment it is withdrawn, and an instruction already in flight fails unless the grantor elected otherwise in advance. Or the grantee changes firms, which suspends every grant to them pending reauthorisation — because the grant was to the person, and an adviser leaving a firm is a decision point, not an inheritance.
What can be revoked, and when
You can withdraw or narrow authority at four levels, and the change takes effect the moment you make it — not at the next review, not when a request is processed, and not in the next business day’s batch.
The whole Passport
Every delegation you have granted, across every account, ends at once.
One account
Every asset held in that account, leaving your other accounts untouched.
One asset in one account
The rest of that account stays as it was — revocation is as precise as the grant was.
The limits themselves
Change a threshold, an aggregate window or an approval requirement across every account or on named accounts only, without withdrawing the delegation.
Because the change is immediate, control does not depend on office hours or on anyone else acting on your behalf. If you decide at midnight that an adviser should no longer be able to act, they no longer can.
An instruction that was accepted but has not yet completed fails when you revoke. That is the default, and it is deliberate: if a delegate’s credentials have been compromised, the instruction already moving is exactly the one you need stopped.
An in-flight instruction is allowed to finish only if you elected that in advance — a checkbox you tick yourself when you set the delegation up. No one can turn it on for you, a delegate cannot turn it on for themselves, and it is never inherited from another grant.
Screening the delegate
- Disqualified persons. In a self-directed retirement account, granting authority to a disqualified person, or to one who benefits from the transaction, can itself create a prohibited transaction. The platform warns at the point of the grant and records the acknowledgement. It does not block, and it does not make the legal determination — and it screens both the Labor interpretive and Treasury excise sides, which are split authority.
- Association and control status. Where a delegate is associated with or employed by an exchange, exchange member, FINRA member or municipal securities dealer, a compliance letter of approval is required and duplicate statements must go to that firm. If the grantor does not authorise duplicate statements, the grant cannot proceed. Control-person status under Rule 144 is captured for the delegate, their household and immediate family.
- Sanctions. Delegates are screened at grant and on a schedule — not only account holders.
What an examiner gets
For any record: the acting identity, the record, the purpose asserted, the grant relied on, the decision, the timestamp and the policy version in force. For any account: who held authority, granted by whom, from when, bounded how, revoked when and by whom.
A signed power of attorney proves authority was granted. It does not prove what was done under it, whether the scope held, whether a threshold was respected, or when it ended. A scoped, time-bounded, threshold-limited, evidenced delegation answers all four. Examination support covers what we can and cannot put in front of your examiner.
Talk to us How authorization works
Delegation controls described on this page are planned platform functionality. Financial Infrastructure, Inc. is a technology provider and is not a bank, trust company, broker-dealer, investment adviser or law firm, and nothing here is legal, regulatory or tax advice. Whether a particular delegation is permissible, durable, or creates a prohibited transaction depends on the instrument, the account type and the jurisdiction, and is a matter for the institution and its counsel.