
domain
Banking Compliance
PSD2-era banking work with per-request, revocable authority
Open banking taught the industry a pattern: access should be scoped, consented, short-lived, and revocable, and every access should be attributable. PSD2 imposed that discipline on third parties touching customer accounts. CueCrux applies the same discipline to the agents a bank runs internally.
Under RCX, each agent request runs on a short-lived capability token scoped to tools, tenant, and tier, self-issued locally and offline-verifiable. There is no standing god-mode credential for the fleet. When policy says no, the refusal fails closed and produces a signed RefusalReceipt with a reason code, which is the difference between "the control exists" and "the control demonstrably operated on this date".
Prudential expectations around operational resilience and third-party risk increasingly ask banks to inventory and evidence their automated processes. Fleet attribution answers with data: which agents acted, on which verbs, at what cost, with every action resolving to a passport identity and trust tier. Revocation is provable, propagating as a signed pull with per-agent acknowledgements and an attestation when zero holders remain.
For compliance teams navigating PSD2, CRD, and resolution-planning obligations, the practical gain is that the evidence of control is generated by the same machinery doing the work.