Skip to content

Innovation

The control plane for agentic payments

Agentic payments need a control plane before they need anything else. Identity and mandates only bind if they are enforced in one place, ahead of execution.

Agentic payments · Part 3 of 3

This series has argued two things. Agents are a new principal class: registered, credentialed, bound to a named operator, holding no standing of their own. And an agent is only as trusted as its mandate: authority delegated from a KYB'd principal, held as evidence, enforced at runtime, revocable instantly. This closing essay is about where those controls have to live.

The thesis is short. Agentic payments need a control plane before they need anything else. When software agents initiate, validate, and reconcile payments, the question is not whether they can move money but under whose rules, and rules only govern when they are enforced in one place, ahead of execution.

Why per-rail controls fail

The instinctive response to agent risk is local: each bank hardens its portal, each API gateway adds its own key policy, each vendor ships its own agent settings. Every one of those controls is reasonable. Together they reproduce the exact fragmentation that broke payment governance for humans: many banks, many rule sets, many audit formats, and no single place where the organization's intent is stated once and enforced everywhere.

Fragmented enforcement has a sharper edge with agents. An agent's effective authority becomes whatever the weakest integration allows, and software finds the weakest integration faster than any human ever did. A limit enforced in four systems out of five is not a limit. It is a suggestion with an audit trail.

Governance has to sit in one place, ahead of every rail at once. CPN sits ahead of your payment rails. For agents, that placement means something concrete: there is exactly one door, and the door checks everything.

One control surface for every principal

Every agent-initiated payment passes the same control surface as a human one: identity, policy, limits, approvals, audit. Agents enter through the Agent API, a gateway that is KYA and mandate-checked before an instruction goes anywhere near a rail. From that point on, the fabric makes no distinction that weakens control: the same policy engine, the same screening, the same thresholds, the same ledger. Verified at the edge, governed inside the fabric.

There is exactly one door, and the door checks everything.

The uniformity is the point. A second, softer rulebook for agents would be an invitation to route around the first one. One rulebook, one evidence trail, one place where revocation takes effect at once, across every rail behind the plane.

What to demand before an agent touches payments

  • Registration. The agent is identified in its own name, bound to a named operator, with no shared credentials.
  • Mandate. A documented grant from a KYB'd principal: scope, limits, expiry, held as evidence and monitored for renewal.
  • Runtime enforcement. Standing, mandate, and policy checked at every stage of every instruction. Out of scope does not proceed.
  • Preserved human controls. Approval thresholds and four-eyes requirements apply to agent actions unchanged.
  • Per-action attestation. Every decision recorded against the mandate: rule, version, inputs, outcome, timestamp.
  • Instant revocation. A kill switch that halts in-flight instructions, not a ticket in a queue.

If any item on that list is missing, the agent is not governed; it is trusted. Those are different things, and the difference is the exposure.

The compounding case

The control plane was not built for agents. It was built because accountability without authority is untenable for human-initiated payments too. Agents compound the case rather than create it: they raise the volume, the speed, and the stakes of ungoverned execution. The architecture that answers them is the architecture that answers everything else. Set your rules once. CPN applies them to every transaction, on every rail.

Know Your Agent is live on the Control Fabric today: registration, mandates in the Trust Vault, runtime enforcement, per-action attestation, and instant revocation. If agents are anywhere near your payment operations, start there.

See the control plane on your flows

Bring your payment flows. The team will show you what governance ahead of the rails changes on them.