Getting started.
From agreed scope to a controlled first decision exercise — what to validate, in which order, and who owns each gate.
Choose how you run: SaaS or managed
Two delivery patterns can be scoped. In white-label SaaS, your team integrates the selected APIs and operates the entitled surfaces. In a managed service, the parties agree which monitoring, tuning, review and advisory tasks TrustStack operators perform. Exact modules, data, roles, evidence, service levels and production responsibilities require diligence and contract; shared design does not make the two models operationally equivalent.
Onboarding, step by step
KYB due diligence
Your organization may be asked for company, director and ownership information during commercial onboarding. Do not assume this mirrors the current GATE UI: the reviewed GATE surface does not yet include UBO capture.
Module selection
HELM provides entitlement and administration surfaces. Adding a module can also require integration, configuration, data, legal or operational work; a catalog selection alone is not activation.
Environments & keys
Where FORGE access is enabled, integrators can use scoped, show-once keys and sandbox surfaces. Production credentials require separate go-live approval and do not make the sandbox production-equivalent.
Rules & policy configuration
A vertical policy template can be a starting point in SENTINEL, subject to local validation. Versioning, approval and maker-checker behavior must be confirmed for the selected workflow; they are not universal controls.
Phased rollout
A bounded pilot may progress through synthetic/test, shadow or read-only operation, limited traffic and a separately approved cutover. Use only modes that the scoped integration has verified, with stop conditions and an agreed baseline.
First-run: what to validate before a pilot or live approval
- Risk appetite: which outcomes map to step-up vs manual review vs block (PULSE thresholds, SENTINEL routing).
- Jurisdiction scope: prohibited and restricted countries, local overrides (SENTINEL geo controls).
- KYC tiering: which customer actions require which verification tier (GATE tiers).
- Payout guardrails: confirm which schedules, limits and withdrawal checks are implemented and integrated; SWITCH currently exposes partial read surfaces.
- Team & roles: invite users and assign owners in HELM where enabled; configure a second reviewer only for actions that support that control. Keep at least one technical and one risk/compliance owner.
- Webhooks: configure only the available FORGE event subscriptions, then test event coverage, signatures, retries and redelivery before operational reliance.
A non-production environment should identify synthetic or mock data clearly, but banner and fail-closed behavior must be verified in that exact build. Never infer production safety from the absence of a warning; approval requires explicit environment, data and integration evidence.
The weekly cadence
A useful operating loop is to generate a PRISM scorecard on demand, compare agreed measures with a baseline, investigate changes and govern any policy update. The reviewed PRISM scorecard is generate-now, not scheduled reporting or an SLA-monitoring service. Cadence, approval steps and production change authority must be agreed for each pilot or contract.
Want the complete manual as a PDF? Leave us your email and we'll send it over.
Request the manual