/// Agents · AI Payments

Autonomy with a leash you hold

The interesting question is not whether AI agents will spend money — it is who sets the rules. With Protocore Agents, the answer is always a human, in advance, in writing.

Per-agent
Budgets and allowlists
Human
Approval above threshold
Immutable
Audit log
Instant
Kill-switch
/// 01

Policy first, payments second

An agent is born with a budget and a merchant allowlist, and it cannot exceed either. Anything above the human-approval threshold pauses and asks. The agent moves fast inside the walls; the walls are yours.

  • [ 01 ]Budgets enforced at the platform, not promised by the agent
  • [ 02 ]Allowlists scope where money can go at all
  • [ 03 ]Thresholds route big decisions to people
/// 02

Every action on the record

The audit log is immutable and complete: what the agent tried, what policy allowed, who approved what. When an agent misbehaves — or a policy turns out wrong — the kill-switch stops it instantly, and the log shows exactly what happened.

/// Features
The whole fleet on one screen — limits, spend, and the policy that binds each agent.
/// 01

Policy console

One screen holds the whole fleet: every agent, its daily limit, its allowlist, and what it spent today. In the demo, three agents have spent €184.20 by 09:41 — two payments blocked, one waiting on a human. Policy edits apply immediately; the agent finds out the next time it tries to pay.

  • [ 01 ]Budgets, allowlists, and thresholds edited per agent
  • [ 02 ]Spend, blocks, and pending approvals at a glance
  • [ 03 ]The last 24 hours of decisions, exportable
Above the line — the agent asks, a human answers, the payment logs itself.
/// 02

Chat approvals

The agent proposes; a person decides. In the demo, the Ops Agent flags invoice #088 from Nord Logistics — €120.00, inside its €500/day budget but above the €100.00 approval line — and a one-line reply clears it. The payment lands as REF 9F21-0716 and hits the audit log at 09:41.

The agent's wallet — budget left, scopes, and the key that signs every payment.
/// 03

Agent wallets

Every agent runs from its own wallet with its own credentials. The demo Ops Agent shows €380.00 still available of a €500.00 daily limit — resetting at 00:00 CET — with capability scopes toggled individually and an API key it can be cut from in one tap. Every payment is signed with the agent key and the current policy hash.

  • [ 01 ]Scopes per capability — payments.send on, subscriptions.manage off
  • [ 02 ]Key rotation any time; policies stay attached
  • [ 03 ]Budget, spend, and reset time visible at all times
Born with a policy — budget, allowlist, and threshold set before keys exist.
/// 04

Creating an agent

An agent is policy before it is code. The demo's Billing Agent gets a €200.00 daily limit, an €80.00 per-transaction cap, two merchants from the allowlist, and human approval above €50.00 — all set in step 3 of 4, before keys exist. Keys are issued once, shown a single time, and every payment signature carries the policy hash.

Policy as a document — versioned, hashed, signed, and replayable before saving.
/// 05

The policy editor

A policy is a versioned document. The demo edit raises the Ops Agent's per-transaction cap: v14 becomes v15, the change carries a required audit note, and it saves signed by the operator with a fresh policy hash. The replay panel runs the last 24 hours of real decisions against the draft — you see what a policy would have allowed before it is live.

  • [ 01 ]Daily limit, per-transaction cap, and monthly ceiling per agent
  • [ 02 ]A written audit note required on every save
  • [ 03 ]24-hour replay against the draft before committing
One decision, fully reconstructed — checks, signature, settlement, hash chain.
/// 06

Audit, decision by decision

Decision DEC-4471 reconstructs one payment completely: the request, every policy check with its result — allowlist pass, cap pass, threshold escalate — the human approval with its signature, and the settled €120.00 with its rail and reference. The record is hash-chained and append-only; editing any field breaks the chain from that point forward.

/// And more

Per-agent budgets

A budget is a hard wall, not a suggestion. Each agent carries a daily limit and a per-transaction cap — €500.00 a day, €150.00 a payment in the demo policy — enforced by the platform before money moves. The travel bot's €640.00 charter attempt was denied on the spot: over-cap.

Monthly ceilings

Above the daily limit sits a monthly ceiling — €6,000.00 in the demo policy. An agent that behaves every single day still cannot drift past what the month allows.

Budget resets on the clock

Daily budgets reset at a stated time — 00:00 CET in the demo — visible on the agent's wallet. Spend accumulates against a window everyone can see, not a rolling mystery.

Merchant allowlists

Agents pay only merchants you listed in advance. The demo Ops Agent knows exactly four — and a €180.00 attempt at an unlisted vendor was denied as not-listed. Adding a merchant is one click; removing one takes effect immediately.

Approval thresholds

Set the line above which a human must say yes. The demo policy escalates anything over €100.00: the agent pauses, a person gets the proposal, and nothing moves until they answer. Below the line, the agent runs free — inside its budget and allowlist.

Signed human approvals

An approval is not a checkbox — it is recorded with who approved, on which device, at what time, with a signature attached. The demo decision shows it: approved in app, phone key, 09:41:12.

