Observer Protocol is what refuses and what proves. Agentic Terminal is how an institution operates it: who may request authority, who may grant it, what they may grant, and what record that leaves.
It is an enterprise product, deployed as an MCP server inside your own perimeter. It takes no custody of funds and holds no signing keys and no credentials, and it is not in your payment path.
Agentic Terminal runs as an MCP server in your infrastructure, operated by your team or by ours. There is no hosted tier, no account to create, and no tenancy on our side to be in scope for your review.
No funds, no signing keys, no credentials. The enforcement point reads the mandate it enforces and holds no key that could issue, alter or re-sign one. There is no store on our side to protect and no lookup for us to gate.
The control sits at the boundary that already holds your credential, before an instruction exists. A refusal anywhere an agent can route around it is advice rather than a control, which is why the enforcement point is the boundary and not a report on one.
If Agentic Terminal disappeared tomorrow, every credential it issued would still verify, because verifying one never involved it. The verification itself needs nothing from us. This is the operational surface around that property, not a substitute for it.
Wherever three parties exist, these controls have something to bind. Where only two do, they mostly do not. The three are: whose money it is, who is authorised to move it, and who may need proof of what was authorised.
Anywhere authority to disburse is delegated, written down, and audited. The same three parties appear on the asset side: a fund or its general partner, an administrator processing capital calls and distributions on its behalf, and a depositary or auditor obliged to verify. Each of the three can check independently, and none of them has to trust the other two or involve us.
Three columns, in the same words agenticterminal.io uses, so a reader comparing the two pages is comparing one register rather than two vocabularies. A capability moves between columns by being built, never by being described differently.
They describe different layers, so neither contradicts the other. At the protocol layer it is built: verification refuses a credential whose status entry is set, and refuses just as firmly when the list cannot be fetched or decoded. The machinery was exercised end to end against the deployed service on 7 August 2026: create a list, allocate an index, set a bit, serve it, verify it, and both refusals. Un-revoking was refused as terminal.
At the console layer it is not: the automated path an operator would use to drive that machinery is designed and not built, so in this deployment a credential is marked revoked by hand. The guarantee a counterparty gets is the protocol one. The convenience an operator gets is the part that is missing.
One further limit, stated because it bounds the first paragraph: the status list's own signature is not yet checked on the delegation path, so that guarantee is currently as strong as control of the address serving the list, and no stronger.
The Lightning demonstration was signed by a demo key. 200,000 sat was denied against a 100,000 sat ceiling at the node's own signing boundary, with local balance available and a live channel to the destination, and a 10 sat payment to the same destination over the same channel settled in the same session. That is what makes it a policy decision rather than a routing or liquidity failure. The mandate for it was signed by a demo key generated on the box, not by our production issuer.
The payout rail has an adapter and no processor. No payment has been made on the bank payout or card rails. The claim that one mandate spans rails is a claim about the policy model, not a report of payments made.
Principal-as-issuer is specified and not built. Mandates are signed by our issuance service on the principal's behalf today. The credential names the principal; the signature over it is currently ours.
The line between the two is not open versus paid. It is primitive versus operation.
Free, open source, self-hostable. The verification logic is public and anyone can implement it, extend it, or run it themselves. It does not custody funds, execute payments, or control access.
How an institution operates the protocol: who may request authority, who may grant it, and what record that leaves. Observer Protocol is the foundation. Agentic Terminal is the business.
We are working directly with a small number of organisations who disburse on someone else's behalf and need this control to exist before they can widen what their agents are allowed to do. If the status section above reads as the shape of your problem rather than a list of gaps, that is the conversation we want.