Skip to content

Innovation

An agent is only as trusted as its mandate

Identity answers who an agent is. The mandate answers what it may do, for whom, within what limits, and until when. Trust lives in the second answer.

Agentic payments · Part 2 of 3

The first essay in this series made the case for treating agents as a new principal class: registered, credentialed, bound to a named operator, and holding no standing of their own. Identity answers who the agent is. It says nothing about what the agent may do. That is the mandate's job.

An agent holds no authority of its own. Everything it may do is delegated from a principal that has passed KYB, and the instrument of that delegation is the mandate: a documented grant naming the principal, the scope, the limits, and the expiry. Not a configuration setting buried in an integration. Evidence, held and monitored like evidence.

The mandate as evidence

In CPN's architecture the mandate lives in the Trust Vault, alongside the incorporation records, ownership documents, and verification evidence of the principal itself. The placement is deliberate. A mandate is not metadata; it is the operational basis on which value moves. The vault versions it, monitors its expiry, and drives renewal and re-approval workflows the same way it does for any other document that authority depends on.

Scope says which actions, which counterparties, which corridors. Limits say how much, per transaction and in aggregate, over what window. Expiry says until when, after which the authority simply is not there anymore. And the principal is named, so accountability has an address.

Enforcement at runtime

A mandate on file protects no one. What matters is enforcement at the moment of execution. Every instruction an agent submits is checked at every stage: does the agent's registration stand, is the mandate current, is the request inside scope, do policy, limits, and jurisdiction rules allow it. A request outside scope does not generate an alert for someone to review tomorrow. A breach is not flagged. It does not proceed.

Human controls survive intact. Approval thresholds and four-eyes requirements apply to agent actions unchanged. An agent can prepare a payment, but a transaction that would require two humans still requires two humans. Delegation extends the team; it does not dissolve the controls the team works under.

A breach is not flagged. It does not proceed.

Attestation and the kill switch

Every action an agent takes is recorded against its mandate in the Evidence & Audit Ledger: rule, version, inputs, outcome, timestamp. The record is hash-chained and tamper-evident, written at the moment of decision rather than reconstructed after the fact. When an auditor asks what an agent did and on whose authority, the answer is a ledger entry, not an investigation.

And when trust ends, it ends instantly. Revoking a mandate halts in-flight instructions, not just future ones. Revocation is a control surface action, not a ticket in a vendor queue, and it works mid-flight because every stage of execution rechecks the mandate before proceeding.

Trust is a discipline, not a sentiment

Organizations do not trust employees in the abstract; they trust them within roles, limits, and review. Agents deserve exactly the same shape of trust, formalized in an instrument that can be verified, enforced, and revoked. An agent is only as trusted as its mandate, and a mandate is only as good as its enforcement. Where that enforcement has to live is the subject of the final essay in this series.

See the control plane on your flows

Bring your payment flows. The team will show you what governance ahead of the rails changes on them.