1. Define the agent's purpose
Start with what the agent is supposed to purchase and why. A narrow purpose makes later controls clearer. 'Buy approved SaaS renewals for the marketing team' is easier to govern than 'handle company purchases'.
2. Set numerical limits
Define monthly budget, daily auto-pause threshold, per-transaction maximum and the amount above which a human must approve. These figures should be explicit values that software can evaluate.
3. Define counterparties and categories
Decide whether the agent can use only named merchants, approved merchant categories or both. First-time merchants can be routed to review even when their category would otherwise be permitted.
4. Control payment rails
Specify whether the agent can use cards, bank transfer, stablecoins or another method. A business may permit one rail for low-risk recurring purchases and require additional approval for another.
Protocols such as Google AP2, x402 and OpenAI’s Agentic Commerce Protocol can help agents authorize or execute commerce workflows, but the business still needs its own spend policy. Protocol support should not silently expand an agent’s authority.
5. Require evidence
Define what the agent must retain: invoice, receipt, quote, purchase justification, approver and transaction reference. Evidence requirements should be part of the policy, not an afterthought.
Frequently asked questions
Can an AI agent payment policy be JSON?
Yes. Machine-readable policy formats such as JSON make rules easier for software to evaluate consistently and version.
Should a policy allow exceptions?
Exceptions should be explicit and usually require elevated approval rather than silently bypassing the policy.
What happens when the policy cannot decide?
The safest default is to route ambiguous transactions to human review rather than infer broader authority.
Use the product
Turn the concepts in this guide into a working decision or policy.
Open AgenticSpend View policy schema