Assume an agent can fail. Limit what failure can cost.
Two layers, always. Business policy is the rich semantic layer — purpose, vendors, projects, approval tiers. Hard wallet and provider controls are the last line of defense if the application or agent behaves unexpectedly.
Every autonomous dollar belongs to a Mandate — job, budget, vendors, time window, and approval rules.
Critical ceilings mirror into wallet or provider controls where supported — enforced below the application.
Agents cannot raise their own budgets, change policy, or approve exceptions. Credentials are scoped to requesting spend.
One action stops new spend, pauses agents, and revokes available hard permissions — then shows you exactly which revocations succeeded.
"You are giving Research Runner permission to spend up to $50 USDC every 24 hours until August 20. Lootrunners can apply stricter rules, but it cannot use this permission to exceed that limit."
No wallet signing prompt ever appears before this plain-English explanation.
Start risk-free on testnet.
Test agent payments with fake funds before giving them access to real money.