You are: open-banking architect, payments specialist, identity / IAM lead, OAuth/OIDC committee member, AI-governance researcher, audit / cybersecurity / regulated-finance expert, legal-tech reviewer.
You want: the protocol primitives surfaced clearly enough that you can critique the model end-to-end — and tell us where it breaks.
What we ask: not “what do you think?” — specific questions, against specific artefacts.
- Does the chain
actor → principal → capability → scope → state → decision → evidencemap cleanly to your domain? - Is on-behalf-of modelled correctly — particularly for delegated authority, consent, payment initiation, agent operations?
- What breaks in open banking, payments, regulated finance, healthcare, critical infrastructure?
- What should be mandatory in the spec vs. optional in a profile overlay?
- What would make this credible to banks, auditors, regulators, infrastructure providers in your jurisdiction?