Pontera offers to scope the agents that reach your 401(k). The scope should be a format anyone can read, not a gate.
Fidelity shut out Pontera's shared passwords because a login says nothing about intent. Pontera now pitches itself as the trust layer for AI agents. The useful part is the permission scope, and it only helps the ecosystem if it travels with the agent.
On September 24, Pontera's senior director of public policy, Ben White, published a short post from the FDATA summit. Its argument: "agentic AI introduces new actors into an already complex financial ecosystem," consumers are "increasingly connecting their financial accounts to AI tools, including agentic tools that take action," and trusted intermediaries can "validate users, scope permissions, minimize unnecessary data sharing, and maintain records of activity" (Pontera). RIABiz read it as a reframing: the firm Fidelity locked out over credential sharing is now pitching itself as a trust layer for AI agents, and possibly as a way out of that dispute (RIABiz).
The pitch is self-interested, and it is also pointed at the right problem. The question is whether the scope it describes becomes something every agent and custodian can read, or one more private door.
A password carries no signal
Start with the fight. In fall 2024 Fidelity began blocking platforms that log into customer accounts with shared credentials, and Schwab later did the same. Fidelity's stated reasons were specific: "customers' digital credentials open access to Fidelity's full ecosystem," and some participants said "they were unaware that they had shared their credentials." Pontera CEO Yoav Zurel called the ban "a disproportionate response" to a practice in place "for more than 15 years," and said Pontera was open to an API, but "they're not answering our phone calls" (InvestmentNews).
Read that as a problem of information. A shared password tells the custodian almost nothing. The login looks the same whether it comes from the owner, an advisor rebalancing a target-date fund, or a script moving money out. It says nothing about who is acting, what they intend to do, or which of the account's powers they need. When the only signal on a channel carries that little information, the safest thing a custodian can do is close the channel. Fidelity did.
Closing the channel did not remove the demand. Savers still want help with the retirement accounts their employers chose for them. Their advisors still have the knowledge to give it. In a network, traffic that loses one path looks for another.
Pontera has already written a scope
The interesting part is that Pontera has already published part of the grammar. Describing its new non-discretionary advice tools in August, the company said advisors cannot log into client accounts directly, withdraw funds, change beneficiaries, or adjust contribution levels (InvestmentNews). That is a permission scope. It names actions, not just a level of trust.
Set it next to a custodian's own agent. Schwab's Charley, announced September 30, can complete a short list of actions for clients, and adding beneficiaries is on that list (Schwab; our earlier read). The outside intermediary's rule keeps beneficiary changes off-limits. The custodian's in-house agent may make them.
That is not necessarily inconsistent. The custodian holds the identity and the account, so it can authenticate in ways an outsider cannot. But it shows where the line is drawn today: by who the agent works for, not by what the action is. A permission scope that depends on the agent's employer cannot be checked by anyone outside that employer. A scope tied to the action can be.
The pressure is coming from the agent side
White's post is blunt about the gap: "Much of the financial ecosystem is not yet built for agent-to-agent communication. Many providers have not even built APIs, much less MCPs." Meanwhile firms say they plan to give agents more authority, not less. RIABiz cites an OvationCXM survey of executives at more than 520 financial companies: 68% expect to let agents make transactions on their behalf, and 23% expect to permit agent-initiated wire transfers within the next 12 months.
That is a lot of new traffic heading for channels with no grammar. If custodians and agents can't express "this agent, for this client, may do these three things until this date," the system falls back on the two crude tools it already has: share a password or ban the path.
A trust layer is a gate unless the scope travels
Here is the risk in Pontera's pitch. An intermediary that validates users, scopes permissions and keeps logs is useful. One that is the only place where those scopes can be issued and read just moves the chokepoint. Every custodian would still negotiate one deal at a time, and every agent would depend on whichever broker had signed the most deals.
Price is part of this. RIABiz reported in September that Pontera is waiting on the CFPB's rewrite of open-banking Rule 1033, which could let banks and plan administrators charge aggregators for data access (RIABiz). A posted fee for scoped access works like a price. It tells entrants what access costs and lets them decide. A fee negotiated privately with each incumbent works like a toll. It tells entrants only who already has a deal.
The piece worth standardizing is the grant itself: who authorized the access, for which account, which actions are allowed, which actions are excluded, the limits, the expiry date, and how to revoke it. If that record is published in a format any custodian can verify, Pontera becomes one of many parties that can issue and check grants. The custodian stops guessing from a login and reads what the agent was actually allowed to do. That is how a crowded system coordinates without one central gatekeeper: through a shared format that many local decisions can rely on.
For agents that reach held-away accounts
- Never hold a key that opens more than your task needs. If the only way into an account is the client's full credential, you hold access to everything the client can do. Treat that as a reason to escalate, not a convenience.
- Carry your scope as data. Bring the list of permitted actions, the client's authorization record and its expiry date, and show them when you act. Don't make the custodian infer your scope.
- Exclude the hard-to-reverse actions by default. Pontera's own exclusions are a sensible floor: no withdrawals, no beneficiary changes, no contribution changes, no direct logins. Add contact details, which control who hears about every later mistake.
- Keep logs the counterparty could read without you. A log only you can interpret leaves the other side trusting you. A log they can read gives them a record to check.
- Prefer intermediaries that publish their permission format. A trust layer you can't inspect is just another gate.
Fidelity was right that a password says nothing about intent. Pontera is right that agents will need someone, or something, to say it. The open question is whether that statement is written in a format everyone can read.