Seeing is not the same as doing
The technique
The permission ledger: four columns, not one
Security claims describe servers you cannot see. The ledger asks four checkable things: what the route sees, what it can do, whom you must trust, and how you revoke. Most people judge only the first column, which is where the routes are most alike.
All four routes can produce a list of amounts, dates and counterparties. The login and the Account Aggregator route see a little more, such as ledger lines that never trigger an alert; alerts see a little less; statements see everything, late. On seeing alone, the routes are close to interchangeable.
The second column separates them. A net-banking password is not a read permission. It is the credential you use to add payees and move money, and the bank cannot tell the tracker's session from yours. The other three routes hand over something that cannot move a rupee: a consent that carries data only, a permission to read messages already sent to you, or a file. Columns three and four decide the rest: where your data ends up, and whether you can end the arrangement yourself, today.
- Apply the ledger to the route, not the brand. Two trackers on the same route share the same ceiling on what they can do and differ only in the last two columns
- The household: 4 accounts, about 120 debits and ₹50,000 of spending a month. The counts below scale with accounts, not transactions, so swap in your own number of accounts






