Agentspay

Explainer

AI Procurement Software: Agentic Procurement Platforms and AI Procurement Agents Compared

Every major procurement suite shipped agents during 2026. Almost none of them answer the question your controller will ask first, which is what happens when the agent is wrong about a purchase and the money has already moved.

Agent Payments Console

Pick an agent

Payment intent

intent:

Policy evaluation

Human approval required

This spend is over your approval threshold. Approve it to issue a scoped card, or deny it.

Scoped virtual card issued

Agentspay

single-use

Wallet budget

spent of

Audit trail

In short

A procurement agent is an AI system that runs part of the buying process on its own: it picks up an intake request, checks it against spend policy and existing contracts, sources or matches a vendor, raises the requisition or purchase order, and routes it to the right approver. The leading platforms in 2026 are Zip, Coupa, Ramp, Levelpath, and the agent layers built into Oracle Fusion and SAP Ariba. Gartner forecast in April 2026 that supply chain management software with agentic AI would grow from less than 2 billion dollars in 2025 to 53 billion dollars in spend by 2030, with adoption among enterprises using SCM software rising from 5 percent to 60 percent. The important detail for a buyer: nearly all of these agents stop at the approval step. They produce a document a human still executes. Giving an agent a live payment credential is a separate decision that needs a hard budget, a vendor allowlist and an approval threshold enforced outside the agent itself.

What is a procurement agent?

In the traditional sense a procurement agent is a person: the buyer in a purchasing department who sources suppliers, negotiates terms and issues purchase orders. The term now carries a second meaning, and that is the one this page is about. An AI procurement agent is software that performs those same steps with a goal rather than a script. You tell it what is needed, and it works out the rest: which vendor, at what price, against which contract, under whose budget. The distinction that matters is between an agent and the automation procurement teams already had. A workflow rule routes a requisition over 5,000 dollars to a director. That is automation, and the path was drawn in advance. An agent reads the request, notices the vendor is not on the approved list, checks whether an equivalent supplier already has a signed master agreement, proposes that instead, and explains why. Nobody drew that path. That flexibility is the product, and it is also exactly why the spend question gets harder rather than easier.

How do AI procurement agents actually buy?

Strip away the vendor language and every agentic procurement flow runs the same six steps. Intake: an employee describes what they need in plain language instead of hunting for the right form. Triage and policy check: the agent classifies the request, tests it against spend thresholds, category rules and preferred-supplier policy, and asks follow-up questions when something is missing. Sourcing or contract matching: it checks whether an existing agreement already covers the purchase before it goes looking for a new vendor, which is where most of the claimed savings actually come from. Requisition and purchase order: it assembles the line items, cost center coding and the PO itself. Approval routing: it sends the PO to whoever policy says must sign, with the reasoning attached. Receipt and match: after delivery it matches the invoice to the PO and the goods receipt. Notice what is missing from that list. Nowhere in those six steps does the agent hand over a card number. The purchase order is a promise to pay, not a payment, and that gap is deliberate. We cover the document chain in detail in AI agent purchase orders and agentic procure to pay.

Assistants, simple agents, advanced agents: know which one you are buying

Gartner splits the market into three tiers, and the split is worth borrowing because vendors do not volunteer which tier they are selling. An assistant answers questions and drafts things: it tells a requester what the bid threshold is or writes the first version of a scope of work. A simple agent completes a discrete task end to end: create this requisition, chase this supplier for a W-9, check this PO status. An advanced agent orchestrates a multi-step workflow across systems and makes judgment calls inside it: take this renewal, benchmark the price, decide whether to renegotiate or switch, and run the sourcing event. Most of what shipped in 2026 is tier one and tier two wearing tier three marketing. That is not a scandal, it is an early market, but it changes your evaluation. Ask a vendor to name the decisions the agent makes without a human, then ask what happens when one of those decisions is wrong. If the answer is that a person reviews everything anyway, you are buying an assistant, and you should price it like one.

