A control preset for bank operational-risk, fintech ops, and payments-operations teams. It is a deterministic EcoCloud Agent Constitution (the eight schema-valid action-gate keys) plus a map of the operational-risk controls to the governance kernels that already enforce them, today. A preset wiring shipped primitives — not a new product, a certification program, or a money rail.
EcoCloud clears governed work; your bank settles money.
Every row is a deterministic control that runs in the execution path — not a policy PDF. Each links to its live kernel demo.
| # | Control | OpRisk pillar | Enforced by |
|---|---|---|---|
| 1 | Risk & control register (RCSA): each control is a constitution rule; a control-test is a dry-run. | Identify & assess | 3 kernels |
| 2 | Four-eyes (maker–checker) + signing-limit escrow before high-impact writes execute. | Mitigate & enforce | 2 kernels |
| 3 | Authority subsetting — an agent's powers are a strict subset of its sponsoring human's. | Mitigate & enforce | 1 kernel |
| 4 | Counterparty gate — KYA passport status + LEI / IBAN / BIC validation + revocation hotlist before any action touches a counterparty. | Third-party & fraud | 2 kernels |
| 5 | Egress allowlist — no governed action to a destination outside the approved set. | Third-party & fraud | 1 kernel |
| 6 | Message preflight — ISO-8583 envelope shape, mandatory fields, currency & limit checks before a payload leaves the boundary. | Execution & process | 1 kernel |
| 7 | Dispute arbitration — reason-code taxonomy, SLA clocks, and an N-role review quorum. | Monitor & report | 2 kernels |
| 8 | Reconciliation — invoice / obligation vs contract → exceptions queue + signed dispute evidence. | Monitor & report | 1 kernel |
| 9 | Regulator mode — read·check·approve·mutate lineage + causal trajectory replay for investigations. | Monitor & report | 2 kernels |
| 10 | Compliance evidence — the tamper-evident audit graph exported as a SOC 2 / regulatory evidence pack. | Monitor & report | 1 kernel |
| 11 | Signed Outcome Receipt — offline-verifiable, zero-trust proof that a controlled action actually closed. | Monitor & report | live |
| 12 | Fleet integrity — behavioral-drift canary + flash-crash breaker on the agent fleet. | Monitor & report | 2 kernels |
The action-gate half of the pack. It validates against the canonical constitution.schema.json (v0.1.0) and runs unchanged in the browser, edge, and Node kernel. Paste it into your workspace constitution or extend it.
"max_priority": "high", "forbidden_terms": ["wire transfer", "move funds", "disburse", "payout", "release escrow", "issue credit", "custody transfer", "settle funds", "drop table", "delete production", "rotate prod secret"], "forbidden_assignees": ["external-counterparty", "unverified-agent"], "forbidden_tags": ["funds-movement", "settlement", "kyc-exempt", "prod-secret"], "objective_tags": ["reconciliation", "control-test", "attestation", "preflight", "dispute-evidence", "counterparty-screening"], "quiet_hours_utc": { "start": 22, "end": 6 }, "max_creates_per_day": 200, "require_approval_below_confidence": 0.8
Where the money goes. The missing partner is a licensed settlement bank / PSP that reads EcoCloud's attestations and netting statements and moves the funds off-network. That boundary is the moat: EcoCloud stays a neutral controls-and-proof layer, which is what lets bank OpRisk and ops teams adopt it without license drag.
Honest scope. This pack packages what is live: twelve deterministic kernels you can run right now, wired into one coherent control set. It does not ship a certification / "EcoCloud Governed" badge program, settlement-bank partner integrations, a network fee schedule, or multi-region active-active — those are scheme-operator concerns, not capabilities claimed here. See Operating Regulations (or-1) for the network rulebook and What's live for the full shipped/planned split.