{"group":"Commonwealth Bank Group","live":true,"model":{"note":"Brands, divisions and authentication patterns are modelled on the Commonwealth Bank from public information, so the federation matches the estate CBA operates.","domain":"demo.cba.raidiam.io","authority_split":{"modelled":true,"observable":false,"distinguished_by":"role namespace","namespaces":{"accreditation":"cba.accredited.","capability":"cba.agentic."},"note":"The estate models four authorities because that is the intended operating model, and the separation of accreditation from capability is a real architectural distinction. This deployment has one authority, so two trust marks issued under it cannot be told apart by their issuer, because their issuer is the same. What IS observable is the role namespace, which appears in the trust mark type: cba.accredited.* means the bank has assessed a party and will let it act at all, cba.agentic.* means what it may then ask for. Read the authority assignment below as the target operating model, not as something a consumer can verify today."}},"treatments":[{"id":"raidiam-product","label":"Raidiam product","note":"Shipping Raidiam capability. This is the Trust Controller and the views over it.","component":true},{"id":"reference-implementation","label":"Reference implementation","note":"Stands in for your authorisation server. In production this is Ping or Entra.","component":true},{"id":"cba-side","label":"CBA side","note":"On the bank side of the boundary, not Raidiam's. Some of these stand in for a system CBA already runs, and some are a system CBA would add. The evidence pack says which, one component at a time.","component":true},{"id":"open-standard","label":"Open standard","note":"Somebody else's published protocol. Nobody on this diagram owns it, and any conformant implementation behaves the same way. It marks a sentence about behaviour, never a box.","component":false}],"trust_anchor":"https://authority.directory.cba.raidiam.io/authority/5a27c88b-97ed-4d37-a3c8-59c66b19aa25","ops":[{"id":"op-netbank","name":"NetBank Identity Platform","treatment":"reference-implementation","stands_in_for":"the retail enterprise authorization server","issuer":"https://netbank.demo.cba.raidiam.io","openid_configuration":"https://netbank.demo.cba.raidiam.io/.well-known/openid-configuration","openid_federation":"https://netbank.demo.cba.raidiam.io/.well-known/openid-federation","token_endpoint":"https://netbank.demo.cba.raidiam.io/token"},{"id":"op-commbiz","name":"CommBiz Identity Platform","treatment":"reference-implementation","stands_in_for":"the business banking authorization server","issuer":"https://commbiz.demo.cba.raidiam.io","openid_configuration":"https://commbiz.demo.cba.raidiam.io/.well-known/openid-configuration","openid_federation":"https://commbiz.demo.cba.raidiam.io/.well-known/openid-federation","token_endpoint":"https://commbiz.demo.cba.raidiam.io/token"},{"id":"op-ibm","name":"Institutional Banking and Markets Identity Platform","treatment":"reference-implementation","stands_in_for":"the institutional authorization server","issuer":"https://ibm.demo.cba.raidiam.io","openid_configuration":"https://ibm.demo.cba.raidiam.io/.well-known/openid-configuration","openid_federation":"https://ibm.demo.cba.raidiam.io/.well-known/openid-federation","token_endpoint":"https://ibm.demo.cba.raidiam.io/token"},{"id":"op-bankwest","name":"Bankwest Identity Platform","treatment":"reference-implementation","stands_in_for":"the Bankwest brand authorization server","issuer":"https://bankwest.demo.cba.raidiam.io","openid_configuration":"https://bankwest.demo.cba.raidiam.io/.well-known/openid-configuration","openid_federation":"https://bankwest.demo.cba.raidiam.io/.well-known/openid-federation","token_endpoint":"https://bankwest.demo.cba.raidiam.io/token"},{"id":"op-asb","name":"ASB FastNet Identity Platform","treatment":"reference-implementation","stands_in_for":"the ASB authorization