Define intent
Write a mandate in plain language or configure exact rules directly.
Authorization infrastructure for agentic commerce
Give agents narrowly scoped financial authority without letting a language model become the decision-maker. Every request is evaluated by deterministic policy, scored for risk, and recorded with an exact reason trail.
Simulation only. No cards, bank credentials, or real payments.
Amount exceeds autonomous limit and merchant is new.
Plain-language definition
AI-agent payment authorization is the control process that determines whether software acting on a person’s or company’s behalf may make a purchase. An agent can propose a merchant, amount, category, and country, but it should not decide its own financial permissions. Mandate checks the request against an active, versioned policy covering identity, status, available budget, transaction limits, merchant and category rules, geography, expiration, and review conditions. The deterministic engine then returns one of three machine-readable outcomes: APPROVED, APPROVAL_REQUIRED, or DECLINED. Risk signals may escalate a request for human review, but they cannot erase a hard policy failure. The language model is limited to converting human instructions into a proposed rule structure. A person reviews and activates that structure. This separation makes automated purchasing least-privilege, explainable, revocable, and auditable without representing that a real payment has occurred.
The model can help translate what you mean. It never receives the authority to decide what can be spent.
Each agent receives its own purpose, status, budget, policy version, and scoped credential. Pause it immediately, require review for every request, or revoke access entirely.
“Give my procurement agent $2,000 per month. Allow software and office equipment. Require approval above $250 and for every new merchant. Block crypto, gambling, and international requests.”
Proposed by language model. Activated by a human.
Every response is predictable for software and understandable for people.
Every hard rule and review condition passed.
The request pauses until a human resolves it.
A hard policy boundary blocked the request.
Agents, MCP servers, and your own backend submit the same authorization request before a purchase. Mandate returns a decision—not a payment.
POST /v1/authorization-requests
X-Mandate-Key: mnd_live_••••••••
{
"amount": 96,
"merchant": "Notion",
"category": "software",
"country": "US"
}{
"decision": "APPROVED",
"riskScore": 12,
"reasons": [
"Within autonomous limit",
"Known merchant and category"
]
}Inspect the exact rule trace, risk factors, original decision, later human resolution, and linked audit event for every simulated request.
Create a workspace, define one mandate, and test the full decision path in simulation.