Least authority
APIs and agent permissions are designed around scoped actions, explicit limits, and time-bounded authority.
Alloy is control-plane software for wallet operations. Customers keep funds, keys, provider contracts, and final authorization authority while Alloy coordinates transaction state, controls, and evidence around those boundaries.
APIs and agent permissions are designed around scoped actions, explicit limits, and time-bounded authority.
Missing authorization, unsupported operation state, policy denial, or approval pause should stop the workflow with a reason-coded receipt.
Native provider IDs, statuses, and exceptions remain visible so teams can debug without losing the original source of truth.
Suitable for design-partner workflow mapping where customers approve provider access and review operational evidence.
For bank and enterprise conversations, the review starts with network, data, tenant, and provider-responsibility boundaries.
Public trust language describes real provider or explicit no-signing control-plane profiles for external review.
Policy decisions, risk outcomes, approvals, provider events, denied actions, and reconciliation exports are designed to stay attached to the operating record so customer teams can inspect what happened without reconstructing it from tickets, CSV files, or screenshots.
Every route keeps Alloy's public story grounded in operating records, custody boundaries, and right-sized modules.
We will map the first workflow Alloy should stabilize, the custody boundary, and the modules that create evidence.
Prefer email? hello@alloy.build