Mandate Firewall
Verify what an agent is allowed to do before execution. Scope, caps, counterparties, and policy rules are enforced server-side before any value moves.
- Per-agent mandates
- Counterparty classification
- Daily caps and policy guards
AgentGuard · Control Plane
The black box, mandate firewall, and settlement workflow layer for AI agents that touch money.
Payment protocols move money for AI agents. AgentGuard verifies intent, detects mandate violations, preserves evidence, and routes financial failures into auditable settlement workflows.
Three pillars
Verify what an agent is allowed to do before execution. Scope, caps, counterparties, and policy rules are enforced server-side before any value moves.
Capture intent, payload, decision hash, and receipt for every authorized action. Hash-chained audit events make every step independently verifiable.
When an action goes wrong, AgentGuard opens an incident case, verifies evidence, and routes it into partner-approved settlement instructions.
Why now
AI agents are starting to call payment protocols, x402-style flows, stablecoin transfers, partner payouts, and wallet actions on behalf of organizations. Most of those actions ship with no mandate verification, no consistent audit trail, and no settlement path when something goes wrong.
AgentGuard sits in front of those actions: it checks the mandate, evaluates policy, records hash-chained evidence, and gives partners a structured way to verify incidents and approve settlements.
Architecture
AgentGuard extends Cryptodam's digital-asset incident protection architecture into AI-agent-driven financial actions. The same modules that govern monitoring, trigger verification, eligibility, and payout workflows are reused to verify agent mandates, classify action attempts, and route verified incidents into partner-approved settlement.
Integration
Partners integrate AgentGuard through scoped API endpoints. Credentials and scopes are managed in the Partner Console — no secrets are exposed on this page.
| Method | Path | Purpose |
|---|---|---|
| POST | /functions/v1/agentguard-authorize-action | Evaluate a proposed action against mandates and policy. |
| POST | /functions/v1/agentguard-record-action-receipt | Record execution payload and produce an evidence trail. |
| POST | /functions/v1/agentguard-x402-webhook | Inbound x402-style payment-protocol receipts. |
Product boundary
AgentGuard is
AgentGuard is not