Spending mandate
A set of rules that bounds what an agent's wallet may spend — per-transaction caps, daily limits, and recipient allowlists — enforced at the wallet, not in the prompt.
A spending mandate is the policy that governs an agent's wallet. It defines how much the agent can spend per transaction, how much in total per day, and which recipients are allowed — turning open-ended payment power into bounded, predictable authority.
Crucially, the mandate is enforced by the wallet itself, not by instructions in a prompt. An agent can't talk its way past a hard limit, and a compromised prompt can't drain the balance.
What a mandate controls
Typical controls include a per-transaction ceiling, a rolling daily or monthly total, an allowlist of payees, and which kinds of payments are permitted. Together they let you delegate routine spending while capping the blast radius.
Anything outside the mandate is rejected or routed for human approval rather than executed.
Why enforcement location matters
Limits expressed only in a prompt are advisory — a model can be misled into ignoring them. Mandates enforced at the wallet are structural: the payment infrastructure refuses to exceed them, so safety doesn't depend on the agent behaving.
FAQ
Can the agent change its own mandate?
No. The mandate is set by you and enforced by the wallet; the agent operates within it and cannot raise its own limits.
What happens to an over-limit payment?
It's rejected or flagged for human approval instead of being executed.
Give your agent an inbox.
A real email address, a vault, 2FA, and an identity in one API call.