One canonical architecture

Identity, budget, settlement, verification, and audit remain fused across every surface.

Control-plane layers

Ingress authority

Signed requests, key-version semantics, replay and idempotency fail-closed rules.

Ordered admission

Sequencer-backed deterministic ordering for money-sensitive writes.

Policy + verification

Policy bundles and IAS verification gate release outcomes.

Forensic truth

Operation + trace + audit chain continuity, plus signed webhook projections.