Policy enforcement for agent payments
Spending rules for AI agents that move money.
Intaglio checks every payment an agent wants to make against your policy before it executes. It approves, denies, or holds the payment for a human, then seals the decision in a record you can hand to an auditor.
- Sub-ms rule evaluation
- Fails closed on any error
- Hash-chained audit records
{ "agent_slug": "treasury-bot-01",
"action": { "type": "transfer",
"amount": 4200,
"currency": "USDC",
"destination": "7xKXtg…xJSw" } }Transaction amount 4200 USDC exceeds auto-approval threshold of 1000 USDC
- rule_triggered
- require_human_review
- hash
- sha256:c8d5e0f1…
- prev_hash
- sha256:9f2c41d7…
- verify
- /verify/c8d5e0f1…
- 41ab0e93
- 9f2c41d7
- c8d5e0f1
How a decision works
One call in. One verdict and one sealed record out.
The agent never holds the rules. Change a limit in the dashboard and the next call is judged by it.
- 01
The agent asks
Before it pays, the agent sends the amount, currency and destination to one HTTP endpoint.
POST /api/enforce - 02
The policy decides
Deterministic rules and an OFAC screen. No model in the loop, so the same input always gets the same answer.
APPROVE · REQUIRE_APPROVAL · DENY - 03
The record is sealed
Every decision is stored with a hash of the one before it. Records cannot be edited or deleted.
prev_hash → hash - 04
Anyone can check it
Hand an auditor the hash. They look it up on a public page, and can check it against a Solana devnet anchor.
/verify/{hash}
Audit record
A record that holds up in an audit.
MiCA Art. 68(9) requires crypto-asset service providers to keep records of every service, activity, order and transaction for five years, up to seven on regulator request, and to produce them on demand. When an agent places the order, application logs are not that record. Intaglio writes one at decision time.
- Append-onlyThe database rejects edits and deletes on audit records.
- Hash-chainedEach record commits to the hash of the one before it.
- Public lookupAnyone with the hash can check the decision. No account needed.
- Stored in the EUAudit records live in AWS eu-west-1, Ireland.
Transaction amount 4200 USDC exceeds auto-approval threshold of 1000 USDC
- agent
- treasury-bot-01
- amount
- 4,200 USDC
- hash
- sha256:c8d5e0f1…
- prev_hash
- sha256:9f2c41d7…
- solana anchor
- devnet · 4vhK…Qm2x
What you control
Your limits, enforced on every call.
Set them per agent in the dashboard. No model decides: the same request against the same policy always gets the same verdict.
Auto-approve limit
At or under it, the payment goes through.
APPROVEApproval threshold
Above it, a person approves or denies in the dashboard.
REQUIRE_APPROVALHard cap
Above it, the payment is blocked. Applied per action.
DENYDestination allowlist
Any destination not on the list is blocked.
DENYCurrency
Limits are set in one currency. Any other currency is blocked.
DENYSanctions screening
Every destination is checked against the OFAC SDN list.
DENY
Talk to us about a pilot.
Bring one agent and the limits you would want enforced on it.