AI procurement agent platforms compared

Five products come up in almost every US evaluation, and they are not substitutes for each other. Zip leads with intake and orchestration, sitting in front of the systems you already run rather than replacing them. Coupa is the full source-to-pay suite and has been buying its way into the agentic layer, acquiring the no-code intake and orchestration platform Tonkean on May 21, 2026, its fourth acquisition in that direction after Cirtuo, Scoutbee and Rossum. Ramp came from the opposite end, corporate cards and AP, and launched a fleet of procurement agents on April 29, 2026 that triage employee requests, source vendors, review contract terms and prepare renewal negotiation briefings. Ramp is also the only one of the five that will issue a payment credential directly to an agent, through Agent Cards scoped to a single merchant and amount. Levelpath is AI-native and deliberately scoped to intake-to-procure rather than full procure-to-pay. Oracle Fusion and SAP Ariba ship agents inside the ERP, which is the right answer if your requisition and budget data already live there. The table below is the honest version, including where each one stops.

Intake-to-procure or procure-to-pay: which half are you buying?

This is the single most useful question to ask early, because it determines whether the product ever touches money. Intake-to-procure covers everything from the moment someone asks for something to the moment a purchase order is approved: the request, the policy check, the sourcing, the negotiation, the PO. Procure-to-pay continues from there through goods receipt, invoice matching, payment and reconciliation. Vendors that stop at intake-to-procure are selling you better decisions, and their agents are genuinely useful without ever holding a credential. Vendors that carry through to pay are the ones where agent autonomy starts to have a dollar value attached to being wrong. Neither is better. But if you buy an intake-to-procure product and then wire your own agents into the payment step to close the loop, you have quietly taken on the control problem yourself, and it will not be in the vendor evaluation you ran.

The moment the agent needs a payment credential

Purchase orders work when the supplier will invoice you. A large share of what companies actually buy does not work that way. Cloud capacity, ad inventory, API calls, SaaS seats, sample orders, conference tickets and marketplace goods are all paid at the point of purchase with a card. There is no PO, no net-30, and no invoice to match. When a procurement agent moves into that category of spend, the six-step flow collapses: intake, policy check, and then the agent has to pay. That is the moment the agent needs a credential of its own, and it is the moment the procurement suite hands the problem back to you. The instinct is to give the agent a corporate card number and set a monthly limit. It fails in a specific and repeatable way. A monthly limit is a ceiling, not a control, and an agent stuck in a retry loop can spend the entire month of budget in ninety seconds, correctly, against a card that was working exactly as configured. What you need instead is a limit evaluated before each authorization and a credential that is worthless outside the one purchase it was issued for. Our agentic payments explainer covers the four rails that carry those credentials.

Five controls a purchasing agent needs before it can spend

The control set is short and none of it is novel. What is novel is where it has to live. Every one of these must be enforced by infrastructure the agent cannot talk its way past, because an agent that reads supplier emails, web pages and tool output can be steered by text an attacker planted there. A budget written into a system prompt is a suggestion. The same budget checked at the authorization boundary is a limit. This is the design Amazon shipped in Bedrock AgentCore Payments, where the per-session spend ceiling is enforced at the infrastructure layer, deliberately outside agent code. Read the practical version in AI agent procurement controls for finance teams, and see when to gate an agent payment on a human for how to pick the threshold.

What procurement agents still cannot do

Being straight about the limits is more useful than another capability list. Agents are weak at commercial judgment under ambiguity: deciding that a supplier relationship is worth paying 8 percent more to protect is not a data problem. They are weak at anything with a counterparty who negotiates back, because the other side adapts and the agent does not have the context a buyer accumulated over three renewal cycles. They are weak at first-time supplier risk, where the signal is thin and the consequences are legal rather than financial. And they are structurally bad at knowing when they are wrong, which is the failure mode that matters most once money is involved. The useful framing is that agents are strong on the repetitive, well-specified 80 percent of purchase volume that consumes most of a procurement team's hours and almost none of its judgment. Point them there first. Tail spend, repeat orders from onboarded suppliers, and renewals with no strategic component are where the return is real and the downside is bounded.

The audit question that stalls agentic procurement programs

Programs rarely die because the agent bought the wrong thing. They die at month end. A charge arrives on a statement with a merchant descriptor and an amount, and finance cannot code it, because nothing on that line says which agent made the purchase, which task triggered it, which human owns that agent, or which policy allowed it. Multiply that by a few hundred transactions and the accounting team, not the security team, is the one that shuts the pilot down. The fix has to be designed in at the start, because the context that makes a charge explainable exists only at the moment of authorization and is gone by the time the statement lands. What you want written down, immutably, per transaction: the agent identity, the human owner, the originating request, the policy that was evaluated, the verdict, and the approver if one was involved. Our page on reconciling AI agent spending covers the month-end workflow.

