What does your agent do with money?
Three things, and then every question a finance lead asks next. Each one is checked before the money moves, and each leaves a receipt. Watch what happens.
Money leaving your account, pay out
Will it refund twice?
No. A refund above your line waits for a person, the yes is for an exact amount, and a lost reply is never retried on a guess.
- You set
- The amount a refund can be on its own. Who says yes above it. A budget per customer, per day.
- support-agentproposes a $2,000 refund to a customer it has never refundedheld for a person
- finance leadapproves exactly $2,000, from Slackapproved
- support-agenttries $4,000 under that approvalrefused, not what was approved
- the railloses the reply to the next refundreconciled, counted once
Money your agent spends, agent wallet
How much can it spend?
Only what you set aside, once. A USDC transfer or ten cents for one call is signed for exactly that amount and is final when the chain says so.
- You set
- What is set aside per agent and per call. A ceiling per day. Nothing is signed above it.
- research-agentpays $0.10 for one call, signed for exactly thatpending
- the chainconfirms the paymentcounted once
- research-agentasks for $0.25 with $0.10 set asiderefused before signing
- invoice-agentsends 250 USDC and the reply is lostreconciled on the chain
Money arriving, pay in
Is the money real yet?
Recorded the moment it arrives, released once the settlement confirms, never early. Limits come later, once the traffic shows where they belong.
- You set
- Nothing to start. Everything arriving is recorded; you add limits when you see the pattern.
- checkout-agentcaptures $180 on an order the customer authorisedallowed
- checkout-agenttries $240 on a $180 authorisationrefused by the rail, recorded
- another agentpays you $0.10 a call, settlement pendingnothing released yet
- the chainconfirmsreleased once
Money leaving your account, pay out
Can it pay a vendor on its own?
No. A payout has no autonomous band. The agent prepares it to the cent, two people say yes, and the balance is checked again before it leaves.
- You set
- Who the payout approvers are, how many of them, and that a payout to a vendor the agent has never paid waits at any amount.
- invoice-agentmatches invoice 4471 to the order and proposes a $18,400.00 payoutheld, payouts never autonomous
- p.raoapproves exactly $18,400.00 from Slack1 of 3
- a.singhapproves exactly $18,400.00 from their assistantapproved, 2 of 3
- the railconfirms with a signed webhook, payout.paidCOMMITTED, reconciled
When the answer is no
What if it splits a payment to get under the line?
The budget catches what the band cannot. Three refunds under $500 to one customer in forty minutes add up, and the fourth is refused by the seven-day budget for that customer.
- You set
- A budget per customer, per day or per week, that survives splitting and retry storms.
- support-agentrefunds $480.00 to cus_4Aballowed, under the band
- support-agentrefunds $450.00 to cus_4Ab, twenty minutes laterallowed
- support-agentrefunds $470.00 to cus_4Abrefused, counterparty budget
- ctrl paymentsnames the pattern: splitting, three receiptsowner notified
When the answer is no
What if it keeps trying after a refusal?
Every attempt is a receipt, refused ones included, so the pattern is visible: two refusals just over the band and then one just under it. The signal drops the agent's band to zero for a day.
- You set
- The band, and that feedback from a signal can narrow it. Feedback only ever narrows, and a person can reverse it.
- support-agentproposes a $6,200.00 refund to cus_2Zqrefused, above $5,000
- support-agentproposes $5,100.00 to the same customerrefused
- support-agentproposes $499.00, just under the bandallowed, then flagged
- ctrl paymentsescalation signal: band on refunds to cus_2Zq dropped to $0 for 24 hoursowner notified
When the answer is no
Can it change its own limits?
No. A policy change is a protected action like a payment. Only a person can propose one, another person approves it, and the receipt for the change sits in the same chain as the payments it governs.
- You set
- Who may propose a change and who may approve it. Nobody widens a band quietly.
- support-agentasks for its refund band to be raisedrefused, agents do not propose policy
- p.raoproposes v4: refund band $500 to $6,000waiting for j.doe
- j.doeapproves the changeapproved, receipt r_9f4
- every connectorapplies v4 and acknowledges itapplied
When the answer is no
What if someone approves their own agent's payment?
The yes is refused. The requester is never the approver, and for a payout it takes two other people. Every refused yes is a receipt too.
- You set
- Separation of duties: which roles may approve which payments, and that a requester is never among them.
- finance-agentproposes a $9,800.00 payoutheld, payout-approver 2 of 3
- the agent's ownerclicks approverefused, requester is not approver
- p.rao and a.singhapprove exactly $9,800.00approved, 2 of 3
- the railconfirmsCOMMITTED
Money leaving your account, pay out
Can it change a subscription?
Inside the band, yes. A small change per period goes through, a larger one waits for a person, and above the ceiling it is refused.
- You set
- The change per period an agent may make on its own, and where a person decides.
- billing-agentmoves cus_7Hq from $80 to $60 a periodallowed, within $100 a period
- billing-agentmoves cus_7Hq from $60 to $420 a periodheld for a person
- finance leadapproves exactly that changeapproved
- billing-agenttries $900 a period on another customerrefused, above the ceiling
Rails
Does it work on more than one rail?
One policy over every rail. A refund on PayPal and a refund on Razorpay meet the same bands, and each rail's own idempotency carries the receipt id so nothing runs twice on either.
- You set
- The rails you connect. Works with any integration, and we add integrations on request.
- billing-agentrefunds $89.00 on PayPalallowed, under $500
- support-agentrefunds ₹42,000.00 on Razorpay to a new customerheld, new counterparty
- finance leadapproves exactly ₹42,000.00approved
- Razorpaysees the same receipt id on a retryduplicate refused by the rail, counted once
Rails
What happens when the rail says no?
It is recorded as the rail refusing, with the reason, and it counts as not executed. The rail is the backstop; ctrl payments is the boundary in front of it.
- You set
- The least-privilege keys the connector holds, so the rail refuses what the policy should never have let through.
- checkout-agentcaptures $180.00 on an authorised orderallowed
- checkout-agenttries $240.00 on the $180.00 authorisationrefused by the rail
- ctrl paymentsrecords it as backstop fired, NOT_EXECUTEDreceipt written
- support-agentrefunds a disputed chargerefused, open dispute
When the answer is no
What if an agent goes wrong?
Freeze it. From that moment every payment it proposes is refused, each one a receipt, until a person unfreezes it. Revoking its grants is the same kind of action, recorded.
- You set
- Who may freeze and revoke. Both are policy actions with a receipt, never a silent flag.
- support-agentproposes eleven refunds in four minutessignal: retry storm
- on-call leadfreezes support-agentfrozen, receipt written
- support-agentproposes a $120.00 refundrefused, frozen
- on-call leadunfreezes it after the fixunfrozen, receipt written
Evidence
What does the auditor get?
A file. Every attempt for the period, refused ones included, with the policy version, the agent, the approver and the outcome, in an open format they can verify without us.
- You set
- Retention, and who may export. The receipts are yours in every plan.
- auditorasks what the agents paid in Marchexport requested
- ctrl paymentsexports 41,900 receipts as JSONexported
- auditorruns verify on their own machinechain intact, 16 of 16 pass
- auditorasks who approved payout inv_4471p.rao and a.singh, in the receipt
The model guesses.
ctrl payments does not.
No rule for it
The payment is refused. Silence is never permission.
refusedAmount changed after sign-off
The old approval is void. A person signs again.
refusedReply lost
No retry until it is reconciled. Nothing is paid twice on a guess.
pending