server","issuer":"https://asb.demo.cba.raidiam.io","openid_configuration":"https://asb.demo.cba.raidiam.io/.well-known/openid-configuration","openid_federation":"https://asb.demo.cba.raidiam.io/.well-known/openid-federation","token_endpoint":"https://asb.demo.cba.raidiam.io/token"},{"id":"op-commsec","name":"CommSec Identity Platform","treatment":"reference-implementation","stands_in_for":"the broking authorization server","issuer":"https://commsec.demo.cba.raidiam.io","openid_configuration":"https://commsec.demo.cba.raidiam.io/.well-known/openid-configuration","openid_federation":"https://commsec.demo.cba.raidiam.io/.well-known/openid-federation","token_endpoint":"https://commsec.demo.cba.raidiam.io/token"},{"id":"op-workforce","name":"CBA Workforce Identity Platform","treatment":"reference-implementation","stands_in_for":"Microsoft Entra ID","issuer":"https://workforce.demo.cba.raidiam.io","openid_configuration":"https://workforce.demo.cba.raidiam.io/.well-known/openid-configuration","openid_federation":"https://workforce.demo.cba.raidiam.io/.well-known/openid-federation","token_endpoint":"https://workforce.demo.cba.raidiam.io/token"}],"services":[{"id":"svc-payments","name":"Payments API","treatment":"cba-side","resource":"https://rs-payments.demo.cba.raidiam.io","endpoint":"https://rs-payments.demo.cba.raidiam.io/mcp/execute_payment","rar_detail_type":"payment_initiation","required_roles":["cba.payments.initiator"],"oauth_protected_resource":"https://rs-payments.demo.cba.raidiam.io/.well-known/oauth-protected-resource"},{"id":"svc-lending","name":"Home Lending API","treatment":"cba-side","resource":"https://rs-lending.demo.cba.raidiam.io","endpoint":"https://rs-lending.demo.cba.raidiam.io/mcp/loan_balance","rar_detail_type":"lending_read","required_roles":["cba.accounts.reader"],"oauth_protected_resource":"https://rs-lending.demo.cba.raidiam.io/.well-known/oauth-protected-resource"},{"id":"svc-cards","name":"Retail Cards API","treatment":"cba-side","resource":"https://rs-cards.demo.cba.raidiam.io","endpoint":"https://rs-cards.demo.cba.raidiam.io/mcp/list_cards","rar_detail_type":"cards_read","required_roles":["cba.accounts.reader"],"oauth_protected_resource":"https://rs-cards.demo.cba.raidiam.io/.well-known/oauth-protected-resource"},{"id":"svc-markets","name":"Markets API","treatment":"cba-side","resource":"https://rs-markets.demo.cba.raidiam.io","endpoint":"https://rs-markets.demo.cba.raidiam.io/mcp/list_holdings","rar_detail_type":"markets_read","required_roles":["cba.accounts.reader"],"oauth_protected_resource":"https://rs-markets.demo.cba.raidiam.io/.well-known/oauth-protected-resource"},{"id":"svc-accounts","name":"Accounts API","treatment":"cba-side","resource":"https://rs-accounts.demo.cba.raidiam.io","endpoint":"https://rs-accounts.demo.cba.raidiam.io/mcp/list_accounts","rar_detail_type":"accounts_read","required_roles":["cba.accounts.reader"],"oauth_protected_resource":"https://rs-accounts.demo.cba.raidiam.io/.well-known/oauth-protected-resource"},{"id":"svc-supplier","name":"Supplier and Invoice API","treatment":"cba-side","resource":"https://rs-supplier.demo.cba.raidiam.io","endpoint":"https://rs-supplier.demo.cba.raidiam.io/mcp/list_invoices","rar_detail_type":"supplier_invoice","required_roles":["cba.supplier.reader"],"oauth_protected_resource":"https://rs-supplier.demo.cba.raidiam.io/.well-known/oauth-protected-resource"}],"flows":[{"id":"flow-ap-envelope","name":"Business banking accounts payable, inside a bounded envelope","kind":"agentic-envelope","run":"/flows/flow-ap-envelope/run"},{"id":"flow-retail-servicing","name":"Retail customer servicing, read only by construction","kind":"servicing","run":"/flows/flow-retail-servicing/run"},{"id":"flow-partner-onboarding","name":"An external agent presents at a platform that has no record of it","kind":"dynamic-onboarding","run":"/flows/flow-partner-onboarding/run"},{"id":"flow-workforce-reconciliation","name":"Workforce agent reading business banking invoices across a platform boundary","kind":"cross-platform","run":"/flows/flow-workforce-reconciliation/run"}]}