
CNBC is calling it crypto's infrastructure era. Coinbase and Circle are handing agents wallets. The headlines write themselves: agents will move money.
The part that matters more is quieter. Who stops a bad decision when money moves at machine speed?
I got drained twice in crypto. Not a little. Cleaned out. Both times, something signed that shouldn't have. The gap was not "did I have a wallet." The gap was authority at the moment of movement. Agents make that gap wider. The actor never sleeps. It never gets that sick feeling when the amount looks slightly wrong.
A session cap is not the same thing as a decision. Caps tell you how much you can lose. They do not decide whether this transfer should happen, to this recipient, under this rule, right now. Coinbase and MetaMask putting some limits on an agent wallet is real progress. It is still mostly one agent, one wallet, some guardrails. The hard part shows up when customers and agents share a fleet, and someone has to explain a wrong payment to a CFO before lunch.
On X and LinkedIn, people already describe the stack in ordinary words. Budget. Corridor. Authority. Receipt.
Budget is how much the agent can spend before it has to stop. Corridor is who it can pay and what kinds of moves are pre-cleared. Authority is who can say no when something sits outside that fence. Receipt is what you can show later: which actor, which rules, what decision, whether a human had to step in. Miss any of those four and you do not have governance. You have hope and a blockchain explorer.
Here is the irony of nanopayments. When amounts get tiny and frequent, per-transaction human review dies. Nobody is going to Face ID every three-cent API call. So teams either freeze agents out of money, or they open the faucet and pray the log is enough. A transaction log is useful. It is not a time machine. The design that survives machine-speed micropayments is an envelope: spend and recipient rules that hold before anything signs, with a human only when the move leaves the envelope. Pre-cleared corridors run at machine speed. Everything outside waits for a person.
I am building FortFi for that layer. Platforms embed governed wallets for their customers and agents, with policy before anything signs, through API and MCP, in their own stack. Brand-side, I call it the trust layer for money that moves itself. Buyer-side is simpler. Before money leaves, you should know which agent is acting, which wallet it can use, who it can pay, how much it can spend, and when a human must approve.
If you are wiring agent payments into a product, do not skip a step. Set a budget that matches blast radius, not vibes. Define corridors so the happy path does not need a meeting. Put authority on a phone when the move is outside the fence. A push notification is enough to unblock a larger spend. Keep a receipt you would hand to audit: who acted, what rule fired, full history, no rewriting after the fact.
For the fleet-scale version of this problem, who provisions and governs hundreds of vaults, I wrote that cut separately: Three agents or three thousand: who governs the fleet? (fortfiapp.com/blog/thousand-agent-treasurers). For the product surface platforms embed, start at fortfiapp.com.
Rails will keep getting easier. Wallets will keep getting cheaper to spin up. The question that does not go away is the one at signing time. Not "can the agent pay." Who stops it when the decision is wrong.
FAQ
- What are AI agent spend controls?
- Rules that decide how much an agent can spend, who it can pay, which wallet it can use, and when a human must approve, checked before a transfer signs.
- Is a wallet spending limit enough for agent payments?
- A cap limits loss size. It does not decide whether a specific payment should happen. You still need corridors (who and what is pre-cleared), authority outside that fence, and a receipt.
- What does policy before sign mean?
- Policy and risk checks run before the signature. If the move fails the rules, nothing signs. Approval can be delegated inside pre-set scopes. A human steps in when the rules require it.
- Who should authorize agent payments?
- Whoever owns the vault sets the envelope. That can be a founder or executive, a finance lead, or a super-admin on an engineering team. Platforms can also white-label the same controls for their customers, so each end customer owns their own vault rules. Individuals through mega enterprises. Same path: the agent acts inside the envelope; a human or co-signer authorizes anything outside budget, corridor, or risk rules.
- How do you govern programmable money when payments are tiny and frequent?
- Per-tx human review does not scale. Use envelopes: pre-cleared corridors at machine speed, human authority at the edge, and a decision receipt for every money-moving action.
Dan M. · Founder, FortFi LLC