Agent Marketplace CBA side, mock catalogue
Illustrative reference model

This is a CBA side illustration standing in for the catalogue the bank already runs, such as ServiceNow or Backstage. It is deliberately thin. What is being demonstrated is the handoff, not the catalogue.

Catalogue ag-ap-orchestrator

Accounts Payable Orchestrator

Runs accounts payable for business banking customers: reads supplier invoices and settles them inside a payment authority the customer approved once.

Catalogue: registered Identity: issued production version 2.3.0

Held here, by the catalogue

Registration

Catalogue id
ag-ap-orchestrator
Business unit
Business Banking, Accounts Payable
Legal entity
Commonwealth Bank of Australia
Division
agentic
Accountable owner
Kirsten Yeo, Accounts Payable Product
Version
2.3.0
Environment
production
Repository
https://github.com/commbank-agentic/ap-orchestrator
Software bill of materials
sbom/ap-orchestrator-2.3.0.cdx.json
Risk assessment
RA-2288
Change reference
CHG-4417
Registered by
Accounts Payable Product

None of this is in the Trust Controller, and none of it needs to be. This is what a catalogue is for.

Held elsewhere, by the Trust Controller

Identity

Entity id
https://agent-ap-orchestrator.demo.cba.raidiam.io
Authorisation server
CommBiz Identity Platform
Capability role
cba.agentic.ap.orchestrator
May request
supplier_paymentsupplier_invoiceaccounts_readaccounts_writepayment_initiation
May move money
yes, inside a delegated envelope
Federation roles
cba.oidc.participantcba.agentic.membercba.agentic.ap.orchestratorcba.accounts.readercba.payments.initiatorcba.supplier.reader
Manufacturer
CBA Agent Provider
Signing key
kms://cba-au/agentic/ap-orchestrator
Lifecycle state
issued

Holds the supplier payment umbrella a business customer approved, and delegates narrower authority to one sub agent per invoice. It is ELIGIBLE for accounts_write and still cannot obtain it, because that type sits outside the delegated envelope. Eligibility and envelope are two different gates, and this role is where that is visible.

Published by the group against the capability role. The catalogue does not write it and cannot change it.

Shown here as a last known outcome. This app did not decide any of it, cannot change any of it, and would be misrepresenting the model if it implied otherwise.

What this agent calls

Integration

The protected resources this agent is built to reach. Being built to call a resource is not the same as being entitled to, which is what the capability role decides and the delegated envelope then narrows.

Supplier and Invoice API

svc-supplier

Accounts API

svc-accounts

Payments API

svc-payments