The control plane for AI-agent economic authority / Europe

Your agents can spend.
You stay in control.

Your agents spend on model APIs, data and compute every hour. Paygente decides which agent may spend what, with whom, for what purpose, and records why.

For teams running AI agents, and the people accountable for the budget those agents spend.

Paygente decides. Nothing is paid. It records what your agents proposed and what your policy would have decided. No funds are held, no card is issued, and no payment provider is contacted.

Research Agent

Runs market and competitor research for the strategy team.

Day budget€86.28 of €120 used

Authority

  • Approved AI and data providers only.
  • €120 per day.
  • A single authorisation above €25 needs a person.
  • A provider not on the list needs a person to add it.
  • Authority ends at 18:00.
  • Model API, analysis run

    €4.62

    ALLOWED
  • Search API, 400 queries

    €1.10

    ALLOWED
  • Company data, 62 records

    €8.00

    ALLOWED
  • 214 further calls to approved providers

    €72.56

    ALLOWED
  • Industry report, extended licence

    €32.00

    NEEDS APPROVAL

    Above €25, so a person decides. Sent to Jonas.

  • Unlisted data vendor

    €18.00

    REFUSED

    Not an approved provider.

  • Overnight batch

    €42.00

    REFUSED

    Only €33.72 of today’s €120 remains.

Illustrative. Open the sandbox for live data.


The authorisation gap

Agents can act.
Payments still assume a human is clicking.

What payment systems assume

Card networks, bank transfers and checkout flows were built around a person at the end of the process. The control is the moment someone looks at a number and decides. Everything downstream - limits, fraud rules, disputes - is calibrated to that pause.

What autonomous agents need

An agent acts continuously, at machine speed, against instructions that may have been influenced by content it read. It loops, it retries, and it does not stop to look at a number. Handing it a credential transfers unbounded authority. What it needs instead is bounded authority: a specific amount, to a specific recipient, for a specific purpose, that expires.

One request can look harmless. So can the next ten. The running total is what matters, and it arrives before anyone reconciles a bill.


Credentials and authority

Why not just give it a key?

A credential gives access

A vendor key identifies an account at that vendor. Many providers add useful controls on top: a scope, a rate limit, often a spending cap.

  • Account
  • Provider
  • Technical scope
  • Sometimes a spending cap

Every one of those controls governs what happens at that one provider.

Paygente decides economic authority

One company policy, applied across every provider an agent can reach, expressed in terms a finance team already uses.

  • Which agent
  • For what purpose
  • With which recipient
  • How much per action
  • How much cumulatively, over which period
  • Until when
  • Under which company policy
  • With which human approval
  • And why it was allowed, escalated or denied

The two are not alternatives. Provider controls bound a provider. Paygente bounds the agent.


How Paygente works

Propose, decide, record. Execution is a separate question.

  1. 01Propose

    An agent proposes an economic commitment.

    Which agent, which supplier, how much, what for, under which cost centre, and what kind of commitment it is. A proposal, not a payment instruction.

  2. 02Decide

    Apply deterministic policy and human approval.

    A pure TypeScript engine evaluates every rule, including the running total against the day and the month, and returns every reason. No language model participates in the decision.

  3. 03Record

    Keep the evidence, whatever was decided.

    Every proposal and every decision is written to an append-only trail with the agent, the supplier, the reasons and a correlation id. This is where it ends - nothing is executed and nothing is paid.


Anatomy of a mandate

Everything that bounds a payment, in one record.

Authorisation reference PG-2051

Approved
Agent identity
Research Agent / research-agent
Purpose
Q2 European logistics dataset
Recipient
Approved data provider - verified, low risk
Approval
Not required below €40.00
Cumulative
€18.50 of €250.00 today
Maximum action
€100.00
Expires
01 AUG 2026 / 09:14 UTC
Evidence
Invoice reference 2211
Principal
Northstar AI Labs
Amount
€18.50 EUR
Execution
Not executed

Illustrative record. Simulated rail.

Agent identity
Which principal is spending, and under whose account.
Purpose
The business reason, recorded verbatim, so an auditor sees what the requester actually wrote.
Recipient
Where the money may go, with the verification and risk that the policy will read.
Approval threshold
The point above which a person must decide.
Cumulative window
What this agent has already committed today and this month. A limit that only counted single actions would not survive a retry loop.
Maximum action
The ceiling no single commitment may cross.
Expiration
When the authority lapses, whether or not anyone is watching.
Evidence
The invoice, quote or reference that justifies the payment.
Amount and asset
Exact integer minor units. Never a floating-point number, at any layer.
Execution status
What the rail actually did, and whether it matched the mandate.

The control layer

Six controls, all enforced server-side.

01

Limits that add up

Per action, per day, per month. Nine retries can each pass a per-action limit and still empty a budget, so the running total is evaluated too. Enforced as integers, never as floating-point numbers, and reserved at approval so the same limit cannot be spent twice.

02

Recipient allow-lists

An agent spends with whoever you decided it may spend with. Recipients carry a verification status and a risk classification, and both are inputs the policy engine reads.

03

Human approval

Above a threshold you choose, a person decides. The person who requested a payment cannot be the person who approves it.

04

Expiration

Authority lapses. A mandate carries a window, the window has a maximum the policy sets, and an expired mandate cannot execute even if it was approved.

05

Revocation

Withdraw authority before execution, from a single mandate - or stop every execution in the organization at once with the kill switch.

06

Audit history

Every proposal, decision, approval and execution attempt, with the actor, the reasons and a correlation id. Append-only, enforced by the database.


