Most enterprise software asks for permission it has not earned yet: connect everything, grant access, then let us prove value. In a bank or regulated payments company, that sequence is backwards. Nobody should hand a new vendor the ability to change systems before the vendor has shown that it understands what is already happening inside them. Seeing comes before acting.
Trust should be earned one permission at a time
Start with read access. Connect to the processor, the ledger, the bank and the case system, and watch. Show where two systems disagree about the same payment, where a balance does not reconcile, and where a transaction took a path the agreement did not allow. Show the institution something it did not already know. Then let the people who own the operation decide whether the system has earned the right to do anything about it.
That changes the sequence completely. Read first and prove value. Then grant one action, in one system, for one defined purpose, and watch that too. Expand only when the evidence supports it. Trust gets earned in pieces rather than handed over at signature.
This is not a slower path to autonomy
It is tempting to call this cautious. It is not. It is a better access model.
A single broad permission says: we trust this vendor to act. Scoped permission says: we trust this system to take this action, in this environment, under these conditions, and we can revoke that permission without touching anything else. That is a very different architecture.
It also changes the security conversation. The first review is about whether the vendor can read defined data from defined systems, not whether it should be allowed to write into critical financial systems. Security and architecture teams already know how to have that conversation. The harder permissions come later, once there is evidence to justify them.
Cordant is built to start by reading
Cordant starts read-only. It connects to what the institution's systems already produce through APIs, webhooks and files, and it changes none of them. It reads what happened, compares it with what should have happened and shows the differences to the people who own them. The decision stays with the institution.
Read-only is the trust model, not a limitation to get past before the real product starts. Cordant should be able to prove it understands the operation before anyone gives it permission to affect the operation. Any permission to act, if an institution ever grants one, should be earned the same way: one system, one action and one permission at a time.
Ask what the vendor has earned
Before you give any vendor the right to act on your systems, ask a simpler question: what has it shown you with read access alone? What did it find, and was it right? Could your team verify the evidence? Did it understand the systems well enough to explain what happened before asking permission to change anything?
If the answer is nothing yet, the request to act came too early.
Money already moves in real time. The decisions should too.




