Skip to main content

Platform architecture

Logical layers

Architectural rules

1. Core APIs remain authoritative

Posting authority, arrangement state transitions, credit decisions, limit enforcement, and servicing outcomes are executed by core services.

2. Agents use governed tools

Finpace MCP exposes business-safe tools rather than unrestricted CRUD access to core services.

3. Protected actions are policy-evaluated

Before execution, the runtime evaluates:
  • actor identity
  • delegated authority
  • channel
  • customer consent
  • product and jurisdiction rules
  • approval profile
  • policy outcome
  • risk score

4. Evidence objects are reusable

The same evidence objects support:
  • internal audit
  • regulator review
  • customer dispute handling
  • operational traceability
  • AI explainability

Deployment model

The reference architecture supports:
  • private cloud
  • client cloud
  • hybrid deployment
  • controlled on-premises deployment for high-sensitivity institutions
Regional isolation is available for:
  • prompts
  • retrieval stores
  • tool execution logs
  • document caches
  • policy packs
  • audit evidence