Assurance that rests on "our monitoring is very good" is a promise. Provable trust rests on a proof and a receipt. Writing on what that distinction means in practice — sector by sector, and control by control.
Claude Code now counts the rules a folder pre-approves — 278 in this repo — and drafts a trust boundary from evidence rather than a questionnaire. Both are the right instinct, and both stop one step short of the question those labels make askable: can the permitted operations, in some order, carry untrusted input out with no gate in between?
It comes with real spending controls — a budget, a per-payment limit, an approved-merchant list. Good controls. They also answer a narrower question than they look like they do: a $10 cap under a $500 budget authorizes fifty transactions, and money has no undo button.
An agent can take a sequence of authorized actions, and the sequence as a whole causes harm. Hugging Face and GitLost show the failure is architectural, not operational — and none of the four control layers answers the question it poses.
Banking's intelligent operating model rests on governance and trust. Neither can stay a promise once agents can act — a per-action check never holds a fact about the set of actions, and the exposure lives in the gaps between the checks.