Use case
AI-agent spend controls
An agent may prepare a payment. It does not get an open key. The blueprint is a budget, an allow-list, and a way to stop it.
A company wants software to buy, pay, or call an API up to a limit, with a record a controller can read.
When shared machinery earns a place
Delegated authority with a hard stop is a product. A chain is optional, and usually not the first version.
When it does not
An agent that holds the only key to customer funds is refused by this constructor.
Conventional-first
Service identity, budget in the application, allow-listed endpoints, audit log, kill switch.
No external settlement. Fast to supervise.
Hybrid
Agent identity, policy service, quorum wallet the agent cannot unilaterally raise, reconciliation.
Two ledgers. The policy service is now critical infrastructure.
On-chain-native
Smart-account limits. The agent is not an owner. A person can pause.
Irreversible mistakes. GPL reference code must not be copied in blindly.
Patterns
Components
- Safe Smart AccountAmber — conditions, and a legal review before you copy it in
- viemGreen — compatible use if you keep the notices
- wagmiGreen — compatible use if you keep the notices
- ERC-4337 contracts (eth-infinitism)Red — reference only, do not incorporate automatically
Questions a person still has to answer
- What is the maximum the agent can move in a day?
- Who can pause it at 3am?
- Which destinations are allow-listed?
- Where is the log kept?
