Who delegated what?
Name the principal, objective, resources, counterparties, limits, expiry, escalation conditions, and revocation owner.
A payment-capable agent crosses from information work into delegated economic action. The operator's job is to keep that authority explicit, bounded, testable, and reversible.
By the end of this lesson, you should be able to inspect a proposed agent-payment workflow, assign evidence-based readiness scores, identify critical stop conditions, and explain why payment settlement is not proof of correct fulfillment.
Name the principal, objective, resources, counterparties, limits, expiry, escalation conditions, and revocation owner.
Keep signing material outside model context. Bind identity and authorization to the request, destination, time window, and rotation policy.
Enforce assets, networks, recipients, resources, amounts, velocity, and aggregate budgets deterministically—not through prompt language.
Preserve distinct states for intent, authorization, execution, settlement, fulfillment, and reconciliation. A transaction reference proves too little by itself.
Exercise replay, timeout, compromised credentials, duplicate requests, partial fulfillment, refund, dispute, and infrastructure outage paths.
An analysis agent may purchase one market-data response for no more than 0.01 USDC on an approved test network. The recipient is allowlisted. Signing is isolated from the model. The team logs payment settlement, but has not tested duplicate requests, correlated delivery to payment, or assigned an incident owner.
Mandate, identity, and policy may receive one point only if their documentation can be inspected; none deserves two without exercised tests. Outcome and exceptions cannot exceed one and may be zero: delivery correlation, idempotency, and incident ownership are missing. The appropriate next step is a testnet failure exercise—not higher limits or production funds.
STOP → TEST