Skip to main content
A policy envelope defines the constraints checked by agent tools that evaluate policy. Grants separately limit the agent’s tools and tenant access. Review both before allowing an agent to act.

Policy controls

A denial takes precedence over step-up. An approval cannot bypass an amount cap or an unapproved destination.

Configure a policy

Use the policy controls available for the agent and review the saved envelope. Package presets are starting points. They do not establish the settings applied to an installed agent. For payment tools that use step_up_amount_cents, zero requests approval for every nonnegative amount that otherwise passes policy. An omitted threshold does not add an amount-based approval requirement. Some tools require approval independently of that field. Card issuance applies its own scope and funding-cap checks. It does not run the same inline step-up flow as payments.initiate. See cards.issue.

Preset examples

The packages include these Trust presets:
  • AP agent: 2,500pertransactionand2,500 per transaction and 10,000 per day. The counterparty allowlist starts empty; there is no automatic QBO or Xero vendor import.
  • Treasury: 50,000pertransactionand50,000 per transaction and 250,000 per day. The skill is blocked on live yield dependencies.
  • Market research cap: 0.50percalland0.50 per call and 50 per day.
These are source-defined templates, not pricing claims or universal account limits. Review the live envelope before spending.

Policy changes and grants

A grant records the policy version at issuance. A version mismatch can reject a later call. Refresh or obtain a new grant through the supported flow after a policy change; do not assume an already-authorized action has been cancelled. Grant validation limits token lifetime to 60 minutes. Refresh also depends on scope, current policy and agent status.

Review outcomes

Check the tool’s result and any pending action. An accepted request or approval is not proof of settlement. If a call fails after submission, resolve its status before retrying.

Next