MiddleLeap
Menu

Portfolio · Regulated reference build

Open Finance
Backoffice.

A bank-neutral operations platform for running UAE Open Finance in both roles: LFI for inbound third-party traffic and TPP-of-record for outbound platform services.

Private evidence snapshot · repository main at 99ab0dd · reviewed 11 July 2026

Executive view

A regulated operating model made tangible.

Backoffice is MiddleLeap's flagship delivery proof: a synthetic-only reference platform showing how Open Finance obligations can become governed workflows, architecture and evidence.

01 / Problem

Operations, not APIs

Banks need one operating layer for consent, servicing, reconciliation, approvals, audit and lineage across LFI and TPP roles.

02 / For whom

Banks and platforms

Relevant to institutions turning a regulatory mandate into an operable platform and accountable control model.

03 / Evidence

Demo-complete

A working reference implementation, quality gates and repository evidence demonstrate the designed control chain.

04 / Boundary

Not production proof

The build remains synthetic and has not yet cleared bank integration, live data, production scale or regulator examination.

05 / Advisory value

Controls become architecture

The work makes implementation trade-offs visible early enough to shape strategy, operating model and investment.

Open Finance is a regulated operation—not only an API programme.

The platform joins consent operations, billing, reconciliation, risk, compliance and audit into one controlled operating surface. A single event can become a care dispute, finance break, risk signal, operational case and four-eyes approval without losing lineage.

Problem

Fragmented controls

Banks need to evidence obligations across two participant roles and multiple internal functions.

Proposition

One operating layer

A role-scoped back office over the Nebras scheme surfaces, with consistent approvals, audit and lineage.

Learning

Controls are architecture

Four-eyes, RLS, secure egress and provenance cannot be retrofitted after product delivery.

One contract, multiple governed surfaces.

The portal and agent interface reuse the same BFF contract. External systems sit behind P1–P9 ports, each with demo and enterprise adapters, so bank adoption replaces edges without branching the application core.

UsersBank operatorsCare · Finance · Risk · Ops
AgentsMCP clientsGoverned admin tools
ExperienceNext.js portalScope-gated institutional UI
Agent interfaceMCP gatewayContract-derived catalogue
Control coreHono BFF + OpenAPIAuth · scopes · approvals · idempotency
BoundaryPorts P1–P9sim ↔ enterprise adapters
EvidencePostgreSQL + RLSInsert-only audit · BCBS 239 lineage
ExternalNebras + bank estateSecure egress · no direct bypass

The first cloth off The Loom: a governed double diamond feeding a spec-first delivery loop.

The Open Finance Backoffice is the first evidenced implementation of The Loom. Its autonomous loop carried 134 of approximately 139 backlog stories to done under quality gates, synthetic-data constraints and human four-eyes merge. The method is reusable; the Open Finance regulation, brand, contracts and controls are this implementation's pattern.

01

Discover

Evidence, problem framing and data-governance gates

02

Develop

Parallel solution directions and a recorded decision

03

Specify

PRD, OpenAPI contract, ADRs and failing acceptance tests

04

Implement

One story, one worktree, one human-reviewed PR

05

Verify

Contract, security, lineage, E2E and release evidence

Technical build recordAI build system · Technology · Quality controls

The model proposes. The harness constrains. Humans decide.

The repository documents Claude Code as the build agent. No Codex build provenance was found in the reviewed repository snapshot. Product MCP and build-time MCP are deliberately reported separately.

Build agent

Claude Code

The documented autonomous build loop is /loop /next-story. Commits retain Claude session and build-model provenance.

Domain skills

Seven repository skills

discovery, brand-render, develop, next-story, implement-story, spec-change and run-ofbo encode the delivery method.

Review agents

Four bounded reviewers

Contract conformance, regulatory hard stops, data governance and discovery-boundary checks remain separate judgements.

Pre-action controls

Four Claude Code hooks

Worktree policy at session start; PII, spec and test-integrity tripwires before file mutations.

Product interface

OFBO MCP gateway

A contract-derived MCP layer exposes governed BFF operations without creating a second auth or approval path.

Design evidence

Stitch MCP

The build log records Stitch MCP use to verify the institutional UI tokens and reference screens.

Worktree isolationSpec + test tripwiresBounded reviewersHuman mergeSealed provenance

A portable TypeScript platform with regulated-data controls.

TypeScriptNext.js 15 + React 19Hono BFFOpenAPI-generated contractsPostgreSQL + RLSMCP SDKCloudflare WorkersOpenNextRailwayVitest + Playwright + axeSemgrep + StrykerJSTerraform

Green means more than tests passed.

Q1 / Q1b

Build integrity

Build, unit tests, generated-artifact drift and anti-reward-hacking controls.

D1–D9

Discovery gates

Evidence, governance, prototype boundaries, stakeholder reaction and delivery traceability.

Q2 / Q2b

Static integrity

Lint, typecheck, SAST, secrets scanning and documentation-drift detection.

Q3

Runtime integrity

Postgres integration, contract verification and Playwright portal journeys.

Q4 / Q4.5

Regulatory integrity

Dependency review, security controls and BCBS 239 lineage validation.

Q5

Human release

Manual approval backed by a SHA-256-sealed release-evidence and agent-provenance bundle.

Demo-complete. Enterprise adoption is the next boundary.

M0

Foundation

Delivered

M1

Substrate + demo

Delivered

M2

Customer care

Delivered

M3

Reconciliation

Delivered

M4

Analytics

Delivered

M5

Hardening

Delivered

M6

Bank adoption

Per-bank engagement

89OpenAPI paths in the reviewed contract
29PostgreSQL migrations in the repository
254Tracked test/spec files across the monorepo
M0–M5Delivered and demonstrable before enterprise port swaps
Known boundary

The public environment is synthetic-only and permanently non-production. M6 requires an adopting bank's enterprise systems, credentials, gateway posture and port-by-port contract acceptance. Service-to-service mTLS is therefore tracked as an enterprise gateway responsibility, not simulated in application code.

Claims are grounded in a reviewed private build record.

The repository is not publicly accessible. This register names the material reviewed; detailed source access can be considered during appropriate diligence.

R1Repository overview and statusReviewed
R2Binding build conventionsReviewed
R3Claude Code hooksReviewed
R4Product MCP configurationReviewed
R5Architecture overviewReviewed
R6Quality-gate workflowReviewed
R7Development backlogReviewed
R8Agentic build recordReviewed

What this venture proves

Regulated operating controls can be designed into the platform from day one.

Bring the architecture, operating-model and AI-delivery learning into your Open Finance mandate.