Where the money actually goes

The same policy question, in three different jobs.

The Research Agent above is one. Two more, written the same way: what the agent is responsible for, what it is allowed to do, and what happened when it tried.

Build Agent

Today

Provisions test environments for the platform team.

Day budget€327.40 of €400 used

Authority

  • Two infrastructure providers.
  • €200 per action, €400 per day.
  • A person decides above €150.
  • Reserved and recurring capacity is never automatic.
  • Authority ends when the run ends.
  • Test environment, 4 hours

    €12.40

    ALLOWED
  • GPU capacity, 6 hours, spot

    €63.00

    ALLOWED
  • Reserved GPU capacity, 1 month

    €180.00

    NEEDS APPROVAL

    Above €150, and capacity that renews. A person decides.

  • Same job, retried 4 times

    €252.00

    ALLOWED

    €327.40 of today’s €400 used.

  • Same job, retried 5 more times

    €315.00

    REFUSED

    Every attempt is €63.00, inside the €200 per-action limit. Only €72.60 of the day remains.

Illustrative. Paygente does not provision infrastructure.

Procurement Agent

Near-term

Handles renewals and supplier orders for operations.

Authority

  • Approved suppliers only.
  • €2,000 per order.
  • A person decides above €250.
  • Every order carries a cost centre.
  • Subscriptions are never automatic.
  • Data licence, Q3, existing supplier

    €240.00

    ALLOWED

    Cost centre CC-RES-207.

  • Same licence, no cost centre

    €240.00

    REFUSED

    This policy requires a cost centre.

  • Observability plan, 12 months

    €1,180.00

    NEEDS APPROVAL

    Above €250. Sent to Jonas, who did not request it.

  • Monthly plan, renewing until cancelled

    €120.00

    REFUSED

    This policy allows orders and invoices, not open-ended subscriptions.

  • Annual panel licence

    €4,800.00

    REFUSED

    Above the €2,000 ceiling. Asking again will not change the answer.

Illustrative. No supplier is contacted.

A spending limit can cap an amount. It cannot require a cost centre, tell a one-off purchase from a recurring commitment, or decide which person has to approve it.


Who enforces the constraint

Paygente decides. Something has to enforce.

Authorisation and enforcement are separate concerns, and today Paygente only does the first. It decides an action against your policy and records the result, then stops. It contacts no supplier, calls no rail and places no order.

Which means the honest question is not which rails we support. It is who refuses an action the policy did not allow.

  1. 01Today

    Your integration enforces

    ■ Built

    Paygente decides, records the decision and every reason behind it. Your runtime respects that decision.

    Bypassable by construction. A system that never asks Paygente is not stopped by Paygente.

  2. 02Direction

    A provider enforces

    □ Not built

    Authority tied to the credential or the service path, so the constraint is applied by whoever holds the thing being spent rather than by the caller.

    Not built. No provider integration exists.

  3. 03Vision

    The network enforces

    □ Not built

    An action outside the authorised boundary refused by the underlying infrastructure, whether or not the agent cooperated.

    Not built, and not a commitment to a date or a protocol.

Paygente decides whether the authority should exist. The infrastructure underneath determines how value moves. Those are different jobs and we intend to keep doing the first one.

Service Agent

Vision

An agent buying a machine service from another company.

Today Paygente decides, and your runtime enforces the decision. An agent that never asks is not stopped; it is recorded.

The direction is stronger enforcement, where the credential, the provider or the network refuses authority the company never granted.

Paygente does not become the payment credential. It decides whether that authority should exist, for which agent, for what purpose, with which recipient, for how much, for how long and on whose approval.

Nothing described here is built. No dates, no protocols, no partners.

For developers

One decision. REST, SDK or MCP.

An agent asks whether it may spend, and gets the answer in the same response. The same Zod schema validates every transport, the same pure engine decides them, and all three land in the same audit record.

Spend request and decision
POST /api/v1/spend-intents

{
  "agentId": "agt_01JQ8F7Z9K3M4N5P6Q7R8S9T0V",
  "recipientId": "rcp_01JQ8F7Z9K3M4N5P6Q7R8S9T0V",
  "asset": "EUR",
  "amount": "1180.00",
  "category": "software",
  "commitmentType": "PURCHASE_ORDER",
  "purpose": "Observability plan, 12 months.",
  "projectReference": "CC-OPS-114"
}

→ REQUIRE_APPROVAL
  AMOUNT_REQUIRES_APPROVAL
  "€1,180.00 is at or above the €250.00
   threshold, so a person has to approve it."

Security and control

The agent proposes. Software decides.

No reusable credentials

An agent never receives a private key, a card number or a reusable payment credential from Paygente. It receives a decision. There is nothing here for a prompt injection to exfiltrate.

Deterministic authorisation

The policy engine is a pure function: no I/O, no randomness, no clock of its own, and no language model. The same inputs always produce the same decision, and a past decision can always be re-explained.

Organization isolation

Every query is scoped by organization. A record belonging to another tenant returns exactly the same response as one that does not exist.

Idempotent execution

A mandate executes once. The state machine, a row lock, a database unique index and the rail’s own idempotency each refuse a second payment independently.

Kill switch

An administrator can stop every execution in the organization immediately, without revoking anything. Approvals survive; execution does not resume until the switch does.

Licensed execution partners

Paygente is software. It holds no funds and custodies no keys. Production execution is intended to be delegated to licensed CASP, EMI, card-issuing or payment partners through adapters.

Read the threat model

Let agents act
without giving up control.

Open the sandbox

Seeded with a demo organization. Nothing to install.