How to pilot an AI purchasing agent without scaring finance

The pilots that survive look boring and share four traits. Pick bounded spend. One category, an allowlist of suppliers you already onboarded, and a total program budget small enough that the worst case is an annoyance rather than an incident. Set the approval threshold low at first and raise it on evidence. Starting at 250 dollars and moving to 2,500 after sixty clean transactions is a much easier conversation than starting high and defending it. Test the failure case in the demo, not in production. Have the agent try to exceed its budget, try to buy from a supplier that is not on the list, and try to run the same order twice. If any of those succeed with a warning rather than a decline, you do not have controls. Instrument reconciliation on day one. If finance can code every agent transaction without asking a question during the pilot, the program expands on its own. If they cannot, no amount of savings will save it. For the wider vendor landscape beyond procurement suites, see AI agent payment platforms compared.

Where Agentspay fits

Agentspay is not a procurement suite and does not compete with one. It is the control plane that sits underneath whichever agent is doing the buying, and it answers the question the suites leave open: should this specific purchase be allowed to complete right now? Each agent gets a funded agent wallet, hard spend limits evaluated before every authorization rather than after, human approval above the threshold you set, scoped virtual cards that are merchant-locked and single-use, and an immutable audit trail naming the agent, the intent and the human owner on every line. Because it is rail-neutral it works whether your agents buy by card, by protocol, or per API call. If you want the product view for a buying team rather than the category view, start with procurement agents on Agentspay.

Whatever standard moves the money, Agentspay is the rail-neutral control plane that keeps it governed. See how it works and the control surfaces that enforce policy, approvals, and audit on every transaction.

Side by side

AI procurement agent platforms compared

Capabilities as documented by each vendor in August 2026. Verify scope and pricing directly, this market is moving every quarter.

Zip Coupa Ramp Levelpath Oracle Fusion / SAP Ariba
What it is Intake-first procurement orchestration Full source-to-pay spend management suite Corporate cards, AP and procurement in one platform AI-native intake-to-procure Agent layers built into the ERP
Where the agents act Intake, approvals, vendor onboarding, renewals Intake, sourcing, contracts, invoicing, supplier onboarding Request triage, vendor sourcing, contract review, renewal briefings Sourcing, contracts, risk intake Requisition creation, PO status, policy questions
Issues a payment credential to the agent No No Yes, Agent Cards scoped to one merchant and amount No No
Where spend is enforced Approval workflow Approval workflow and budget checks At card authorization, plus the issuing user policy Approval workflow ERP budget checks and approval hierarchy
Covers procure-to-pay end to end Partly, it orchestrates across your existing systems Yes Yes for card and AP spend No, stops at procure Yes
Best for Enterprises wanting one front door over systems they keep Global enterprises standardizing source-to-pay US mid-market finance teams already on Ramp Teams replacing a legacy intake process Companies committed to the ERP

The control layer

Five controls a procurement agent needs before it can spend

The controls are ordinary. Where they are enforced is what separates a real limit from a suggestion an agent can be argued out of.

Control What it stops Where it has to be enforced
Hard per-agent budget A retry loop or a misread quantity turning one order into forty At the authorization boundary, checked before every transaction, not as a wallet balance the agent can drain in one call
Vendor and category allowlist An agent buying from a supplier nobody onboarded or diligenced In the issuer or control plane, never in the agent prompt
Approval threshold An agent committing above the amount a controller will delegate In a routing step that pauses the purchase and names a specific approver
Scoped single-use credential A leaked or prompt-injected card number being reused elsewhere At the card issuer, locked to one merchant and one amount
Immutable audit record A charge landing on a statement with no agent, task or owner attached Written at authorization time, not reconstructed from statement data later

Frequently asked

Questions people ask about AI Procurement Agents

What is a procurement agent?

Traditionally, a procurement agent is a person in a purchasing department who sources suppliers, negotiates terms and issues purchase orders. In 2026 the term also means an AI procurement agent: software that performs those steps from a goal rather than a fixed workflow, taking an intake request through policy checks, contract matching, PO creation and approval routing.

What is AI procurement?

