Margin

Authorization design

Security

An agent’s request should be checked against the authority its owner granted. That principle guides the system we’re building.

Planned authorization flow

01

Agent request

Account
Checking
Action
Payment
Amount
$25.00
02

Policy check

  • Account access
  • Action permission
  • Amount and recipient
03 / Within policy

Continue

Proceed within the owner’s rules.

Outside policy

Require approval

Ask the owner or decline the request.

Scope

Grant each agent access to specific accounts and actions.

Limits

Set amounts, recipients, and the situations that require approval.

Revocation

Withdraw access when an agent no longer needs it.

Records

Keep a traceable history of requests, decisions, and outcomes.

Launch requirements

Standards & assurance

Margin will launch only after meeting DORA and NIS2 requirements, completing PCI DSS validation, and obtaining ISO/IEC 27001 certification.

The security program is in development. These requirements have not yet been completed.