Policy reference: use this page for policy concepts and examples, not a promise of universal enforcement. For control evaluation and route-coverage caveats, read the agent spending controls guide.

Guardrails

Policies that travel
with the agent.

Configure supported caps and approval requirements. Hard-cap failures may be rejected rather than sent for approval; enforcement depends on the execution path.

Three Caps. One Gate.

Supported spend-gated routes check per-transaction, daily and monthly caps and can require approval. Generic x402.pay_url has an optional per-call maximum, not the mandate-bound spend gate.

  • → Evaluated on supported spend-gated routes
  • →Enforcement depends on the execution route
  • →Applies where the tool invokes the spend gate
// Illustrative policy pseudocode — not an API contract
async function checkLimits(agent, amountCents) { if (amountCents > agent.perTxnLimitCents) return { ok: false, reason: 'PER_TXN_EXCEEDED' }; const [daily, monthly] = await Promise.all([ spentSince(agent.id, '24h'), spentSince(agent.id, '30d') ]); if (daily + amountCents > agent.dailyLimitCents) return { ok: false, reason: 'DAILY_EXCEEDED' }; if (monthly + amountCents > agent.monthlyLimitCents) return { ok: false, reason: 'MONTHLY_EXCEEDED' }; return { ok: true }; }

Approval Routing & Overrides

Spend-gated requests may require approval. A hard-cap rejection is not an approval that can be overridden; adjust policy through authorized controls if appropriate.

WhatsApp · Just now
A
AgentWallet
Approval Required
triage-bot-01 is requesting spend
$1,200.00
Vendor: Amazon Web Services
Reason: Threshold exceeded ( >$1000 )
Rail: Virtual Card

Notification Paths

Review and resolve pending approvals through the supported approval interfaces. Notification availability depends on the configured integration.

Manager Chains

Use the supported approval flow for requests that require review. This page does not promise multi-hop routing or multi-signature thresholds.

Force-Approve Override

Authorized users can resolve supported approval requests. Approvals do not waive hard caps or add funds, and administrative permissions depend on the action.

Define policies as code.

Inject policy JSON during provisioning or update it on the fly.

const
policy = {
"velocity": {
"per_txn_usd": 1000,
"daily_usd": 5000,
"monthly_usd": 20000
},
"merchants": {
"allowlist": ["openai.com", "anthropic.com", "aws.amazon.com"],
"mcc_blocks": [7995, 6051] // gambling, crypto
},
"geofence": {
"allowed_countries": ["US", "CA", "GB", "EU"]
},
"approvals": {
"auto_approve_under_usd": 50,
"require_human_over_usd": 1000
}
};

Compare us to the alternatives.