Operations, not APIs
Banks need one operating layer for consent, servicing, reconciliation, approvals, audit and lineage across LFI and TPP roles.
Portfolio · Regulated reference build
A bank-neutral operations platform for running UAE Open Finance in both roles: LFI for inbound third-party traffic and TPP-of-record for outbound platform services.
Private evidence snapshot · repository main at 99ab0dd · reviewed 11 July 2026
Executive view
Backoffice is MiddleLeap's flagship delivery proof: a synthetic-only reference platform showing how Open Finance obligations can become governed workflows, architecture and evidence.
Banks need one operating layer for consent, servicing, reconciliation, approvals, audit and lineage across LFI and TPP roles.
Relevant to institutions turning a regulatory mandate into an operable platform and accountable control model.
A working reference implementation, quality gates and repository evidence demonstrate the designed control chain.
The build remains synthetic and has not yet cleared bank integration, live data, production scale or regulator examination.
The work makes implementation trade-offs visible early enough to shape strategy, operating model and investment.
Why it exists
The platform joins consent operations, billing, reconciliation, risk, compliance and audit into one controlled operating surface. A single event can become a care dispute, finance break, risk signal, operational case and four-eyes approval without losing lineage.
Banks need to evidence obligations across two participant roles and multiple internal functions.
A role-scoped back office over the Nebras scheme surfaces, with consistent approvals, audit and lineage.
Four-eyes, RLS, secure egress and provenance cannot be retrofitted after product delivery.
Product architecture
The portal and agent interface reuse the same BFF contract. External systems sit behind P1–P9 ports, each with demo and enterprise adapters, so bank adoption replaces edges without branching the application core.
The Loom · reference implementation
The Open Finance Backoffice is the first evidenced implementation of The Loom. Its autonomous loop carried 134 of approximately 139 backlog stories to done under quality gates, synthetic-data constraints and human four-eyes merge. The method is reusable; the Open Finance regulation, brand, contracts and controls are this implementation's pattern.
Evidence, problem framing and data-governance gates
Parallel solution directions and a recorded decision
PRD, OpenAPI contract, ADRs and failing acceptance tests
One story, one worktree, one human-reviewed PR
Contract, security, lineage, E2E and release evidence
AI build system
The repository documents Claude Code as the build agent. No Codex build provenance was found in the reviewed repository snapshot. Product MCP and build-time MCP are deliberately reported separately.
The documented autonomous build loop is /loop /next-story. Commits retain Claude session and build-model provenance.
discovery, brand-render, develop, next-story, implement-story, spec-change and run-ofbo encode the delivery method.
Contract conformance, regulatory hard stops, data governance and discovery-boundary checks remain separate judgements.
Worktree policy at session start; PII, spec and test-integrity tripwires before file mutations.
A contract-derived MCP layer exposes governed BFF operations without creating a second auth or approval path.
The build log records Stitch MCP use to verify the institutional UI tokens and reference screens.
Technology
Quality system
Build, unit tests, generated-artifact drift and anti-reward-hacking controls.
Evidence, governance, prototype boundaries, stakeholder reaction and delivery traceability.
Lint, typecheck, SAST, secrets scanning and documentation-drift detection.
Postgres integration, contract verification and Playwright portal journeys.
Dependency review, security controls and BCBS 239 lineage validation.
Manual approval backed by a SHA-256-sealed release-evidence and agent-provenance bundle.
Development record
Delivered
Delivered
Delivered
Delivered
Delivered
Delivered
Per-bank engagement
The public environment is synthetic-only and permanently non-production. M6 requires an adopting bank's enterprise systems, credentials, gateway posture and port-by-port contract acceptance. Service-to-service mTLS is therefore tracked as an enterprise gateway responsibility, not simulated in application code.
Evidence register
The repository is not publicly accessible. This register names the material reviewed; detailed source access can be considered during appropriate diligence.
What this venture proves
Bring the architecture, operating-model and AI-delivery learning into your Open Finance mandate.