Safeguards for Agentic Finance at Runtime (v1.0)
The source document. Defines the envelope, the four components, and the four outcomes. Start here.
Annotated reading on runtime governance for agentic AI in finance. Annotations are our own. Vendor material is labelled.
The source document. Defines the envelope, the four components, and the four outcomes. Start here.
Practical guidance including agent-specific practices: least privilege, kill switches, searchable logging. SAFR builds on this groundwork.
Singapore's governance framing for agents: bounding use cases, limiting access, human oversight, accountability.
A three-layer model for agentic payments that identifies control and authorisation as the critical governance point.
Seventeen considerations across scope, risk management, lifecycle, and enablers. The board-level companion.
Where the correlated-behaviour concern comes from: concentration in a few AI providers as a systemic risk.
The 2026 follow-up, extending the herding and procyclicality concerns.
MAS's supervisory guidelines on AI risk. Useful for understanding what SAFR is not.
Map, Measure, Manage, Govern. The widely used US baseline for AI risk.
Experiments with a generative AI agent handling intraday liquidity trade-offs.
Bounded capabilities, runtime telemetry, continuous authorisation, tiered containment. Closest academic neighbour to SAFR.
Mandate-based authorisation with cryptographic signatures, enforced at machine speed.
Compliance architecture for regulated tokenised assets.
Programmable conditions on tokenised value, one of the settlement-layer controls SAFR sits above.
Delegated authorisation, the lineage behind SAFR's mandate concept.
The origin of capability-based security, which the mandate concept draws on.
Cryptographically signed mandates for agent spending authority. A concrete example of SAFR-style mandates.
Open standard for agent-coordinated fiat and stablecoin payments at the settlement layer.