GuardState Gateway
A narrow, independently governed boundary between approved financial actions and provider execution. Gateway verifies authority; it does not trust client-side intent.
Explicit command scope
Gateway commands bind the applicable workspace, financial action, correlation identity, validity window, nonce, idempotency identity, and typed input. Ambiguous or mismatched commands fail closed.
Independent authorization
Execution requires the applicable server-side or commissioned Edge authorization state, including Mandate, Authority Envelope, risk, policy, approvals, Acceptance, Permit, boundary identity, and provider capability evidence.
Provider separation
A cryptographically valid GuardState artifact does not force a broker, custodian, OMS, exchange, or other provider to execute. Providers retain their own legal, operational, account, and risk controls.
Failure behavior
Expired, malformed, replayed, mis-scoped, unauthenticated, or otherwise invalid commands are denied and evidenced. A denied command is not silently downgraded into a weaker execution path.