The Drift Layer
Four Measures for Mandate Conformance
| Author | Matthew T. Kirby, Independent Researcher, River Falls, Wisconsin, USA — matthew.kirby@driftlayer.org |
|---|---|
| Date | 10 September 2026 |
| Version | 1 |
| Licence | CC BY 4.0 |
| First published | In the RPIB consultation response, 9 September 2026 |
Abstract
Four measures would make it answerable how often transactions executed by software stay inside the authority a person gave it. The response in which they were first published records that no public transaction-level conformance measure with a defined cross-rail denominator was found. They are set out here in the wording in which they were first published, in the author's response to the Bank of England's RPIB consultation of 9 September 2026, together with the ways each of them can be made to lie.
Provenance
These definitions were first published on 9 September 2026 in the author's response to the RPIB consultation, section Q17a. The wording below is that wording. Where any earlier working draft differs, the published text governs.
The four measures
1 · Evaluation coverage
The evidence in question is a signed mandate, a canonical commitment over the transaction, the evaluation criteria as pinned when the mandate was signed, and evidence of how the transaction was initiated. Anything missing one of these is neither a pass nor a failure — it is unevaluable.
2 · Mandate conformance
The denominator is evaluable, mandate-bound transactions — not all agent traffic. A rate computed over everything an agent did is a statement about instrumentation, not about conformance.
3 · Divergence incidence
Those six classes are a design taxonomy for a scoreboard, not a census of error codes already shipped one-to-one in ACP, UCP, AP2 or Open Banking v4.0.1. Live codes name a mismatch or a failed control; they do not yet publish this split.
No scaling denominator is prescribed here. A rate per thousand borrows its unit from card fraud reporting; counts reported against their base carry more information and disclose the volume, which a reader needs in order to read the rate at all.
4 · Unauthorised continuation
This is one line inside a richer measure, the divergence resolution split: of those divergences, how each ended — resolved by a signed user amendment, resolved by superseding the mandate, declined, expired unresolved, or still open — each carrying transaction value. The open bucket is not bookkeeping fussiness: no published profile defines a time-out for an unresolved divergence, so folding open cases into declines invents a result.
Unauthorised continuation is the line in that split that matters: money moved after an evaluation failed, with no fresh human signature.
Coverage is printed first
A conformance rate published without its coverage figure beside it describes only the subset that happened to be observable.
The word to use
Mandate conformance, never authorisation conformance. In payments, authorisation means issuer approval, so an authorisation conformance rate reads to that audience as a decline rate. The measure here is about the mandate, and the word has to say so.
How these can be made to lie
None of these is unjukeable, and it is worth saying so plainly. A mandate written loosely enough passes everything. A transaction that was never evaluated looks clean and is a coverage miss, not a conformance hit. Changing the evaluation criteria between mandates silently changes what conformance means. Chargeback files are a biased sample of pain and must never be published as a conformance rate. A metric published with its own failure modes attached is a measurement vocabulary; one published without them is marketing.
Implementing them
These definitions are free to implement and require no permission and no relationship with the author. The artefacts they are computed over — mandate, canonical commitment, divergence record, supersession record — have an open reference implementation at mandatepatch.org. Neither is a condition of the other.
Cite as
@misc{kirby2026measures,
author = {Kirby, Matthew T.},
title = {Four Measures for Mandate Conformance},
year = {2026},
month = sep,
howpublished = {\url{https://driftlayer.org/papers/definitions/}},
note = {Version 1}
}
Versions
Version 1 — 10 September 2026. First publication.
Versions are never overwritten. See versions and errata.
Disclosure
A US provisional patent application (No. 64/141,321) was filed on 26 August 2026 and precedes both the disclosure and the repository. The specification is published as Mandate Lifecycle Extensions for Agentic Payment Credentials, Technical Disclosure Commons, Defensive Publications Series no. 11517 (August 2026), under CC BY 4.0. A reference implementation of the artefact layer is published at github.com/MandatePatch/mandatepatch under Apache-2.0. The mechanisms described are one implementation of a more general requirement. Each licence governs what it names and nothing else.