Security

Financial authority requires security by design.

Machine Allowance is being built as a control plane for money movement. Security is not a feature—it is the product.

Designed for least-privilege allowance policies

Every agent will start with the narrowest useful allowance and be scoped up deliberately by policy, not by inheritance.

Designed for signed authorization records

Authorization decisions are designed to be cryptographically signed and tied to the evaluating policy version.

Role-based access controls

Fine-grained roles govern who can register agents, edit policies, approve exceptions and view audit evidence.

Append-only audit history

The Allowance Ledger is designed as an append-only record of identity, intent, decision, approval and payment outcome.

Short-lived authorization tokens

Approvals are designed to convert into narrowly scoped tokens with explicit expirations to limit downstream misuse.

Configurable policy expiration

Allowances can be time-bound to a task, project or reporting period, then reviewed before renewal.

Separation of duties

The person who owns an agent, the person who approves its policies and the person who reviews evidence can be distinct.

Encryption in transit and at rest

All authorization traffic and stored records will be encrypted using industry-standard algorithms.

Where we are

Machine Allowance is in active development with design partners. SOC 2 and other security certifications are on our roadmap and will be published as they are completed. We'd rather show you the real status than a badge wall.