AI procurement is the use of AI to run purchasing work that previously needed a buyer. It spans three levels: assistants that answer policy questions and draft documents, simple agents that complete one task such as creating a requisition, and advanced agents that orchestrate a full sourcing or renewal workflow across systems and make judgment calls inside it.

What is the best AI agent for procurement?

There is no single best one, because the products solve different halves of the problem. Zip and Levelpath are strongest at intake and orchestration. Coupa covers source-to-pay for global enterprises. Ramp suits US mid-market finance teams and is the only one that issues scoped payment cards directly to agents. Oracle Fusion and SAP Ariba make sense if your requisition data already lives in the ERP.

Can an AI agent create a purchase requisition?

Yes. Requisition creation is one of the most widely shipped agent capabilities, available in Zip, Coupa, Ramp, Levelpath and the agent layers in Oracle Fusion and SAP Ariba. The agent gathers the line items, applies cost center coding, checks the request against spend policy, and submits it. Approval still routes to a human above your threshold.

Can an AI agent approve a purchase order?

Technically yes, and in most organizations it should not. Approval is where accountability attaches, and an approver who cannot be questioned afterward is not much of a control. The common pattern is tiered: the agent auto-approves below a small amount, notifies in a middle band, and requires a named human above a threshold that starts low and rises as the agent proves itself.

How is agentic AI used in procure to pay?

Across four steps. It triages intake requests and checks them against policy, it matches the request to an existing contract or sources a new vendor, it raises the requisition and purchase order and routes approvals, and it performs the three-way match between the PO, the goods receipt and the invoice. The payment step itself usually stays with AP or a card control layer.

How do you set a spending limit on a procurement agent?

Set it outside the agent. A limit in a system prompt can be argued away by text the agent reads. A real limit is a per-agent budget evaluated at the authorization boundary before every transaction, combined with a per-card cap at the issuer, a vendor allowlist and a human approval threshold. See hard spend limits.

Will AI procurement agents replace procurement teams?

Not on current evidence. Agents handle the repetitive, well-specified majority of purchase volume that consumes hours and little judgment: tail spend, repeat orders from onboarded suppliers, routine renewals. They are weak at commercial negotiation, first-time supplier risk and knowing when they are wrong. The roles that shrink are transactional buying, not category strategy or supplier management.

Keep reading

More explainers

ServiceNow AI Control Tower

ServiceNow AI Control Tower

ServiceNow AI Control Tower is the most complete agent inventory and risk console a large US enterprise can buy, and it now reaches across AWS, Google Cloud and Azure. We read the schema ServiceNow ships to developers to answer the one question the rollout meeting always ends on: can it stop an agent from spending money? It cannot, and the reason is written into the data model.

Read

Gemini Enterprise

Gemini Enterprise

Google did something in August 2026 that the other agent platforms have not done: it shipped a hard monthly spend cap that genuinely stops usage instead of emailing you about it. That deserves credit, and it also moves the interesting question one step along. A cap that stops something is only as useful as the thing it is scoped to, so we went and measured what Google can actually point that cap at, in the API model Google publishes for anyone to read.

Read

Salesforce Agentforce

Salesforce Agentforce

Agentforce is the largest agent platform any US enterprise is likely to already own, and it moved to consumption billing, which means the meter now runs on what your agents do rather than on how many seats you bought. That raises a finance question the rollout deck rarely answers: when an Agentforce agent is loose in production, what actually stops it spending. We went and measured the answer in Salesforce own published object model rather than guessing at it.

Read

AWS AgentCore

AWS AgentCore

Amazon shipped the missing piece in August 2026. Bedrock AgentCore Payments went generally available, and it is a real payments product: an agent can now hold a wallet, meet an HTTP 402, pay, and carry on reasoning without a human in the loop. So the question a platform lead has to answer stopped being whether AWS gives agents money and became a narrower, more awkward one: how much of a spend policy did AWS actually ship? We went and measured it, property by property, in the API model AWS publishes.

Read

Microsoft Agent 365

Microsoft Agent 365

Microsoft shipped a control plane for AI agents, and it is a good one. It gives every agent an identity, a registry entry, an owner, a sponsor and a Conditional Access policy. Then somebody in finance asks the obvious follow-up question: fine, but what stops the agent from spending money? This page answers what Agent 365 costs, what it governs, and what we measured when we went looking for a dollar amount anywhere in Microsoft's agent governance surface.

