Global technical whitepaper · 16 September 2026BOOM / PHOTON AI
Protocol specification · agentic commerce · settlement

Boom
Agentic Commerce
Protocol

A technical specification for turning local-currency intent into an authorized, executable and auditable transaction across wallets, agents, merchants, services and settlement assets.

Author · Peter Alfred-Adekeye

Abstract

One request. One transaction graph.

We define a governed protocol in which a principal expresses intent, a local-language agent constructs a candidate action, the principal signs the scope, BoomPay executes the approved route, and the resulting payment, delivery and evidence events are reconciled.

Principalintent
Agentplan
BMCsettle
Merchantdeliver
01
Identity and consent are part of the transaction, not an afterthought.
02
Local money remains the entry point for users and institutions.
03
BMC is proposed as the common settlement reference.
04
Evidence closes the loop from intent to outcome.
01 · IntroductionOverview · What · Why
Overview
1 / The problem
2bn adults.
$33tn in cash.
Offline by default.

We design for roughly two billion adults, mainly in emerging markets, who transact outside the banking system. Across about 100 currencies, this is a multi-trillion-dollar cash economy. In Africa, roughly 90% of daily commerce is cash, making the gap between physical value and digital commerce especially visible.

People want to custody their own money and settle directly. Cash preserves independence at rest, but cash cannot be spent online and cannot settle a cross-border trade through a communications channel.

01 / CASH

Cash cannot move online.

Banknotes are local, physical and difficult to route across borders. They cannot carry a signed online instruction, delivery proof or programmable settlement state.

02 / TRUST

Banks are a trust bottleneck.

Users avoid institutions they do not trust with access, custody, continuity or pricing. They want self-custody and direct settlement rather than leveraged deposit intermediation.

03 / USABILITY

Crypto is not everyday commerce.

Blockchain systems have not yet made identity, language, payment, delivery and evidence simple enough for mass-market use.

WHAT

Boom is the cash-to-commerce protocol.

A permissionless product layer lets a user create an account in about one minute, hold a self-custodial wallet, fund locally and transact online. Where licensed, deposits are designed to be 100% backed by sovereign bonds rather than leveraged against user balances.

WHY

Turn local value into global participation.

Our thesis is that if Africa and other emerging economies could trade online with one another and globally, the resulting increase in market access and commerce velocity could double GDP across participating economies in less than ten years.

02 · WhatL0 Earth -> L4 Orbit
Ecosystem schema
2 / The stack

The stack turns local value into global action.

The architecture separates physical infrastructure, settlement rails, user-facing applications, commerce domains and future orbital nodes. Each layer can evolve independently while preserving one transaction record.

L4 / OrbitNodes
Boom Nodes-in-OrbitFull-node nano-satellite constellationsFuture L1 propagation layer
L3 / CargoCommerce
EnergyFinancialsLuxuryTelecomsHealthcareMaterialsEducationIndustrialsGovernmentSports
L2 / TrainsApplications
Boom SuperApp · marketplace · wallet · messagingBoomPay · payment gatewayBoomSwap · tokenized assetsBoomcoin · BMCLarge language models
L1 / RailsSettlement
Boomchain · permission blockchain dedicated to commerce
L0 / EarthOperating system
Photon AI · renewable-energy AI data centresPhoton · sovereign compute and storageCyber defence · local inference · governed data
L0 to L4 define the system's placement and composition.
System invariant. Boom SuperApp, BoomPay, Boomchain, BoomSwap, Photon AI and the BMC settlement asset are adapters and services around a shared principal, intent, consent, state and evidence model.
03 · Agentic transaction protocolIntent -> quote -> consent -> execute -> close
Message format
3 / Signed action envelope

A personal AI agent converts intent into a signed action.

The agent may search and plan. The principal authorizes. The rail executes. The ledger records.

transaction = { id: hash(principal_id | nonce | intent), principal_id: kyc_reference, intent: { action, objects, destination }, constraints: { amount_max, expiry, policy }, quote: { price, currency, route, evidence }, consent: signature(principal, quote, constraints), settlement: { entry_asset, reference_asset: BMC }, callbacks: { payment, delivery, custody, exception } }
01

Intent

Natural language or structured request.

