Agentic payments · Part 1 of 3
Software agents are crossing a line. For years they read, summarized, and recommended. Now they act: they raise purchase orders, book freight, reconcile invoices, and increasingly, they initiate payments. The moment an agent can commit value, it stops being a feature of someone's workflow and becomes something the payments world has no category for.
The market keeps asking whether agents should be allowed to move money. That is the wrong question, and it is answering itself: they already do, informally, through credentials borrowed from the humans who deploy them. The question that matters is under whose rules. Authority, not capability, is the frontier.
The categories we have do not fit
Payments infrastructure recognizes two kinds of principal. A person, verified through KYC. An organization, verified through KYB. Every control in the stack assumes the actor behind a payment is one of the two. An agent is neither. It is not an employee: it has no contract, no accountability of its own, no seat in an approval chain. It is not a counterparty: it holds nothing and owes nothing. And it is not a system account, although that is how it usually gets treated.
Authority, not capability, is the frontier.
The system-account habit is where the risk concentrates. A shared credential with standing access, no expiry, and no bounded scope, exercised by software that acts faster than any reviewer. When something goes wrong, the audit trail reads: the integration did it. No principal, no mandate, no accountability. That pattern was tolerable when the software only read data. It is not tolerable when the software moves money.
A new principal class
The fix is to treat agents as what they are: a new principal class. Registered, credentialed, bound to a named operator, and holding no standing of their own. Each clause carries weight.
- Registered. The agent has an identity of its own, on record: not a borrowed login, not a shared key. You cannot govern what you cannot name.
- Credentialed. Its credentials are individual and verifiable, with no shared credentials anywhere in the chain, interoperable with emerging agent identity protocols.
- Bound to a named operator. A person or organization answers for the agent. Software cannot be accountable; its operator can.
- No standing of its own. Whatever the agent may do is inherited from a principal that has passed KYB. Authority is delegated, bounded, and revocable, never possessed.
This is Know Your Agent: KYA, taking its place beside KYB and KYC. It extends the identity discipline organizations already accept for people and companies to the software now acting on their behalf. Verified at the edge, governed inside the fabric.
Registration is what makes delegation usable
None of this is an argument against agents. It is the opposite. An enterprise that cannot identify its agents has two options: block them and lose the leverage, or tolerate them and carry ungoverned execution inside its own treasury. Registration opens the third option: delegate with confidence, because the delegation has a name, a boundary, and an owner.
Identity is only the first layer. A registered agent still needs its authority defined: what it may do, for whom, within what limits, until when. That instrument is the mandate, and it is the subject of the next essay in this series. An agent is only as trusted as its mandate.