Read

QuickBooks MCP Server

QuickBooks MCP server

Connecting an accounting system to an AI assistant is now a ten minute job. Deciding what that assistant is allowed to do once it is connected is the part nobody writes about, and it is the part your controller will ask about first. This page compares what the official QuickBooks, NetSuite and Xero MCP servers actually hand a model, measured rather than summarized from marketing pages.

Read

Payment MCP Servers

payment MCP servers

Every large payment company shipped an MCP server in the last eighteen months, and almost every write-up of them is a setup tutorial. The setup is the easy part. The question worth answering before you connect one to a production account is narrower and much less comfortable: what, exactly, can the model on the other end of that connection do to your money?

Read

PayPal Agentic Commerce

PayPal Agentic Commerce

PayPal made a bet that most merchants would rather not implement a commerce protocol at all. Where Stripe and OpenAI shipped a spec for you to build against, PayPal shipped two products that sit on top of the checkout you already have, and then bought a company to make the catalog half work. That choice is the whole story: it explains why Agent Ready needs almost no engineering from you, why there is nothing for an agent to discover about your store on the open web, and why the thing PayPal will not do for you is the thing that gets expensive later.

Read

Shopify Agentic Commerce

Shopify Agentic Commerce

Shopify switched agentic commerce on by default, so your store is probably already selling to AI assistants whether or not anyone on your team configured it. Instead of restating the announcement, we checked something you can check too: on September 2, 2026 we requested the machine-readable capability file that Shopify publishes for real storefronts, on fourteen well-known US brand domains, and read what it exposes to an agent. Eleven answered correctly. The three that did not share one trait, and it is quietly costing them agent traffic.

Read

Web Bot Auth

Web Bot Auth

Web Bot Auth is the reason your agent either gets served or gets throttled with the scrapers. Almost everything written about it repeats the same architecture diagram, so we did something different: on September 1, 2026 we fetched the published key directories of more than twenty major AI operators and infrastructure vendors to see who is genuinely signing their traffic. Four were. The results are in the first table.

Read

Tempo Blockchain

the Tempo blockchain

Tempo is the payments chain Stripe and Paradigm built, and it shipped with a protocol that lets software pay for things on its own. It settles machine payments in under a second. It has nothing at all to say about whether your agent should have paid.

Read

AI Agent Governance

AI agent governance

Every agentic AI governance framework published so far governs the same four things: identity, tools, data and prompts. Not one of them carries a budget. Here is what the real frameworks say, which guardrails actually bind at runtime, and what to do about the last mile none of them reach.

Read

A2A Protocol

A2A Protocol

Most explanations of the A2A protocol stop at the sentence that agents can now talk to each other. That was true in April 2025 and it is no longer the interesting part. A2A shipped version 1.0 in April 2026 under Linux Foundation governance, it runs in production inside Azure AI Foundry and Amazon Bedrock AgentCore, and the questions engineers actually get stuck on are narrower: what an Agent Card commits you to, when to reach for MCP instead, and what happens the first time one of your agents has to pay another one for the work. That last question has a specific answer, and it is not in the core spec.

Read

Mastercard Agent Pay

Mastercard Agent Pay

Nearly every article about Mastercard Agent Pay is a retelling of one press release from April 2025, the one where Mastercard said AI agents would be able to shop with Agentic Tokens and named Microsoft as the first platform. That was sixteen months ago, and four more things have shipped since. Reading only the launch coverage leaves you with roughly a quarter of the picture, and the missing three quarters are the parts that decide whether you can actually put this into production.

Read

Visa Intelligent Commerce

Visa Intelligent Commerce

Almost everything written about Visa Intelligent Commerce is a retelling of the April 2025 announcement, when Visa said AI agents would be able to pay with a Visa credential. Three more things have shipped since, including an open agent-identity protocol built with Cloudflare that most coverage does not mention at all. This page is the current version, checked against Visa’s own developer documentation and newsroom in August 2026.

Read

Stripe agentic commerce

Stripe agentic commerce

Most writing about Stripe and agentic commerce is still a retelling of the September 2025 launch week, when Stripe and OpenAI shipped Instant Checkout and published the Agentic Commerce Protocol together. Stripe has built a good deal more since then, and some of it points in a direction the launch coverage never anticipated. This page is the current version, checked against Stripe’s own documentation in August 2026.

