Hive For ICE Data Services · Private
Data delivery Entitlements Why allowed Technical Other options Dashboard Check a receipt

Hive keeps a signed record beside ICE's systems. It never sits in the path. If Hive stops, nothing at ICE stops.

A made-up example. Nothing here is connected to ICE.

ICE entitlement evidence

Why was this request allowed?

ICE can already show what it sent a customer. This walks through how ICE could also show why that person, app or AI agent was cleared to get it.

Walk through it

Here's what ICE has said in public. Using the ICE Data Services MCP connector needs an active ICE Data Services account, licenses for the content you want, and multi-factor sign-in. Access follows the customer's existing ICE entitlements, and ICE doesn't keep query or session data after the connection ends. Everything below is our own made-up example built on those public facts. We don't know how ICE's entitlement systems work inside, and this doesn't pretend to.

Made-up example

01 · The ask

Northstar's valuation team needs ICE data this morning.

Northstar Capital is a fictional asset manager. Its valuation team is going over a bond portfolio, checking last night's closing prices before the day gets busy.

The team's AI assistant asks ICE for End-of-Day Evaluations and Enhanced Evaluation Transparency. They want to understand why a handful of prices moved, and update their own valuation and risk numbers.

Northstar pays for this data, and real work depends on it. If anyone asks about these numbers later, Northstar will want to point to this request.

Risk reviewValuationPortfolio
Firm
Northstar Capital
Human sponsor
Maya Chen, Head of Fixed Income Valuation
Requesting application
Northstar Valuation Agent
Purpose
Internal valuation and risk review
ICE content requested
End-of-Day Evaluations + Enhanced Evaluation Transparency
Portfolio scope
3,412 bonds

Northstar, Maya and every number here are made up. We're not suggesting Northstar is an ICE customer.

What we're suggesting

Try it on one real workflow.

90days. One path.*

Pick one workflow ICE already runs, where a signed-in person, app or agent asks for licensed data. Hive sits off to the side and watches a copy of the events. ICE keeps doing sign-in, licensing and access decisions exactly as it does today. If Hive goes down, nothing on ICE's side notices.

What we agree on first

  • One request workflow
  • Who's in scope: people, apps, agents
  • Which sign-in references we use
  • Which permission references we use
  • Entitlement fields
  • Product and permitted-use fields
  • Allow, deny and review outcomes
  • How each answer links to the delivery or refusal
  • What gets kept, and for how long
  • Who does what
  • What counts as success

What Hive would watch

  • Request received
  • Requester or application reference
  • Firm or account reference
  • Authentication reference
  • Delegation or authority reference where it applies
  • Entitlement snapshot reference
  • Content requested
  • Permitted use
  • The access decision and its reason
  • Delivery, reduced scope, refusal or review
  • Later entitlement change
  • Any correction

What ICE gets at the end

  • An agreed record format
  • A small connector that reads ICE's events
  • A dashboard of the records as they come in
  • A customer-facing access record like the one above
  • One allow example
  • One deny or reduced-scope example
  • One later revocation example
  • A history of any corrections
  • The free offline checker
  • A plain list of what's still missing for production

The one question the test answers: can ICE and its customer both see why a request was allowed or refused, without opening up ICE's whole entitlement system?

See the test outline

* The 90-day test is offered for entitlements only, the first focus ICE named. Nothing has been agreed.

For the technical folks

The record itself Proposed format entitlement.reliance.v1

Example data in a format we're proposing. It isn't an ICE product or an agreed standard.


    
What this record can and can't tell you

It can show what was recorded about

  • A named requester, application or agent
  • A named firm or account
  • The sign-in and permission references that were accepted
  • Which entitlement snapshot applied at the time
  • The requested content
  • How the data was allowed to be used
  • Whether the answer was yes, no, partial or review
  • The reasons given
  • A link to the delivery or refusal that followed
  • Any later correction or revoked access
  • Whether the record has been changed since (once it's signed in production)

It can't tell you, on its own

  • The person's real-world identity
  • That authentication was performed correctly
  • Whether ICE read the license correctly
  • Whether the customer stuck to the usage limits afterward
  • That the delivered data was accurate
  • That every event was captured
  • Whether a yes should really have been a yes
  • That ICE endorses Hive