Assume an agent can fail. Limit what failure can cost.
Lootrunners separates agent capability from financial authority. Application policy defines the rich boundary — purpose, vendors, Rules, approval tiers. Independent provider or wallet controls enforce critical ceilings where the payment rail supports it. Sensitive changes stay human-controlled and auditable.
Connecting a service does not give every agent access. Resources can be granted to one agent or one Run. Credentials stay behind the connector; the model receives only the capability it needs.
Every autonomous purchase is evaluated against a Mandate and the shared Rules that apply.
Critical ceilings can be mirrored into supported provider or wallet controls and verified separately from application policy.
Agents cannot widen their own Mandates, approve their own exceptions, grant themselves Resource access, or unfreeze spending.
One action blocks new autonomous spend and revokes supported external permissions — then shows you exactly which revocations succeeded.
AUTO, ASK, and BLOCK decisions keep the rule, evidence, and actor behind them. Workspaces using the Rules library see the governing Rule and version cited.
"You are giving Research Runner permission to spend up to $50 USDC every 24 hours until August 20. Lootrunners can apply stricter rules, but it cannot use this permission to exceed that limit."
No wallet signing prompt ever appears before this plain-English explanation.
Start risk-free on testnet.
Test agent payments with fake funds before giving them access to real money.