Agent Marketplace CBA side, mock catalogue
Illustrative reference model

This is a CBA side illustration standing in for the catalogue the bank already runs, such as ServiceNow or Backstage. It is deliberately thin. What is being demonstrated is the handoff, not the catalogue.

Catalogue ag-workforce-ops

Operations Reconciliation Agent

Reconciles supplier invoices against settled payments for group operations staff.

Catalogue: registered Identity: issued production version 1.2.1

Held here, by the catalogue

Registration

Catalogue id
ag-workforce-ops
Business unit
Group Operations, Reconciliation
Legal entity
Commonwealth Bank of Australia
Division
agentic
Accountable owner
Group Operations Automation
Version
1.2.1
Environment
production
Repository
https://github.com/commbank-agentic/operations-reconciliation
Software bill of materials
sbom/operations-reconciliation-1.2.1.cdx.json
Risk assessment
RA-2296
Change reference
CHG-4419
Registered by
Group Operations Automation

None of this is in the Trust Controller, and none of it needs to be. This is what a catalogue is for.

Held elsewhere, by the Trust Controller

Identity

Entity id
https://agent-workforce-ops.demo.cba.raidiam.io
Authorisation server
CBA Workforce Identity Platform
Capability role
cba.agentic.workforce.assistant
May request
accounts_readsupplier_invoice
May move money
no
Federation roles
cba.oidc.participantcba.agentic.membercba.agentic.workforce.assistantcba.accounts.readercba.supplier.reader
Manufacturer
CBA Agent Provider
Signing key
kms://cba-group/agentic/operations-reconciliation
Lifecycle state
issued

An internal operations agent that reconciles invoices against settled payments for a staff owner.

Published by the group against the capability role. The catalogue does not write it and cannot change it.

Shown here as a last known outcome. This app did not decide any of it, cannot change any of it, and would be misrepresenting the model if it implied otherwise.

What this agent calls

Integration

The protected resources this agent is built to reach. Being built to call a resource is not the same as being entitled to, which is what the capability role decides and the delegated envelope then narrows.

Supplier and Invoice API

svc-supplier

Accounts API

svc-accounts