The escalation trail

Propose, escalate, approve, allow — each step timestamped in the decision record. When someone asks why a payment happened, the answer is a sequence, not a shrug.

Immutable audit log

Every decision is on the record: what the agent tried, what policy said, who approved what — down to key rotations. Entries are append-only and exportable. When something looks wrong, the log shows exactly what happened and when.

Hash-chained integrity

Each audit record carries its own hash, the previous record's hash, and its chain position — #4,471 in the demo. Verify the chain on demand; any edit anywhere breaks everything after it.

Export as JSON

Any decision exports as JSON, hash included — ready for your own archive, your auditor, or your incident review. The log is yours to take, not ours to keep.

Kill-switch

One tap pauses an agent and halts all agent-initiated payments instantly. Keys stay valid, so nothing else breaks — the agent simply cannot spend until a human turns it back on. In the demo fleet, the travel bot sits paused at €0.00 spent.

Frozen, not lost

Pausing an agent freezes its pending proposals rather than discarding them. Un-pause and the queue is exactly where it was — no proposal silently dies because a human hit the brakes.

Scoped keys

An agent's credentials grant capabilities, not blanket access. Scopes like payments.send and refunds.issue toggle independently — the demo agent has subscriptions.manage switched off. Revoke or rotate a key without touching the policy underneath it.

Keys issued once

Agent keys are shown a single time at issuance and never again. What the platform cannot re-display, an attacker cannot re-request.

Policy hash in every signature

Every payment is signed with the agent key and the hash of the policy that allowed it. A payment does not just say what happened — it proves which rules were in force when it did.

Policy versioning

Policies carry a version, a hash, an author, and a timestamp — v14, updated 17 Jul at 09:12 in the demo. Every decision references the exact policy version that judged it.

Replay before you commit

The editor replays the last 24 hours of decisions against your draft: what was allowed, what was denied, what would change. Policy mistakes surface in the preview, not in production.

Settlement on real rails

An approved proposal becomes a real payment — the demo's €120.00 settled by SEPA Instant with reference 9F21-0716, minutes after approval. Agents spend from the same core the rest of the family runs on.

MCP endpoint

Agents connect over MCP at mcp.protocore.io/agents — any framework that speaks the protocol can hold a Protocore wallet. The integration surface stays small: propose a payment, receive a decision. Policy lives on the platform, not in the prompt.

Fleet of agents

Run one agent or many. The demo runs three — ops, procurement, a travel bot — each with its own budget, allowlist, and threshold. Pause one and the others keep working; policy never bleeds across agents.

/// In the product
The policy console — budgets, allowlists, and thresholds per agent.
Above the threshold — a human approves before money moves.
The agent's wallet — budget, spend, and every payment logged.
Born with a policy — budget, allowlist, and threshold set before keys exist.
Policy as a document — versioned, hashed, signed, and replayable before saving.
One decision, fully reconstructed — checks, signature, settlement, hash chain.
/// FAQ

Agents under policy, answered.

  • The budget is enforced at the platform, not promised by the agent. An agent cannot exceed its daily or per-transaction limit whatever it decides, and anything above the approval threshold pauses and asks a human before money moves.

  • Only to merchants on its allowlist. The allowlist scopes where money can go at all, before any budget check — an agent pays where you said it could, and nowhere else.

  • It pauses and routes to a person for approval; the payment settles only after a human signs off, and the request, the checks, and the signature are all recorded. Below the line, the agent moves on its own inside the walls.

  • A kill-switch per agent stops it in one tap — instantly, not at the next cycle. The audit log then shows exactly what it did up to that point.

  • Over MCP at mcp.protocore.io/agents, with the API and docs to wire any framework to a policy. The policy — budget, allowlist, threshold — is set before the agent's keys even exist.

  • The audit trail is immutable and hash-chained: the request, each policy check with its result, the human approval signature, and the settled payment. The policy itself is versioned, hashed, signed, and replayable before you save it.

/// Evaluate

Give an agent a policy and a budget.

[ 01 ]

Guided demo walkthrough

We walk the whole loop with you — create an agent, set its policy, and watch a payment escalate for approval and settle as ordinary SEPA.

[ 02 ]

Sandbox account

A test environment where your team can set budgets, allowlists, and thresholds, then trip each one and read the append-only log.

[ 03 ]

MCP + API access and docs

Connect a test agent over MCP at mcp.protocore.io/agents, with the API and docs to wire your own framework to a policy.

[ 04 ]

Standalone or whitelabel

Evaluate under the Protocore brand or yours — your agents, your policy, either surface.

Availability

Available standalone or whitelabel — your agents, your policy, either brand.

In the ecosystem

Agents spends on Pay's rails under human policy, settles as ordinary SEPA, and writes to the same audit model Center reads.

Pick a product. Or take the core.

Everything above runs in production demos we can walk you through — standalone, whitelabel, or as one platform. Tell us what you're building and we'll show you the shortest path to it.

Contact us