Financial governance control plane

Technical access is not financial authority.

Named roles, independent decisions, institutional key custody, controlled recovery and verified release evidence must exist before production. Today, every production authority remains empty.

Controls are defined; identities and authority are not.

Repository membership, cloud access, provider access, deployment rights or an AI workflow cannot silently become approval, signing, recovery or value-movement authority.

Control domainCurrent valueMeaning
Production authority assignments0

No human or workload identity holds a production financial role.

Active production keys0

No signer, HSM, MPC provider, recovery share or key ceremony is represented as active.

Approved production releases0

A merge, deployment, domain, provider or AI decision cannot activate production.

Verified backup snapshots0

No backup, restore test, alternate provider, RTO or RPO is claimed.

Production data stores0

No processor, cross-border transfer or retention schedule is approved.

Build-time denial cases18

Every adversarial fixture must deny and return its expected reason.

GitHub branch protectionNot enforced

CODEOWNERS is published, but live branch rules must still be configured and verified.

One identity cannot control the whole financial chain.

Future high-impact roles require phishing-resistant MFA, hardware-bound authentication, just-in-time elevation, time-bounded approvals, session evidence and periodic access recertification.

Boundary 01

Requester cannot be the sole approver

Independent evidence and accountable human domains are required.

Boundary 02

Approver cannot be the sole signer

Independent evidence and accountable human domains are required.

Boundary 03

Signer cannot be the sole reconciler

Independent evidence and accountable human domains are required.

Boundary 04

Key custodian cannot solely recover and activate

Independent evidence and accountable human domains are required.

Boundary 05

Incident command cannot solely resume production

Independent evidence and accountable human domains are required.

Boundary 06

Independent audit cannot hold value-moving authority

Independent evidence and accountable human domains are required.

No raw keys, seed phrases or automatic failover authority.

A future ceremony requires institutional HSM or reviewed MPC controls, three distinct human roles, two independent witnesses, device/provider attestation, readable purpose, approved quorum and tamper-evident evidence. Backups cannot carry raw private keys or grant financial authority.

CODEOWNERS is present; main-branch protection is not yet enforced.

The published runbook requires two approvals, Code Owner review, stale-approval dismissal, current Quality gates and Vercel checks, signed commits, and no force-push, deletion or administrator bypass.