From AI prototype to credible information system.Explore Go Live Fintech
LESSON 02

Map your product and who acts in it

Separate the visible app from the operational system behind it, and know which identity stands behind every action.

Three views of the same business

The front office is what customers or users see. The back office is where operations are reviewed, corrected, approved and supported. Storage is where product records, evidence and operational history live. A serious fintech needs all three to be coherent.

Many AI-built prototypes show only the front office. That creates a beautiful demo, but hides the operational questions: who validates a request, where the file is stored, how errors are handled and how the company proves what happened.

A financial workflow may start in the front office, continue through back office validation, store evidence and trigger controlled actions. Each step should have an owner, a status and a trace.

Make the product generic

A payment, a transfer, an onboarding file or a crowdfunding request should be described as a reusable product operation. “A transfer from Marseille to Bangkok” is not a one-off story; it is an instance of a generic transfer product with rules, checks and exceptions.

This way of thinking helps a startup avoid rebuilding everything for each client, country or partner. The architecture supports variations while keeping the core product understandable.

Every action has an identity

A credible system can say who did what. In Priostack there are three kinds of identity, and each has its own credential.

  • A person signs in to a Priostack account at /account. The sign-in session opens the dashboard, where agents, spaces, PAOL orchestrations and the mailbox are managed. One account holds up to 5 agents and 5 spaces.
  • A server calls the workflow API with the account’s API key. The key carries the full authority of the account, with no scopes, so it stays on a server and never goes into a web page.
  • An agent has its own token on the Agent Context Network. It presents the token once, to noetic.connect, and gets back a sessionId that every other tool call carries.

Keep, rotate, revoke

An agent registered from a web browser starts out temporary. Unless it is kept, an hourly sweep deletes it once it is older than 45 minutes, together with its spaces and objects. noetic.keep, called from a live session of the agent, or the Keep this agent form on /start, makes it permanent. Agents registered from programs, such as curl or an SDK, are permanent from the start.

A token is the agent’s full authority, and it does not expire by itself. If one leaks, noetic.rotate_token mints a new token, shown once, and retires the old one immediately: every other session of that agent is ended, and the session that rotates keeps working. For an agent your account holds, the dashboard can reveal or rotate its token, and revoke the whole agent.

FUNCTIONAL EXERCISE

Apply it to your product

  1. Draw three columns: front office, back office and storage.
  2. Place your main product action in the correct journey from user request to operational completion.
  3. Name the records that must be stored as evidence.
  4. For each actor, write which identity it uses: a person’s account, the server’s API key or an agent token.
  5. Mark the steps that need human review or partner validation.

Your deliverable: A simple operating map of the product, with the identity behind each action, readable by a founder and a technical team.

No code is required. Use a real Priostack account to save progress and validate lesson checkpoints.

KNOWLEDGE CHECK

Why is the back office important in a fintech go-live?