Obsta CoreGate · The control plane for agentic banking

Enable agentic banking without handing over control.

CoreGate lets AI agents interface with legacy bank systems through deterministic permissioning, audit, kill-switch governance, and bounded action controls — so every action is attributable, non-destructive by default, audited, and instantly stoppable.

Deterministic — no ML in the control path Agent-agnostic · system-agnostic Pattern proven · clean-room reference in preparation
The problem every bank now has

Banks have systems of record. They now want systems of action.

AI agents can become that action layer. The technology is ready — permission is not. What blocks agentic AI in a regulated bank is not model quality. It is governance, identity, auditability, and operational risk. No CISO, CRO, or regulator will let an agent touch a core system on the promise that "the model behaves."

THE FEAR

One wrong action

An agent deletes, over-mutates, or moves something irreversible — and no one can prove what happened or stop it in time.

THE GAP

Prompts aren't controls

"Please don't" is not a control a board can sign off. Guardrails written in English fail silently.

THE COST

Frozen at the POC

Pilots stall before production because risk, compliance, and audit can't get a structural guarantee.

What CoreGate is

A deterministic control plane between AI agents and your legacy systems.

It sits in front of whatever you already run — core banking, ledgers, ticketing, internal APIs. We do not replace or re-platform your internals: CoreGate wraps approved interfaces, mirrors your identity model, and exposes only bounded actions to agents.

INSIDE THE BANK

AI Agents

Any model, any vendor, any workflow. They request actions — they never get raw access.
COREGATE · KILLGATE

The gate

Bounded capability · identity mirroring · non-destructive by default · maker-checker on high-risk · full audit · instant kill switch. Deterministic.
SYSTEMS OF RECORD

Legacy & core

A connector exposes each approved system, one at a time — built under your controls, in your environment.

What it is

  • Regulated agent-enablement infrastructure
  • A structural boundary, enforced in code
  • Agent-agnostic and system-agnostic

What it is NOT

  • An AI model or autonomous decision-maker
  • A core-banking replacement
  • A data-exfiltration path — only bounded values leave
CONCRETELY

An agent can retrieve customer-case metadata, draft a remediation action, and open a ticket — but cannot move money, delete records, change limits, or write to core without maker-checker release. Every step is identity-scoped, recorded, and stoppable.

The spine · KillGate

Five controls that block unsafe agent actions before they run.

Every control is structural — enforced before an action runs, not detected after. CoreGate evaluates the action at the gate and blocks it there if policy denies it.

01 · BOUNDED

Capability

Agents get an allow-listed set of actions. Destructive operations are disabled at the code path — not policed by prompt.

02 · IDENTITY

Mirroring

Agents act under the bank's own ACL-respected principal. They see exactly what that identity may — never more.

03 · NON-DESTRUCTIVE

By default

Only non-destructive actions run by default. Irreversible or high-risk ones route through maker-checker, dual control, or human release before execution.

04 · AUDITED

Full provenance

Every action is attributed, idempotent, and recorded. Nothing crosses the boundary without redaction.

05 · KILLABLE

Instant switch

One global control suspends all agent capability immediately and deterministically, across every connector.

Together, the five give a bank the control evidence it needs before agents touch systems of record. The limits are enforced in code, not asked for in a prompt.

DEPLOYMENT

CoreGate runs inside the bank-controlled environment. Agent requests are mediated locally; secrets and sensitive payloads do not need to leave the bank boundary.

Proof, not slideware · the pattern is built

The KillGate pattern is built — and exercised against real enterprise workflows.

We did the hard version: a bounded agent interface where agents got real capability and the dangerous actions were made structurally impossible. For external evaluations — and to protect every client's confidentiality — a neutral, clean-room reference connector is being prepared, so a serious evaluator can see the same guarantees end to end, without exposure to any client-derived system. We will show it under a scoped walkthrough.

KillGate guaranteeHow the pattern enforces it
Bounded capabilityDestructive operations are disabled at the code path in both the command and agent interfaces; they refuse and make no call. Capability is retained behind a deliberate re-enable.
Identity mirroringAgents act under the system's canonical actor identity, so access-controlled data is visible only to those entitled — no token-claim escalation.
Provenance & auditProvenance headers, idempotency keys, and request IDs on every write; a redaction gate ensures only bounded values ever leave the machine.
Read-by-defaultAll read paths work without write authority; writes are explicit, confirmed, and paged-capped to protect the system of record.
5/5
KillGate guarantees built and enforced
0
irreversible actions reachable by an agent
100%
agent writes carry provenance + idempotency
What the lighthouse demo shows

At the end of the pilot, your risk & compliance team watches seven things happen.

Not a slide. A live sequence against one approved system, with seeded identities and a real audit trail — the whole decision in one sitting.

01

An AI agent requests a bounded action against one approved system.

02

The request is evaluated against identity, capability, and policy before anything runs.

03

A safe read path succeeds — scoped to exactly what that identity may see.

04

A destructive or out-of-scope action fails before it reaches the system.

05

A high-risk action routes to maker-checker approval / human release.

06

A full audit trail: actor, agent, request ID, idempotency key, and decision.

07 · THE MOMENT

One global kill switch suspends all agent capability immediately — across every connector, deterministically. That switch is the whole decision.

Engagement & pricing

Land with a lighthouse. Expand per system.

Priced as risk-reduction infrastructure for the enterprise — not as a utility. Every engagement begins with a paid, scoped pilot that ends in a demo to your risk and compliance teams.

START HERE

CoreGate Lighthouse — from $125k

A fixed-fee paid pilot: one system, one or two workflows, with audit trail, kill switch, and identity mapping — ending in a demo to your risk and compliance teams. 6–10 weeks. Pilot fees credit toward the first production year.

THEN SCALE

Production & enterprise — scoped

Production licensing and enterprise control-plane pricing are scoped by systems, connectors, audit requirements, and deployment model. We share the full pricing model in the scoping conversation.

The next step

Let's run one lighthouse.

Pick one legacy system and one workflow. In weeks, your risk and compliance teams will watch AI agents operate it — and watch a single switch shut it all down. That demo is the whole decision.

banking@obsta.ai