CBA side illustration

Bankwest Home Lending

Reports home loan balances, offset positions and an indicative redraw amount. Read only: nothing here draws down, redraws or restructures a loan.

This service is an illustration built on the CBA side of the boundary. It is not a Raidiam product. It exists to show what a resource server can demand of an agent, and to show that a refusal can always be explained.

What an agent has to discover

Resourcehttps://rs-lending.demo.cba.raidiam.io
Authorization serverhttps://bankwest.demo.cba.raidiam.io
Trust anchorhttps://authority.directory.cba.raidiam.io/authority/5a27c88b-97ed-4d37-a3c8-59c66b19aa25
Detail typeslending_read
Scopesopenid, lending.read
Sender constrainingDPoP verified when presented, required for bound tokens
Mutabilityread only

Authorization detail types

lending_read

Authority to read loan balances, offset positions and indicative redraw availability. It moves no money.

Required members: type purpose

Optional members: none

{
  "type": "lending_read",
  "purpose": "Report the customer's lending position"
}

Token claims this resource decides on

Tools

ToolPurposeRequiresEffect
loan_balance Balance and rate on each home loan, or on one named loan. lending_read read only
offset_position The offset balance attached to each loan and the interest it is offsetting. lending_read read only
redraw_quote Indicative redraw available on a loan. Information, not an instruction. lending_read read only

Guardrails, published in advance

Every call carries a token from the named authorization server

Calls are accepted only with an access token issued by https://bankwest.demo.cba.raidiam.io and addressed to this resource as its audience. A token minted for a different resource is refused even when it is otherwise valid.

Refusal reason missing_access_token, invalid_token · decided at authorization · policy id rs.authenticated_caller

What clears it: Read this metadata document, then request a token from the authorization server it names, with this resource as the audience.

Authority is the RFC 9396 detail type, not a scope

Each tool names one authorization_details type. The token must carry that type, or an umbrella type that narrows to it. Holding a scope, or holding authority for a neighbouring resource, does not admit the call.

Refusal reason insufficient_authority · decided at authorization · policy id rs.authority_gate

What clears it: Obtain a token carrying the detail type the tool names. Delegation only ever narrows, so the delegating envelope must already contain it.

A revoked delegation stops working before its tokens expire

Revocation arrives as a Shared Signals event and is applied to the delegation, not to a single token. Every token issued under a revoked delegation is refused from that moment, whatever its expiry says.

Refusal reason delegation_revoked · decided at authorization · policy id rs.revocation_honoured

What clears it: The customer must grant a fresh delegation. There is no way to appeal a revocation at the resource.

Sender constrained tokens are bound to the key that holds them

A DPoP proof is verified whenever one is presented, and is required whenever the access token names a key in its cnf.jkt claim. Each proof is accepted once, so a captured proof cannot be replayed.

Refusal reason dpop_proof_required, invalid_dpop_proof, dpop_key_mismatch, dpop_proof_replayed, access_token_not_dpop_bound · decided at authorization · policy id rs.dpop_binding

What clears it: Request the access token with a DPoP proof so the authorization server binds it to your key, then send a fresh proof with every call.

Bankwest Home Lending never changes state

This resource publishes read_only true and exposes no path that writes. A mutating tool is refused before it runs, regardless of the authority the caller presents, so an agent cannot widen its own position by writing here.

Refusal reason resource_is_read_only · decided at authorization · policy id rs.read_only_resource

What clears it: State changing instructions belong to the resource that owns the record. This one only reports.

A malformed request is refused with the reason it was malformed

Arguments are validated before any business rule runs, and the refusal names the argument at fault rather than returning a bare failure.

Refusal reason tool_error, invalid_amount, unknown_tool · decided at execution · policy id rs.request_validity

What clears it: Correct the named argument. The tool schemas are published in this document.

A group is not one trust boundary

This resource accepts tokens from the Bankwest platform only. A token from another CBA Group platform is refused whatever authority it carries, because the issuer is not the one this resource names. Being inside one corporate group does not make two platforms one trust boundary.

Refusal reason untrusted_issuer · decided at authorization · policy id lending.brand_boundary_is_real

What clears it: Obtain authority from the Bankwest platform this resource names in its protected resource metadata.

Nothing here moves a loan

Drawdown, redraw and restructure are not offered at any authority. An indicative redraw amount is information rather than an instruction, and acting on it happens elsewhere under a different authority with a human in it.

Refusal reason resource_is_read_only · decided at execution · policy id lending.read_only_by_construction

What clears it: Redraw is requested by the customer through Bankwest.

Observability

Every admission decision, allowed and refused, is recorded with the policy that decided it and the values it turned on. Read them at /decisions.