Security / Target control model

Security controls around every request and balance change.

The target design resolves every operation to one workspace and account, protects balance changes with balanced journals and reservations, and carries durable lifecycle Events through signed Webhook Deliveries.

  • Workspace-scoped access
  • Ledger-backed balances
  • Signed deliveries
REFERENCE CONTROL TRACE / WITHDRAWAL PRODUCT MODEL
WITHDRAWAL INTENT account wallet + destination
WORKSPACE SCOPED
  1. 01 / IDENTITY BOUNDARY Credential resolves workspace credential → one workspace
    CONTROL
  2. 02 / ACCOUNT BOUNDARY Ownership remains bound workspace → user → account → wallet
    CONTROL
  3. 03 / MONEY BOUNDARY Gross amount reserved available → reserved
    CONTROL
  4. 04 / DELIVERY BOUNDARY Event delivered with signature event identity + delivery identity
    CONTROL

01 / Boundary model

Every operation stays inside explicit boundaries.

The target model resolves identity and ownership before money state changes, then separates durable product Events from their signed delivery transport.

01 / AUTHENTICATE

Identity boundary

A revocable server credential resolves exactly one workspace; callers do not select tenant context.

credential → workspace
02 / ISOLATE

Account boundary

Users, accounts, wallets, balances, transfers, and Events retain one workspace and account binding.

workspace → user → account
03 / ACCOUNT

Money boundary

Finality, reservations, and balanced journals control when available or reserved amounts can change.

journal-backed state
04 / VERIFY

Delivery boundary

A signed Webhook Delivery binds Event content, freshness, and delivery identity for receiver verification.

event + delivery signature

02 / Money-state controls

Correctness rules protect the balance.

Crypto activity and customer balances are not treated as the same thing. Durable control points decide when a transfer can affect available or reserved funds.

  • No deposit credit before finality.
  • No withdrawal submission before the gross amount is reserved.
  • No repeated command, callback, or transition creates a second money effect.
  • No Webhook Delivery is trusted before authenticity and freshness are verified.
TARGET CONTROL MODEL Money-state invariants
PRODUCT MODEL
Target money-state controls
Operation Target control Durable effect
Inbound deposit Finality + mapping + deduplication One completed transfer, credit, and Event
Accepted withdrawal Account-wallet gate + reservation Available moves to reserved
Execution submission Separate execution-liquidity gate Reservation remains held
Terminal withdrawal Definitive execution outcome Completed consumes; failed releases

03 / Operations and evidence

Preserve facts before resolving exceptions.

Execution callbacks, state transitions, operator actions, and reconciliation findings remain attributable. Uncertain or mismatched facts create durable exceptions; they never silently rewrite an account-wallet balance.

  1. 01 CALLBACK Verify and retain Deduplicate external facts
  2. 02 EXCEPTION Preserve uncertainty Do not force a money transition
  3. 03 OPERATOR CONTROL Hold, resolve, or suspend Preserve reservations and audit actions
  4. 04 RECONCILIATION Compare product and execution views Never auto-adjust the ledger
REFERENCE CONTROL MODEL retain → decide → audit → reconcile

04 / Shared responsibility

A clear line between platform and customer.

The target processing layer protects its internal boundaries. Your application remains responsible for end-user access, business and compliance decisions, destination correctness, credential protection, and verified consumption.

PROCESSING PLATFORM

Controls inside the processing boundary

  • Resolve requests and data to one workspace and account.
  • Apply finality, reservation, and balanced-journal rules.
  • Retain and deduplicate callbacks; produce durable Events and signed Webhook Deliveries.
  • Preserve exceptions, suspend safely, and reconcile without automatic balance correction.
  • Audit sensitive platform and operator actions.
YOUR APPLICATION

Controls inside your product boundary

  • Authenticate and authorize your own end users.
  • Decide when to request a withdrawal and provide the complete destination.
  • Own business and compliance policy outside the processing boundary.
  • Protect API credentials and webhook verification material.
  • Verify Deliveries, deduplicate Events, and treat product reads as authoritative.

Security evaluation

Review the target boundaries before implementation.