02

Quote

Offers, price, route and evidence.

03

Consent

Principal signs the exact scope.

04

Execute

Adapters perform the approved action.

05

Close

Receipt and proof reconcile state.

Transition rule
Required condition
Intent -> Quote
Agent has access to eligible inventory, route constraints and a current policy context.
Quote -> Consent
Quote contains price, currency, expiry, recipient, evidence and a stable transaction id.
Consent -> Execute
Signature covers the quote and constraints; nonce and expiry prevent replay.
Execute -> Close
Payment, delivery, custody or exception callbacks are received and linked to the same record.
Human boundary. The protocol treats confirmation as a cryptographic and operational boundary. An agent can prepare work ahead of consent, but it cannot commit value outside the signed envelope.
04 · Settlement protocolLocal entry · common reference · reconciled exit
Value layer
4 / Fund -> authorize -> settle -> reconcile

Local money is the edge. BMC is the common reference.

Users and institutions may enter through cash, local-currency rails or another approved method. The settlement layer records the entry value, references BMC, and closes against the merchant, service, commodity or remittance outcome.

01 · FUND

Entry instrument

Local currency or approved funding method creates available wallet balance.

02 · AUTHORIZE

Signed intent

Principal approves amount, recipient, route, expiry and evidence requirements.

03 · SETTLE

Common reference

BoomPay invokes the route and links the approved value movement to BMC.

04 · RECONCILE

Outcome proof

Payment, delivery, custody, fee and exception events close the transaction.

Proposed settlement asset
BMC

BMC is proposed as the common settlement and treasury reference for approved wallet, payment, remittance, commodity and reconciliation flows.

LedgerBoomchain is a permission blockchain dedicated to commerce.
VisibilityBoomscan exposes observable transaction and ledger state.
ExchangeBoomSwap provides a self-custodial exchange design for tokenized fiat and real-world assets.
SupplyTotal supply is permanently capped at 2bn BMC; 75% of total supply is available for sovereign acquisition to ensure sovereign participation.
local entry asset -> BMC reference -> merchant receipt / delivered asset / remittance destination
BoomPay

Payment gateway

Connects wallet funding and merchant acceptance to the transaction graph.

Boomchain

Commerce ledger

Records state transitions and references linked evidence.

BoomSwap

Asset exchange

Exchanges approved instruments under policy and custody controls.

Boomscan

State inspection

Lets participants inspect the resulting record and settlement state.

05 · Sovereign executionDevice · local server · institutional node
Trust boundaries
5 / Intelligence follows jurisdiction

Run intelligence at the nearest trusted boundary.

Photon AI provides the cognitive layer: local-language understanding, agentic planning, tool selection and execution support. The personal AI runs natively and locally on all supported smartphones, keeping private context on-device and preserving data sovereignty; higher-assurance workloads move only to an approved local or institutional boundary.

One app. Identity, money, commerce, AI. The smartphone hosts the personal agent, wallet, marketplace, messaging context and payment controls in one governed interaction surface.
01 · Device

Private context first

Runs natively and locally on the smartphone's CPU. The personal agent has no data-centre dependency for the interaction; prompts, user context and task preparation stay on-device by default.

  • Local-language interaction
  • Buys, books, reminds and translates
  • Offline-capable preparation
02 · Local server

CPU-first regional nodes

Approved workloads can run on ordinary local servers with controlled synchronization and a local audit boundary.

  • Lower infrastructure dependence
  • Policy-aware inference
  • Controlled synchronization
03 · Institutional node

Accountable execution

High-assurance workloads remain inside an approved jurisdiction with ownership, access review and escalation to people.

  • Data residency
  • Human accountability
  • Evidence for oversight
Angel 1,000

Sovereign LLM

Language capability designed for African languages, knowledge and local context.

Archangel

Cyber defence

Cyber-defence frontier model designed to defend against attacks at machine speed.

LKM

Local knowledge

Institutional knowledge and values become useful model input with provenance.

Renewable capacity

Distributed AI

Photon AI is building toward renewable AI data centres across Africa and other markets to host sovereign models and inference.

