Insight

Read First. Earn the Right To Act.

Banks grant access one system and one action at a time. Software should earn it the same way. Ask any vendor what it has shown you with read access alone.
Two colleagues review a tablet in a glass-roofed office.
Sagi Ittah
Written by
Sagi Ittah
In a regulated institution, access is not granted once at signature. It is earned system by system and action by action, and software that asks for all of it up front has misread how the buyer works.

Most enterprise software asks for permission it has not earned yet: connect everything, grant access, then let us prove value. In a bank or regulated payments company, that sequence is backwards. Nobody should hand a new vendor the ability to change systems before the vendor has shown that it understands what is already happening inside them. Seeing comes before acting.

Trust should be earned one permission at a time

Start with read access. Connect to the processor, the ledger, the bank and the case system, and watch. Show where two systems disagree about the same payment, where a balance does not reconcile, and where a transaction took a path the agreement did not allow. Show the institution something it did not already know. Then let the people who own the operation decide whether the system has earned the right to do anything about it.

That changes the sequence completely. Read first and prove value. Then grant one action, in one system, for one defined purpose, and watch that too. Expand only when the evidence supports it. Trust gets earned in pieces rather than handed over at signature.

This is not a slower path to autonomy

It is tempting to call this cautious. It is not. It is a better access model.

A single broad permission says: we trust this vendor to act. Scoped permission says: we trust this system to take this action, in this environment, under these conditions, and we can revoke that permission without touching anything else. That is a very different architecture.

It also changes the security conversation. The first review is about whether the vendor can read defined data from defined systems, not whether it should be allowed to write into critical financial systems. Security and architecture teams already know how to have that conversation. The harder permissions come later, once there is evidence to justify them.

Cordant is built to start by reading

Cordant starts read-only. It connects to what the institution's systems already produce through APIs, webhooks and files, and it changes none of them. It reads what happened, compares it with what should have happened and shows the differences to the people who own them. The decision stays with the institution.

Read-only is the trust model, not a limitation to get past before the real product starts. Cordant should be able to prove it understands the operation before anyone gives it permission to affect the operation. Any permission to act, if an institution ever grants one, should be earned the same way: one system, one action and one permission at a time.

Ask what the vendor has earned

Before you give any vendor the right to act on your systems, ask a simpler question: what has it shown you with read access alone? What did it find, and was it right? Could your team verify the evidence? Did it understand the systems well enough to explain what happened before asking permission to change anything?

If the answer is nothing yet, the request to act came too early.

Money already moves in real time. The decisions should too.

‍

Continue reading
A man works with a laptop and notebook.
September 22, 2026
Insight
Put The Command Center in Place Before the Ai Operating System
Before an institution gives agents authority over financial operations, it needs a command center that can tell them what actually happened, what should have happened and which record is right when the systems disagree.
Read article
A man considers his work beside a laptop in an office.
September 21, 2026
Insight
Money Moves in Seconds. Finding Out What Happened to It Still Takes Days
Payments now settle in a quarter of the time they took five years ago, yet finding out what went wrong with one still takes as long as it always did, and this year's research shows why.
Read article
Traffic light trails run through a city financial district at night.
September 21, 2026
Insight
Your Best Operators Know What Your Systems Do Not
Your most experienced operators carry a working model of how your operation really behaves, none of your systems records it, and it is the context your agents will need most.
Read article