Approval model
Roles are Owner, Admin, Approver, Operator, Agent and Auditor. Every workflow must name an approval chain. Empty approval chains are rejected at validation, and agents cannot appear in one.
Security
Approval stays human, evidence stays verifiable, and access stays scoped. AI never approves and never releases funds.
Roles are Owner, Admin, Approver, Operator, Agent and Auditor. Every workflow must name an approval chain. Empty approval chains are rejected at validation, and agents cannot appear in one.
Agents may read, draft, classify, screen, collect, route, prepare and submit for review. Agents cannot approve, release or move funds. Every controlled write requires a named human approval and produces audit evidence.
Each state change is recorded in one SHA-256 hash chain with a daily git-anchored checkpoint. There is no per-event signature, and the chain is not built yet.
Scoped and revocable API keys and OAuth tokens. IP restrictions on controlled writes. Per-tenant isolation, rate limits and kill switches at global, tenant and workflow level.
Workflow definitions pass schema, permission, security, policy and partner-capability checks before any human review, and compliance review where required.
This describes the security model of Next Payment, and the live surface stays sandbox-only until production gates pass. Items we cannot yet confirm are omitted rather than softened. An absent claim is safer than a vague one for regulated buyers.