The gate sits on the routed surface — a payment rail or a commitment instrument — tiers each action against RAFCF, and returns a first-class HELD status in milliseconds, so a human decides without ever blocking the agent's thread.
One material action, from the agent's call to the recorded decision and its tie-out to the accounting entry.
A commitment — approving an invoice, issuing a purchase order, changing a payee’s bank details — or a movement: a vendor payout, refund, or treasury transfer.
The action is routed through Reddix at the point of execution — not scraped after the fact.
Reversibility and materiality decide the tier, drawn from the versioned Finality Registry. Tier 0–1 clear automatically; Tier 2+ is held. Unknown actions default to the higher tier and are flagged, never silently lowered.
A stable identifier is attached at classification and propagated into the executing instruction and the resulting accounting entry wherever each format permits.
The agent receives a first-class HELD status in milliseconds and moves on — no open connection, no timeout.
The held action surfaces for maker-checker review with full context: agent, counterparty, tier, amount.
A human resolves it on their own time. On approval, Reddix releases the instruction. The approver is distinct from the initiator and mapped to your segregation-of-duties model.
The decision, the approver, and the true outcome — released, denied or expired — are hash-chained into the record. An expiry is never recorded as a human decision.
The gate never lives inside the agent's tool-call thread. CO-3.3
How each connects — and why adoption is easy, earned, or trust-gated.
How it connects: read-only — Reddix records and classifies every agent financial action, commitment and movement alike, with no code in your payment path.
Why it's easy: nothing changes for the agent. You see governed volume and tier distribution in your own numbers before committing to anything.
How it connects: material actions are routed through the inline gate, one surface at a time, with fail-open / fail-closed behaviour agreed per tier in advance.
Why it's earned: inline is opt-in and conformance is per-surface — you decide which surfaces and thresholds cross the gate, and expand as trust grows.
How it connects: the inverse is registered at classification and executed on trigger; where no mechanism exists it degrades to prepare-and-instruct, then to documented claim.
Why it's last: it depends on a trusted gate and a proven record — turned on once the first two rungs have earned it.
A normative design constraint, not an implementation preference. CO-3.4 · §8
Value remains with your organization and its existing financial institutions throughout. Reddix is never a counterparty to the movement and never a party to the funds — adopting the framework introduces no new institution into the flow of funds and creates no new counterparty exposure.
A control plane holding an instruction and one holding money look similar in a product diagram and are entirely different in law, in risk, and in what an auditor must evaluate. An implementation that never receives, holds, or directs custody of value avoids the question — without weakening any control objective.
Run Reddix at Level 1 in shadow mode for 30 days and see your governed volume, tier distribution and exposure in your own numbers — before anything goes inline.