Guide · agentic commerce
How to verify an AI agent before it pays
Before an AI agent completes a purchase, verify three things: who the agent is, whether this purchase is inside what it was allowed to do, and whether you will be able to show that afterwards. In practice that is seven checks, run in order at the moment the agent asks to pay — not in a review the next morning.
The seven checks
Run them in this order; each one that fails should stop or hold the purchase rather than log a warning.
- Identity: the request comes from a registered agent, not an unknown process holding a key.
- Status: the agent is active — not suspended, quarantined or retired.
- Owner: a named person is accountable for the agent.
- Granted action: this kind of purchase is one the agent was explicitly permitted to make.
- Amount: the amount is below the threshold that needs a person; at or above it, the purchase waits for approval.
- Destination: the merchant or account being paid is one your rules allow.
- Record: the decision, its inputs and the rule that made it are stored before the payment runs.
Why before, not after
A control that reviews purchases after they settle produces refunds and disputes, not prevention. Deciding before the payment call means a wrong purchase never reaches the card network, and the decision record exists even when the answer was no.
What the payment protocols add
Card-network agent programmes and protocols such as AP2 help the merchant and the network verify the agent and the person’s mandate. They complement, rather than replace, the checks above, which are about what your organisation allows its own agents to do.
How Agent Trust Cloud runs these checks
Agent Trust Cloud keeps the agent registry, evaluates each action against policy before it executes — including amount thresholds and destination rules — holds purchases above a threshold for a person, refuses actions an agent was not granted, and stores a decision record per action. You can start free with Discover to find and register the agents you already run.