Read

ChatGPT Instant Checkout

ChatGPT Instant Checkout

Almost every guide to ChatGPT Instant Checkout still reads like it was written the week it launched, walking merchants through how to apply and what the fee will be. OpenAI changed course in March 2026. Here is the accurate version: what Instant Checkout was, what the numbers actually looked like, what replaced it, and which parts of the stack are still very much alive.

Read

Google AP2

Google AP2

Most guides to Google AP2 still describe an Intent Mandate and a Cart Mandate, because most of them are rewrites of the September 2025 launch post. The specification moved. Here is what the Agent Payments Protocol actually defines today, and the one question it deliberately does not answer.

Read

Human in the loop AI

Human in the Loop AI

Every guide to human in the loop AI describes the same shape: the agent pauses, a person decides, the agent continues. The shape is right. What almost none of them ask is a harder question, which is where the pause is enforced, because a pause written into the agent's own code is a pause the agent is trusted to honor.

Read

AI agent cost

AI Agent Cost

Every cost guide for AI agents answers the same two questions: what does it cost to build, and what does it cost to run. Both are answerable, and both are on somebody's invoice. The third question is the one that ends up in a variance report, because the agent also spends your money, and nobody sends you a bill for that.

Read

Agentic checkout

Agentic Checkout

Nearly every guide to agentic checkout is written for the merchant who wants to receive these orders. Far fewer are written for the company whose agents are placing them, which is odd, because agentic checkout quietly removes the one screen where spending used to get a second look.

Read

API monetization

API Monetization

Most guides to API monetization argue about which pricing model wins. The harder question in 2026 is who is calling. An API priced for a signed-up developer with a key behaves very differently when the caller is an agent that showed up once, wants one record, and has no account.

Read

x402 protocol

x402 Protocol

x402 took the one HTTP status code the web never used and turned it into a payment rail machines can drive. The protocol is elegant and genuinely small. The part it deliberately leaves to you is the budget.

Read

Agentic payments

Agentic Payments

Agentic payments move money with no human at the checkout. The rails to do it all shipped during 2026. The part most teams have not solved is deciding, before the money moves, whether the agent was allowed to spend it.

Read

AI agent monetization

AI Agent Monetization

Every AI agent company is rewriting its price list. The models that survive are metered. The ones that quietly fail are the ones where nobody measured what a single task costs to serve.

Read

Agent payment platforms

AI Agent Payment Platforms

Five different kinds of product now call themselves an AI agent payment platform, and they solve five different problems. Picking the wrong category is the expensive mistake, not picking the wrong vendor inside a category.

Read

Universal Commerce Protocol

the Universal Commerce Protocol (UCP)

Google and Shopify shipped UCP as an open standard so an AI agent can check out at any merchant that supports it. Here is what the specification actually defines, where it is live for US buyers, and the one thing it deliberately leaves to you.

Read

MCP Payments

MCP Payments

MCP payments are how an AI agent discovers a payment tool and calls it to move money. The catch: the Model Context Protocol carries the tool call, not the spending decision, so nothing in the stack asks whether the purchase should have happened.

Read

Visa Intelligent Commerce vs Mastercard Agent Pay

Visa Intelligent Commerce vs Mastercard Agent Pay

Visa Intelligent Commerce and Mastercard Agent Pay are the two big card networks racing to let AI agents pay. They take different routes to the same idea, and neither one decides whether a given purchase should have happened.

Read

Agentic Commerce Protocol

the Agentic Commerce Protocol

ACP is the open standard behind agentic checkout in ChatGPT. It tells a merchant how to sell to an AI agent. It says nothing about whether your agent should have made the purchase.

Read

AP2 vs ACP vs x402

AP2 vs ACP vs x402

AP2, ACP, and x402 are the three standards shaping how AI agents pay. They solve different layers of the problem, and most real systems will touch more than one.

Read

Machine payments protocol

Machine payments protocol

As software starts paying software, machine payments protocols define how value moves without a human at the keyboard. The harder question is how to keep that spending governed.

Read

Know Your Agent (KYA)

Know Your Agent

KYA, or Know Your Agent, extends the idea of customer due diligence to autonomous software. When an agent spends, you need to know which agent, on whose authority, and under what limits.

Read

Keep agent spending governed

Add policy, hard limits, human approval, and an immutable audit trail across any protocol or rail. Start in the sandbox today.

Never moves money without policy