Overview
Allow workspace applications to call exact PayStream finance operations without direct database access.
Problem
Connected applications need finance services while PayStream remains authoritative for its financial resources.
Solution
Use app-scoped capability grants, trusted execution provenance, and PayStreamRuntime authorization across Handler, RCP, Bridge, EventBus, and ContextResolver actions.
How it works
Discover the application, probe capabilities, select PayStream operations and transports, save the app grant, and let all execution paths converge on operation, resource, and delegation authorization.
Who is this for
Workspace Administrator
Integration Engineer
Expected outcomes
- Finance capabilities shared without database coupling
- Exact per-app operation and transport authorization
Key metrics
Security impact
- Installed-app identity, capability metadata, PayStream app grants, integration connections/bindings, resource ownership, and execution audit state · PII: depends on the finance operations and resources authorized for the connected application
Compliance
- Workspace permissions, trusted execution, resource authorization, Core secrets, finance audit, and app-scoped grants.
Availability & next steps
Enterprise