Skip to content

Authorization infrastructure for agentic commerce

AI agents can request.
Mandate decides whether they may spend.

Give agents narrowly scoped financial authority without letting a language model become the decision-maker. Every request is evaluated by deterministic policy, scored for risk, and recorded with an exact reason trail.

Simulation only. No cards, bank credentials, or real payments.

Authorization requestApple · Office equipment
$899.00
Requesting agentProcurement agent
ACTIVE
Agent statusActive
PASS
Monthly authority$1,904 remaining
PASS
Autonomous limit$250 maximum
REVIEW
Merchant historyApple is new
REVIEW
Deterministic outcomeAPPROVAL_REQUIRED

Amount exceeds autonomous limit and merchant is new.

46/100 risk
Policy v3 · 6 rules evaluated · AI did not authorize this request
Deterministic authorizationLeast-privilege mandatesHuman approval when requiredMachine-readable reasons

Plain-language definition

What is AI-agent payment authorization?

AI-agent payment authorization is the control process that determines whether software acting on a person’s or company’s behalf may make a purchase. An agent can propose a merchant, amount, category, and country, but it should not decide its own financial permissions. Mandate checks the request against an active, versioned policy covering identity, status, available budget, transaction limits, merchant and category rules, geography, expiration, and review conditions. The deterministic engine then returns one of three machine-readable outcomes: APPROVED, APPROVAL_REQUIRED, or DECLINED. Risk signals may escalate a request for human review, but they cannot erase a hard policy failure. The language model is limited to converting human instructions into a proposed rule structure. A person reviews and activates that structure. This separation makes automated purchasing least-privilege, explainable, revocable, and auditable without representing that a real payment has occurred.

A separation of powers for every purchase request.

The model can help translate what you mean. It never receives the authority to decide what can be spent.

Define intent

Write a mandate in plain language or configure exact rules directly.

Evaluate deterministically

Identity, budget, limits, merchants, categories, countries, and risk are checked in code.

Keep humans in control

Ambiguous or elevated requests stop for review with the original evidence preserved.

Authority is explicit, narrow, and revocable.

Each agent receives its own purpose, status, budget, policy version, and scoped credential. Pause it immediately, require review for every request, or revoke access entirely.

  • Monthly and per-transaction limits
  • Merchant, category, and country rules
  • New-merchant and approval thresholds
  • Pause, revoke, and approval-all controls
Active mandateProcurement agent · v3
ACTIVE
“Give my procurement agent $2,000 per month. Allow software and office equipment. Require approval above $250 and for every new merchant. Block crypto, gambling, and international requests.”
Monthly authority
$2,000
Autonomous transaction
$250
Allowed scope
Software · Office equipment
Blocked scope
Crypto · Gambling · International

Proposed by language model. Activated by a human.

Three outcomes. No probabilistic authorization.

Every response is predictable for software and understandable for people.

APPROVED

Every hard rule and review condition passed.

APPROVAL_REQUIRED

The request pauses until a human resolves it.

DECLINED

A hard policy boundary blocked the request.

Put Mandate between an agent and the action it wants to take.

Agents, MCP servers, and your own backend submit the same authorization request before a purchase. Mandate returns a decision—not a payment.

Scoped agent credentials Idempotent REST requests Stored policy and risk evidence
REQUESTRESPONSE
POST /v1/authorization-requests
X-Mandate-Key: mnd_live_••••••••

{
  "amount": 96,
  "merchant": "Notion",
  "category": "software",
  "country": "US"
}
{
  "decision": "APPROVED",
  "riskScore": 12,
  "reasons": [
    "Within autonomous limit",
    "Known merchant and category"
  ]
}

Built for scrutiny, not magic.

Inspect the exact rule trace, risk factors, original decision, later human resolution, and linked audit event for every simulated request.

User intentAgent requestPolicy evaluationRisk evaluationDecisionHuman resolution

Give your agents boundaries before you give them a budget.

Create a workspace, define one mandate, and test the full decision path in simulation.

Create a workspace