Business authorisation dashboard
Each role sees only what it needs. A finance lead approves spend, compliance audits the trail, IT sees system health, not who paid whom.
Awaiting your approval
The Facilities Maintenance operations agent has requested to sub-delegate a £3,200.00 emergency contractor payment, above the £2,000 threshold that requires your explicit sign-off. Requested 2 hours ago.
Telemetry
One transaction in the last 24 hours fell outside this agent's established pattern. It stayed within every mandate threshold, so no suspension was triggered, logged for baseline review only. No transaction detail is shown here by design.
Mandates
Read-only in this view- Ceiling
- £8,000.00 / mo
- Vendors
- 6 approved
- Expires
- 31 Mar 2027
- Ceiling
- £25,000.00 / qtr
- Vendors
- 4 approved
- Expires
- 30 Jun 2027
Transactions & audit trail
DORA Art. 30| Date & time | Supplier | Amount | Mandate | Status |
|---|---|---|---|---|
| 22 Aug 2026, 11:20 | Crestline Office Supplies | £412.50 | Office Supplies | Completed |
| 21 Aug 2026, 14:05 | Reliant HVAC Services | £3,200.00 | Facilities Maintenance | Pending approval |
| 20 Aug 2026, 09:40 | Bright Print Co. | £96.00 | Office Supplies | Completed |
| 18 Aug 2026, 15:12 | Reliant HVAC Services | £1,150.00 | Facilities Maintenance | Completed |
Compliance & retention
Records are retained for a minimum of five years from the transaction date under the EU AML Regulation. This entry reflects the Register of Information Mastercard maintains on TrustElevate as an ICT third-party provider under DORA.
System & security
Incident and vulnerability handling status. No transaction or supplier data is shown in this view by design.
Reporting clock: 24hr early warning, 72hr notification, per the EU Cyber Resilience Act.
Mastercard compliance & competent authority
This tier is not filtered by counterparty or role. Mastercard's own compliance function and their competent authority see the same unrestricted view of TrustElevate as an ICT third-party provider, platform-wide, not scoped to any one business or consumer relationship.
Register of Information
Art. 28(3)The record Mastercard maintains on TrustElevate as an ICT third-party provider, reported to their competent authority annually. Shown here as TrustElevate holds it, so any discrepancy with Mastercard's own filing is visible immediately rather than found at inspection.
Sub-processors
Art. 29–30| Sub-processor | Function | Prior approval | Status |
|---|---|---|---|
| PQShield | Post-quantum protection of retained verification records | Confirmed, consortium onboarding | Approved |
| SIROS Foundation | EUDIW / EBW wallet infrastructure, mandate attribute storage | Confirmed, consortium onboarding | Approved |
| Cloud hosting provider | Platform infrastructure, EU region | Pending confirmation | Awaiting sign-off |
Incident & vulnerability reporting
DORA 4hr · CRA 24/72hr| Date | Type | Severity | Notified within deadline | Status |
|---|---|---|---|---|
| 14 Jul 2026 | Dependency vulnerability, non-exploited | Low | Yes, 19 hrs | Resolved |
No active or major incidents at present. The single logged item above is a routine, non-exploited dependency finding, shown to demonstrate the reporting mechanism functions, not withheld until something serious occurs.
Interoperability & assurance metrics
- Checks run
- 17
- Succeeded
- 17
- Avg. latency
- 410 ms
- Drift signals
- 2
- Auto-suspensions
- 0
- False positives
- Not yet measurable at this volume
- Floor
- 5 years
- Basis
- EU AML Regulation
- Records past floor
- 0
Audit access log
Access under this tier is itself logged| Date & time | Accessed by | Scope |
|---|---|---|
| 14 Aug 2026, 10:02 | Mastercard Compliance | Register of Information, full export |
| 3 Aug 2026, 15:40 | Mastercard Compliance | Interoperability metrics, 30-day view |
This is a design mockup for pilot discussion, not a compliance certification. It illustrates how TrustElevate's authorisation dashboard is being built to address specific obligations under GDPR, DORA, the EU AML Regulation, and the Cyber Resilience Act, each element above is tagged to the requirement it responds to. Several of the underlying obligations, including a completed DPIA, a Register of Processing Activities, and a formal DORA Register of Information entry, are organisational work not yet finished, and are not represented as done by this mockup.