Placement rule. Data, models and actions should run at the lowest-cost boundary that satisfies trust, latency, resilience and policy requirements.
06 · Security and privacyThreats, controls and evidence
Failure model
6 / Fail closed when proof is missing

The protocol is useful because it is constrained.

Security is not one control. It is the composition of identity, policy, signatures, bounded authority, evidence and explicit failure handling at each transition.

Threat
Control
Replay or duplicate spend
Unique transaction id, nonce, expiry and ledger-side idempotency key.
Agent exceeds authority
Consent signs the exact quote and constraints; adapters reject out-of-scope actions.
False inventory or commodity claim
Evidence requirement binds supplier, custody, assay, delivery and exception records.
Compromised endpoint
Device trust, step-up confirmation, institutional review and policy-scoped credentials.
Partial failure
State machine records pending, failed, reversed and disputed outcomes instead of silently retrying value movement.
Privacy model

Minimum necessary disclosure.

Share only the claims required by the next actor. Keep private context on the device or within the approved execution boundary. Expose public state as commitments and receipts, not as an unbounded copy of personal data.

disclose(claims, actor, purpose, expiry) -> receipt
Traceable commodity example
01 / ORIGIN

Site

Licence, location, participants and KYC evidence.

02 / BATCH

Weigh-in

Weight, image, GPS, assay and miner payment.

03 / CUSTODY

Hand-off

Signed aggregator, transport and export transfers.

04 / REFINE

Assay

Bar, coin, serial and NFC evidence map back to origin.

05 / VAULT

Outcome

Fully traced value supports approved reporting and settlement.

Security claim. The system does not remove trust; it makes trust explicit, scoped, inspectable and replaceable at every boundary.
07 · Deployment and referencesDefine -> integrate -> verify -> scale
Implementation
7 / From protocol to production
Deploy one closed loop before scaling the graph.

Boom is fully functional as of September 2026. The platform supports the core wallet, payment, commerce and settlement loop, with multiple new use cases in the pipeline and Agentic AI integration advancing the execution layer.

We extend the live core through a defined jurisdictional perimeter, funding route, merchant or service surface and evidence-heavy workflow. The same linked record carries payment, fulfillment, custody, exception and reconciliation state as the graph scales.

01 · DEFINE

Set the perimeter

Identity, data, custody, AML, sanctions, disclosure, escalation and retention requirements.

02 · INTEGRATE

Connect adapters

Wallet, agent, merchant, fulfillment, commodity, remittance and settlement interfaces.

03 · VERIFY

Run the loop

Measure successful intents, settlement time, exception rate and evidence completeness.

04 · SCALE

Extend the graph

Add languages, currencies, merchants, institutions, assets and jurisdictions.

Open question 01

Which boundaries are sovereign?

Define which data, models, credentials and decisions must remain inside each approved execution zone.

Open question 02

Which outcomes are final?

Define confirmation depth, reversibility, dispute handling and evidence required for each asset class.

Protocol statusProposed architecture. Production use requires jurisdictional authorization, custody, disclosures, market controls and reconciliation.

References

[1] Satoshi Nakamoto. Bitcoin: A Peer-to-Peer Electronic Cash System. 2008. bitcoin.org/bitcoin.pdf
[2] Wei Dai. b-money. 1998. weidai.com/bmoney.txt
[3] Stuart Haber and W. Scott Stornetta. How to time-stamp a digital document. Journal of Cryptology, 1991.
[4] Ralph C. Merkle. Protocols for public key cryptosystems. IEEE Symposium on Security and Privacy, 1980.
[5] International Monetary Fund. The Cross-Border Initiative in Eastern and Southern Africa. 1999. imf.org/external/np/cross
[6] World Bank. The Global Findex Database 2021 identifies opportunities for increasing financial inclusion. 2022. worldbank.org/global-findex
[7] Photon AI Ltd. Photon AI: sovereign AI, local inference and infrastructure. 2026. photonai.ai
[8] Boom Technologies Ltd. Boom: identity, wallet, marketplace, payments and agentic commerce. 2026. boom.market