Skip to content

Agentic commerce needs a separation of powers.

The model can understand what a person means. That does not make it the right place to decide what the person is financially allowed to do.
By Arnav Kakar 7 minute read

The argument

Delegated action needs an independent authorization boundary. The software proposing a purchase can be flexible and probabilistic. The system granting financial permission should be deterministic, narrow, and accountable to rules a person deliberately activated.

Interpretation and authority solve different problems

A language model is useful when a business owner says, “Let the procurement agent renew ordinary software, but ask me before it tries a new vendor.” The model can identify likely fields: software is allowed, new merchants need review, and the rule applies to the procurement agent.

That translation is still a proposal. Language is ambiguous, models can misunderstand it, and hostile content can attempt to redirect the interpretation. Financial authority should not inherit those uncertainties. A person must be able to inspect the structured rule, correct it, and activate a specific version.

The agent should request, not rule

An agent attempting to renew Notion should submit facts: its identity, merchant, amount, category, country, and a unique request key. It should not send “approved” as an instruction that the control system trusts. The authorization layer derives the result from authenticated identity, active policy, budget state, transaction limits, merchant rules, geography, and review conditions.

This pattern resembles separation of duties in finance and security. The actor performing work is not the sole actor certifying that its work was permitted.

Human review is a resolution, not a rewrite

When policy returns APPROVAL_REQUIRED, the initial result should remain intact. A human approval adds a second event: who reviewed the request, what evidence was available, what note they supplied, and when the resolution occurred. Preserving both states makes the system explainable after the fact.

Likewise, a hard decline should not become a one-click approval. The operator can change the policy intentionally and submit a new request, but the original failure remains evidence that the prior authority did not allow the action.

Protocols are moving toward explicit authority

Google’s description of the Agent Payments Protocol emphasizes typed mandates and proof of intent alongside commerce protocols. Visa’s agentic-commerce materials similarly emphasize authenticated instructions, controls, and transparency. These efforts differ in implementation, but the shared architectural point is important: an agent’s capability to act is not itself proof that the action was authorized.

Mandate is not integrated with these networks today. It models the upstream business-control question they make more urgent.

The practical test

Ask one question of any agent-payment design: Could the agent, model, or untrusted content it encounters expand the authority used to approve this same request? If the answer is yes, the boundary is circular.

A safer design lets models interpret, agents request, deterministic code authorize, and people resolve exceptions. See the knowledge base for how Mandate represents each part.