SAFR is easy to confuse with adjacent things. Getting the boundaries right is what makes it useful.

SAFR is not…

Because…

Regulation

The whitepaper states it is not regulatory guidance or a supervisory expectation, and doesn't anticipate future guidance. Each institution remains responsible for its own alignment with supervisory expectations.

A payment rail

SWIFT, card networks, and settlement platforms move money. SAFR governs the decision to move it, before it reaches the rail.

A compliance platform

SAFR can incorporate checks like sanctions screening, but its purpose is the structured governance record, not replicating existing compliance engines.

An LLM guardrail

Content filters and prompt-injection defences govern what the model outputs. SAFR governs whether the resulting action is authorised. An agent can pass every guardrail and still propose a payment above its authority.

A managed service

It's a reference for institutions to implement in their own infrastructure.

A certification

There is no official SAFR certification. OpenSAFR's conformance suite (planned) tests against the OpenSAFR schema, not an official MAS standard.

OpenSAFR itself is also not official. It is an independent implementation of a published reference approach.